Coinbase Exploit Hacker Swaps $5M DAI to USDC, Bridges Funds After 35-Minute Idle Window

ccn.comPublished on 2025-10-02Last updated on 2025-10-02

Key Takeaways
  • Coinbase threat actors behind the May breach have become active again, transferring $5 million DAI.
  • The hackers then swapped DAI to USDC using Circle’s CCTP bridge.
  • The stolen funds sat in a USDC address for over 35 minutes, but Circle’s compliance norms failed to freeze it.

After five months, the May Coinbase exploit hacker has swiped $5 million of DAI stablecoins for USDC using Circle’s CCTP bridge.

The incident is linked to a breach in which Coinbase users had been tricked into sending funds to attackers after they gained access to personal information.

At the time, Coinbase had estimated that the losses could mount to $400 million.

Try Our Recommended Crypto Exchanges
Sponsored
Disclosure
We sometimes use affiliate links in our content, when clicking on those we might receive a commission at no extra cost to you. By using this website you agree to our terms and conditions and privacy policy.
promotions
Earn rewards worth up to 5,000 USDT on your first deposit
Coins
Bitcoin Ethereum Tether Litecoin Bitcoin Cash 88
  • Bitcoin
  • Ethereum
  • Tether
  • Litecoin
  • Bitcoin Cash
  • TRON
  • Binance Coin
  • XRP
  • Cardano
  • Binance USD
  • USD Coin
  • Polkadot
  • Shiba Inu
  • Basic Attention Token
  • Qtum
  • Ethereum Classic
  • Chainlink
  • Solana
  • Polygon Matic
  • Cosmos
  • Wrapped Bitcoin
  • PancakeSwap
  • The Sandbox
  • Storj
  • iExec RLC
  • Bancor
  • Uniswap
  • Enjin Coin
  • 1inch Network
  • Chiliz
  • Aave
  • Synthetix
  • Maker
  • Compound
  • Theta Network
  • Celo
  • Curve DAO Token
  • Decentraland
  • JUST
  • Axie Infinity
  • Gala
  • Internet Computer
  • The Graph
  • Filecoin
  • dYdX
  • Mask Network
  • Lido DAO Token
  • Reserve Rights
  • Chromia
  • Ankr
  • Ocean Protocol
  • Adventure Gold
  • Origin Protocol
  • Celer Network
  • NKN
  • Bitget Token
  • Alchemix
  • Immutable
  • Ethereum Name Service
  • Avalanche
  • Zilliqa
  • JasmyCoin
  • Toncoin
  • Convex Finance
  • Spell Token
  • Holo
  • Render Token
  • SushiSwap
  • MetisDAO
  • Audius
  • Illuvium
  • ARPA Chain
  • Osmosis
  • Fantom
  • Neo
  • Arweave
  • Algorand
  • Kusama
  • XDC Network
  • APEcoin
  • MultiversX
  • THORChain
  • NEAR Protocol
  • Nexo
  • Amp
  • Livepeer
  • PAX Gold
  • TrueUSD
  • BitTorrent
  • Golem
  • FLUX
  • Helium
  • Dai
No result
promotions
Receive up to $100,000 worth of exclusive gifts for newcomers upon registration.
Coins
Bitcoin Ethereum Tether Binance Coin USD Coin 151
  • Bitcoin
  • Ethereum
  • Tether
  • Binance Coin
  • USD Coin
  • Solana
  • XRP
  • Dogecoin
  • Cardano
  • Toncoin
  • Shiba Inu
  • Avalanche
  • TRON
  • Chainlink
  • Polygon Matic
  • Polkadot
  • Wrapped Bitcoin
  • Litecoin
  • Dai
  • NEAR Protocol
  • Bitcoin Cash
  • Stellar
  • Cosmos
  • Filecoin
  • Ethereum Classic
  • Aptos
  • Hedera Hashgraph
  • Immutable
  • Optimism
  • Arbitrum
  • VeChain
  • The Sandbox
  • Decentraland
  • Axie Infinity
  • Injective Protocol
  • Render
  • The Graph
  • Maker
  • Aave
  • Chiliz
  • Helium
  • PAX Gold
  • Compound
  • Lido DAO Token
  • Sui
  • Conflux Network
  • Lido Staked ETH
  • OKB
  • Uniswap
  • Pepe
  • Ondo
  • Mantle
  • First Digital USD
  • XDC Network
  • Artificial Superintelligence Alliance
  • Jupiter
  • Quant
  • Worldcoin
  • Bonk
  • Tether Gold
  • JITO
  • JasmyCoin
  • Core
  • Floki Inu
  • Ethereum Name Service
  • SushiSwap
  • 1inch Network
  • Tezos
  • Algorand
  • Flow
  • Trust Wallet Token
  • Curve DAO Token
  • MultiversX
  • Basic Attention Token
  • Enjin Coin
  • Ethena
  • Ethena Staked USDe
  • Audius
  • Alchemy Pay
  • Arkham
  • API3
  • Bounce Token
  • Altlayer
  • Aergo
  • Amp
  • Aevo
  • Ankr
  • Axelar
  • Alpaca Finance
  • Blur
  • Biconomy
  • Tranchess
  • Celer Network
  • Shentu
  • Civic
  • Convex Finance
  • Cartesi
  • Cyber
  • COTI
  • DIA
  • dYdX
  • ether.fi
  • FLUX
  • Ampleforth
  • Golem
  • Holo
  • IoTeX
  • Illuvium
  • JUST
  • Livepeer
  • Memecoin
  • Manta Network
  • Treasure
  • Mask Network
  • Origin Protocol
  • ORDI
  • Ontology
  • Phala Network
  • Pendle
  • Portal
  • Pyth Network
  • ConstitutionDAO
  • iExec RLC
  • Reserve Rights
  • Ravencoin
  • Storj
  • Status
  • Spell Token
  • Sun (New)
  • SuperVerse
  • Tellor
  • LayerZero
  • Scroll
  • Usual
  • Eigenlayer
  • Hamster Kombat
  • Catizen
  • Berachain
  • KAITO
  • Pudgy Penguins
  • Solayer
  • Bio Protocol
  • ChainGPT
  • Cookie DAO
  • Solv Protocol
  • Movement
  • DeXe
  • Nexo
  • Hyperliquid
  • STEPN
  • Synthetix
  • Neo
  • APEcoin
  • Gala
  • Internet Computer
  • Pi Network
No result

ZachXBT Alerts Community

On-chain Seluth ZachXBT shared the incident in his Telegram group, which tracked the movement of funds on the blockchain after months of idleness.

The on-chain investigator said that the threat actor from the “Coinbase breach swapped ~5M DAI for ~5M USDC, which had been sitting as USDC for 35 minutes.”

Due to Circle’s compliance policies and slow response times in freezing suspicious addresses, the funds were successfully extracted via bridges, including Circle’s official Cross-Chain Transfer Protocol (CCTP).

ZachXBT called out Circle for being inactive and non-compliant

“Due to Circle not being compliant, the funds were just bridged away.  A portion was bridged using the official Circle CCTP bridge.”

Circle’s policy allows blacklisting USDC addresses but requires manual review. The 35-minute idle was flagged in this case, but processing delays prevented a freeze. CCTP transfers are “validated” post-burn, so recovery is harder once they are minted at the destination.

Theat Actors and Social Engineering Technique

The May Coinbase breach was one of the largest in crypto exchange history. It exposed sensitive customer data for around 69,461 users and enabled social engineering attacks that led to direct thefts totaling $200–400 million.

Hackers bribed overseas customer support agents from Indian call centers like TaskUs to access internal Coinbase systems. These insiders stole data for <1% of monthly active users but targeted high-value accounts with 7–8 figure balances.

The threat actors managed to gain access to emails, phone numbers, the last four digits of SSNs, photo IDs, and physical addresses. This fueled phishing campaigns in which actors posed as Coinbase reps, tricking users into sending crypto.

The hackers behind the whole operation contacted Coinbase, demanding a $20 million bounty. However, the crypto exchange denied the ransom and converted it into a reward for anyone who could help them identify and recover funds.

Related Reads

Bitcoin Withdrawals Continue: 8 Years of Storage in a Coldcard Cold Wallet Ended in Zero

Coldcard Hardware Wallet Hacked: Losses Mount Due to Vulnerable Seed Generation A critical vulnerability in Coldcard hardware wallets has led to a continued wave of fund thefts. According to Galaxy Research, the total stolen has reached 1,367.05 BTC (approx. $88.6 million) from 4,585 addresses, a significant increase from the initial 594.5 BTC reported on July 30, 2026. Most of the stolen funds remain on the attackers' addresses. The issue is not with the current firmware, which Coinkite has updated, but with seed phrases generated on vulnerable devices between March 2021 and the release of fixed firmware versions. Due to a programmer error, devices switched from using a hardware random number generator to the software-based Yasmarang generator, which was initialized with publicly accessible data like the chip's serial number. This made the seed phrases predictable through offline brute-force attacks, meaning wallets remain at risk until funds are moved to a new wallet generated with the patched firmware. Affected devices include Mk2/Mk3 with firmware 4.0.1–4.1.9 (and up to 5.0.3), Mk4/Mk5 up to version 5.6.0, and Q models up to 1.5.0Q. The only exceptions are seeds created with a high-entropy method like at least 50 independent dice rolls or a strong unique BIP-39 passphrase. All other owners must generate a new seed on the fixed firmware and transfer their assets. A case highlighting the human impact involves a 39-year-old long-term investor who lost 2 BTC (approx. $130,000) in minutes. He had accumulated the Bitcoin over eight years through physical labor, viewing it as a financial lifeline and a retirement plan in a country suffering from hyperinflation. His story underscores that even conservative "buy and hold in cold storage" strategies can be compromised by such underlying technical flaws. From a technical perspective, this incident echoes historical failures where weak random number generators undermined cryptographic security, challenging the assumption that offline storage is automatically foolproof.

cryptonews.ru3h ago

Bitcoin Withdrawals Continue: 8 Years of Storage in a Coldcard Cold Wallet Ended in Zero

cryptonews.ru3h ago

Trading

Spot
活动图片