Coinbase Exploit Hacker Swaps $5M DAI to USDC, Bridges Funds After 35-Minute Idle Window

ccn.comОпубліковано о 2025-10-02Востаннє оновлено о 2025-10-02

Key Takeaways
  • Coinbase threat actors behind the May breach have become active again, transferring $5 million DAI.
  • The hackers then swapped DAI to USDC using Circle’s CCTP bridge.
  • The stolen funds sat in a USDC address for over 35 minutes, but Circle’s compliance norms failed to freeze it.

After five months, the May Coinbase exploit hacker has swiped $5 million of DAI stablecoins for USDC using Circle’s CCTP bridge.

The incident is linked to a breach in which Coinbase users had been tricked into sending funds to attackers after they gained access to personal information.

At the time, Coinbase had estimated that the losses could mount to $400 million.

Try Our Recommended Crypto Exchanges
Sponsored
Disclosure
We sometimes use affiliate links in our content, when clicking on those we might receive a commission at no extra cost to you. By using this website you agree to our terms and conditions and privacy policy.

ZachXBT Alerts Community

On-chain Seluth ZachXBT shared the incident in his Telegram group, which tracked the movement of funds on the blockchain after months of idleness.

The on-chain investigator said that the threat actor from the “Coinbase breach swapped ~5M DAI for ~5M USDC, which had been sitting as USDC for 35 minutes.”

Due to Circle’s compliance policies and slow response times in freezing suspicious addresses, the funds were successfully extracted via bridges, including Circle’s official Cross-Chain Transfer Protocol (CCTP).

ZachXBT called out Circle for being inactive and non-compliant

“Due to Circle not being compliant, the funds were just bridged away.  A portion was bridged using the official Circle CCTP bridge.”

Circle’s policy allows blacklisting USDC addresses but requires manual review. The 35-minute idle was flagged in this case, but processing delays prevented a freeze. CCTP transfers are “validated” post-burn, so recovery is harder once they are minted at the destination.

Theat Actors and Social Engineering Technique

The May Coinbase breach was one of the largest in crypto exchange history. It exposed sensitive customer data for around 69,461 users and enabled social engineering attacks that led to direct thefts totaling $200–400 million.

Hackers bribed overseas customer support agents from Indian call centers like TaskUs to access internal Coinbase systems. These insiders stole data for <1% of monthly active users but targeted high-value accounts with 7–8 figure balances.

The threat actors managed to gain access to emails, phone numbers, the last four digits of SSNs, photo IDs, and physical addresses. This fueled phishing campaigns in which actors posed as Coinbase reps, tricking users into sending crypto.

The hackers behind the whole operation contacted Coinbase, demanding a $20 million bounty. However, the crypto exchange denied the ransom and converted it into a reward for anyone who could help them identify and recover funds.

Пов'язані матеріали

The Hunter Becomes the Hunted: The Most Profitable MEV Bot Gets Hacked

A well-known and highly profitable Ethereum MEV Bot, Jaredfromsubway.eth, suffered a sophisticated on-chain attack this Saturday, losing over $7.5 million. Analysis by Blockaid and others reveals this was not a conventional phishing or smart contract exploit, but a targeted "counter-MEV honeypot attack." The attacker meticulously laid a trap over several weeks, deploying 66 fake token contracts and liquidity pools disguised as major assets like WETH and USDC. These pools created the illusion of arbitrage opportunities. The MEV Bot's automated system detected these signals, executed trades, and in the process, granted approval permissions to attacker-controlled contracts. These approvals were not revoked, creating a persistent vulnerability. The attacker then exploited this in a single transaction, draining the bot's ETH, USDC, and USDT holdings. Jaredfromsubway.eth is notorious as one of Ethereum's most active and profitable MEV Bots, primarily known for executing "sandwich attacks" to profit from transaction slippage. Estimates suggest it has earned tens of millions in MEV revenue. The incident highlights escalating crypto security threats, demonstrating that even top-tier automated "predators" are vulnerable to novel, logic-based attacks designed to exploit their own operational rules. Following the hack, an unverified X account impersonating Jaredfromsubway.eth emerged, falsely offering a bounty for the return of funds, prompting developer warnings for users to stay vigilant.

marsbit34 хв тому

The Hunter Becomes the Hunted: The Most Profitable MEV Bot Gets Hacked

marsbit34 хв тому

The Reality of Payments in Latin America Is Not What You Think

The payment landscape in Latin America is undergoing a fundamental shift, driven by on-the-ground realities that challenge common perceptions. Based on over 500 hours of field research across the region, key insights emerge. Firstly, QR code payments, like Brazil's Pix, are becoming the dominant payment method in most emerging markets, overtaking cards. However, these domestic instant payment systems lack international interoperability, creating a significant gap for cross-border users. Secondly, the narrative around crypto cards is often misunderstood; their primary volume comes from high-net-worth professionals using them for salary conversions (e.g., USDT to local currency via Pix), not retail micro-payments. Competition in payments is shifting from customer acquisition to controlling the settlement layer, leading fintechs to acquire banking licenses for efficiency. Thirdly, treating "Latin America" as a single market is a mistake. Countries like Argentina, Brazil, and Mexico have distinct economic realities, user segments, and regulatory approaches. Brazil alone has at least five distinct user segments with different financial flows. Overlooked markets like Guatemala, Honduras, and El Salvador (the "forgotten five") offer high remittance volumes with lower competitive density. Finally, regulation in Latin America is often ahead of the US, with clearer frameworks for digital assets and a pragmatic approach from regulators focused on safety rather than obstruction. The margin on stablecoin forex is rapidly compressing toward zero, meaning future winners will be those building value-added services on top of the infrastructure, not just the cheapest exchange.

marsbit50 хв тому

The Reality of Payments in Latin America Is Not What You Think

marsbit50 хв тому

Making Music in a Bear Market: The Survival Experiment of a Bitcoin Band

"Orange Pill Jam: A Bitcoin Band's Survival in the Bear Market" Orange Pill Jam is a musical group exploring themes of financial sovereignty and privacy, born from the Bitcoin community. Formed after singer Mermaid performed her song "Dollar Apocalypse" at a 2022 conference, the band creates music intended for both Bitcoin enthusiasts and general audiences. Their creative process involves Mermaid writing lyrics and melodies, which producer/multi-instrumentalist Michi then shapes with a precise, rhythm-focused approach, often demanding numerous retakes to achieve his unique standard of timing. Their songs, like "Cypherpunks' Manifesto" and "Fire of Freedom," tackle concepts of digital privacy, the pitfalls of "free" services, and personal sovereignty, influenced by experiences in places like El Salvador. Despite operating in a crypto bear market with a Copyleft model (offering music for free sharing/remixing and accepting optional Bitcoin donations), they face practical challenges. Their growth is slow on platforms like YouTube and Spotify, which aren't optimized for their niche content. The band also navigates the rise of AI-generated music. While acknowledging AI's efficiency for certain tasks, they believe human creativity occupies a unique space that algorithms cannot replicate—the ability to create new genres and capture intangible rhythmic feeling. For Orange Pill Jam, the core argument for both Bitcoin in a downturn and human artistry in the AI age lies in this irreplaceable, intentional, and imperfectly human creative process. Their project persists as an anti-algorithm experiment, valuing the unquantifiable impact of music over scalable metrics.

marsbit56 хв тому

Making Music in a Bear Market: The Survival Experiment of a Bitcoin Band

marsbit56 хв тому

Торгівля

Спот
Ф'ючерси
活动图片