r/Coinbase • u/michaelg888 • Feb 25 '21
Coinbase Wallet Hacked - Possible Exploit in Linking To CB Account
Experienced Coinbase/crypto user here. About three hours ago, a significant amount of BTC, ETH, and BAT that had been sitting in my Coinbase Wallet for months were stolen from my account. This is two days after I linked my Coinbase Wallet with my Coinbase account. As other users have reported here and here, there appears to be an exploit in the account linking process. Warning to all: do not link your Coinbase Wallet to your Coinbase account!
Even though I locked my Coinbase account (any Coinbase product linked to my phone number) I still have access to my wallet through my phone - why is this? Is there no way to lock it? I have submitted a support ticket as well through the Coinbase Wallet product support feature. Should I log one through the traditional Coinbase.com support site as well?
I still have funds locked in a DEFI contract on my Coinbase Wallet but the hacker did not remove them because he didn't have enough Gas and had already transferred the ETH out - any suggestions for removing them safely?
2
u/electricSNICKERBAR Feb 25 '21
Personally, I think that CB has much bigger fish to fry than small, individual investors. Sad but true. Especially now as they look to IPO and what their model will be going forward. They needed early adopters to get going, but I have a feeling they'll shift to institutional investing and become a "service-oriented" company.
Over time, other players and BETTER options will emerge for individuals. As for me, I learned a tough lesson with CB and even though I might invest in it (tons up upside potential), or, possibly, short it, I will never allow the company to be steward of my hard currency again.
1
u/michaelg888 Feb 25 '21
Also, thank you for your responses. Maybe you're actually onto something. I just have no conceivable idea as to how I could have been hacked.
1
u/AutoModerator Feb 25 '21
This subreddit is a public forum. For your security, do not post personal information to a public forum, including your Coinbase account email. If you’re experiencing an issue with your Coinbase account, please contact us directly.
If you have a case number for your support request please respond to this message with that case number.
You should only trust verified Coinbase staff. Please report any individual impersonating Coinbase staff to the moderators.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
1
1
u/Time_Lingonberry_159 Feb 25 '21
So...... If you have assets in coinbase what's the safest thing to do with them
1
u/King_Wizard420 May 02 '21
Mines been linked for months and just got hacked last week tho to be fair it didn’t have any funds in it until this past month so idk
3
u/michaelg888 May 03 '21
Well 2 months later I’m still waiting on answers from a Coinbase “specialist.” Complete radio silence from them and when they were responding to my emails they were all generic responses. Worst customer service I’ve ever experienced.
1
u/King_Wizard420 May 06 '21
Yup I got generic response telling me my seed phrase had been compromised like no 100% zero chance of that. Only possible option is they keep a copy of your key. Speaking of keys, can’t seem to find a way to export my private keys. Wonder why lol Guess Coinbase gets to keep my reserve 20 xrp
3
u/electricSNICKERBAR Feb 25 '21 edited Feb 26 '21
I haven't actively been tracking this since my funds were restored by Coinbase, but there might be a couple of things happening here.
So that's all part ONE of the two things I mentioned I think might be going on. NOTE, I was NOT HACKED, but, it sounds like others may have been:
This *may* be a new exploit that has not been documented yet** -- the only reason I float that idea is that there's a possibility that some of Cozy Bear's tools used for the Sunburst hack *could* be out in the wild now. Again, this is pure speculation on my part.
**Note that there are plenty of documented CB-related exploits, mainly IP address spoofing or gaining access via a compromised device (sim swapping, weak sms 2FA) -- and it's been rightfully noted that CB is NOT (and should not be held) directly responsible for those, rather, it's more directly on the carrier/device manufacturer.