Canadian scammer posing as Coinbase support exposed in $2 million crypto theft

Source Cryptopolitan

A scammer posing as support personnel from Coinbase defrauded more than $2 million in cryptocurrency during 2025 by staging social engineering attacks.

Blockchain investigator ZachXBT exposed the Canadian threat actor, known as Haby or Havard, using on-chain analysis and social media evidence. The scammer made calls to Coinbase users with phone numbers claiming to be from customer support, and then directed the victims to transfer funds to wallets controlled by the attackers.

ZachXBT traces theft via blockchain analysis.

Investigations began when Haby, on December 30, 2024, posted a screenshot showing a 21,000 XRP theft worth $44,000 from a Coinbase user. ZachXBT matched the wallet address to two additional Coinbase user thefts amounting to approximately $500,000. Analysis showed Haby had swapped stolen XRP to Bitcoin through instant exchanges.

Through timing analysis, ZachXBT tracked down Haby’s Bitcoin address. In February 2025, Haby had shared screenshots in a group chat showing a wallet containing $237,000.

The Bitcoin balance for the identified address matched the screenshots from February 1, 2025. Tracing backward from this address uncovered three additional Coinbase support impersonation thefts totaling over $560,000.

The investigator linked the wallets to Haby through leaked information in social media posts and screen recordings. A leaked video showed Haby conducting a social engineering call with a target.

The screen recording exposed the email address and his Telegram account. Additional Instagram screenshots displayed posts bragging about social engineering thefts. One story post revealed “From Harvi’s MacBook Air” in the device information.

Scammer operated with poor operational security

Haby regularly posted stories and selfies on social media platforms displaying his lifestyle funded by stolen cryptocurrency. The posts showed purchases of expensive Telegram usernames, luxury items, bottle service, and gambling expenses. A member of his chat group advised him to stop posting about his activities so frequently.

The scammer appeared to have little concern for operational security. Social media analysis revealed his location in Abbotsford, near Vancouver, British Columbia. OSINT performed on his story posts confirmed the location.

Haby frequently bought expensive Telegram usernames and deleted his most recent account two days before the investigation was published. Previous accounts showed his alias in various chats, confirming the authenticity of leaked screenshots.

Coinbase support impersonation scams escalated in 2025

The 2025 period was a rather challenging time for Coinbase users. Attackers moved from traditional phishing to precision targeting using data stolen from Coinbase support systems. A May 2025 insider data breach carried out highly effective impersonation scams throughout the year.

It involved bribery by cybercriminals who hired overseas customer support agents, mainly in Hyderabad, India, to steal internal data. Compromised information includes names, emails, phone numbers, home addresses, government ID images, and real-time account balances.

The attackers did not access the private keys and passwords directly. Overall, about 1% of Coinbase users were targeted, amounting to approximately 70,000 high-value clients.

Attackers demanded a $20 million ransom in exchange for deleting the stolen data. Coinbase declined the ransom demand, set up a $20 million bounty on the attackers, and refunded affected victims.

Multiple arrests happened in December 2025

Law enforcement activity peaked in December 2025 with several arrests related to Coinbase impersonation scams. Ronald Spektor of Brooklyn, New York, was charged with stealing $16 million from approximately 100 users.

His methodology involved using stolen customer data to pose as Coinbase “Elite Support” and alerting users to pending unauthorized transactions. He guided victims to move funds to a “secure vault” that was actually a wallet he controlled.

Indian police arrested a former Coinbase support agent on December 29, 2025, connected to the May data theft. The arrest confirmed the bribed insider theory and was the first major law enforcement action against the source of the data leak.

If you're reading this, you’re already ahead. Stay there with our newsletter.

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Markets in 2026: Will gold, Bitcoin, and the U.S. dollar make history again? — These are how leading institutions thinkAfter a turbulent 2025, what lies ahead for commodities, forex, and cryptocurrency markets in 2026?
Author  Insights
Dec 25, Thu
After a turbulent 2025, what lies ahead for commodities, forex, and cryptocurrency markets in 2026?
placeholder
ECB Policy Outlook for 2026: What It Could Mean for the Euro’s Next MoveWith the ECB likely holding rates steady at 2.15% and the Fed potentially extending cuts into 2026, EUR/USD may test 1.20 if Eurozone growth proves resilient, but weaker growth and an ECB pivot could pull the pair back toward 1.13 and potentially 1.10.
Author  Mitrade
Dec 26, Fri
With the ECB likely holding rates steady at 2.15% and the Fed potentially extending cuts into 2026, EUR/USD may test 1.20 if Eurozone growth proves resilient, but weaker growth and an ECB pivot could pull the pair back toward 1.13 and potentially 1.10.
placeholder
Two Crypto “Buy” Calls for 2027: Bitcoin Looks Plausible, XRP Looks Like a High-Conviction BetStandard Chartered’s Kendrick-backed 2027 targets paint large upside for Bitcoin and XRP—but Bitcoin’s ETF-led adoption case looks sturdier, while XRP remains a higher-volatility bet dependent on ETF traction and real-world payments scaling.
Author  Mitrade
Yesterday 09: 39
Standard Chartered’s Kendrick-backed 2027 targets paint large upside for Bitcoin and XRP—but Bitcoin’s ETF-led adoption case looks sturdier, while XRP remains a higher-volatility bet dependent on ETF traction and real-world payments scaling.
placeholder
Silver Price Forecasts: XAG/USD drops below $75.00 after Trump - Zelenkyy’s meeting Silver (XAG/USD) has lost more than $10 since hitting a fresh record high near $86.00 on Monday’s early trading. The precious metal has retreated to levels in the $74.00 area at the time of writing, weighed by comments by US President Trump about the chances of a peace deal in Ukraine.
Author  FXStreet
Yesterday 09: 42
Silver (XAG/USD) has lost more than $10 since hitting a fresh record high near $86.00 on Monday’s early trading. The precious metal has retreated to levels in the $74.00 area at the time of writing, weighed by comments by US President Trump about the chances of a peace deal in Ukraine.
placeholder
Ethereum smart contract deployments reach new 8.7M high in Q4Token Terminal data revealed that smart contracts deployed on the Ethereum network hit an all-time high of 8.7 million in the fourth quarter of 2025.
Author  Cryptopolitan
Yesterday 09: 42
Token Terminal data revealed that smart contracts deployed on the Ethereum network hit an all-time high of 8.7 million in the fourth quarter of 2025.
goTop
quote