• Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
Wednesday, September 10, 2025
  • Login
  • Register
Coin24h.com
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
Coin24h.com
No Result
View All Result
Ledger Nano X - The secure hardware wallet
ADVERTISEMENT

How Coinbase Phishers Steal One-Time Passwords

13 October 2021
in DOT
Reading Time: 6 mins read
A A
0
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter
cryptotrader
ADVERTISEMENT

A recent phishing campaign targeting Coinbase users shows thieves are getting smarter about phishing one-time passwords (OTPs) needed to complete the login process. It also shows that phishers are attempting to sign up for new Coinbase accounts by the millions as part of an effort to identify email addresses that are already associated with active accounts.

DevOps Experience

A Google-translated version of the now-defunct Coinbase phishing site, coinbase.com.password-reset[.]com

Coinbase is the world’s second-largest cryptocurrency exchange, with roughly 68 million users from over 100 countries. The now-defunct phishing domain at issue — coinbase.com.password-reset[.]com — was targeting Italian Coinbase users (the site’s default language was Italian). And it was fairly successful, according to Alex Holden, founder of Milwaukee-based cybersecurity firm Hold Security.

Holden’s team managed to peer inside some poorly hidden file directories associated with that phishing site, including its administration page. That panel, pictured in the redacted screenshot below, indicated the phishing attacks netted at least 870 sets of credentials before the site was taken offline.

Related articles

Polkadot Price Likely to Crash xx% Despite Recent Protocol Upgrade

Polkadot Price Likely to Crash xx% Despite Recent Protocol Upgrade

30 July 2024
Here’s Why UNI and Polkadot (DOT) Holders Are Flocking To Rollblock

Here’s Why UNI and Polkadot (DOT) Holders Are Flocking To Rollblock

28 July 2024

The Coinbase phishing panel.

[crypto-donation-box]

Holden said each time a new victim submitted credentials at the Coinbase phishing site, the administrative panel would make a loud “ding” — presumably to alert whoever was at the keyboard on the other end of this phishing scam that they had a live one on the hook.

In each case, the phishers manually would push a button that caused the phishing site to ask visitors for more information, such as the one-time password from their mobile app.

Cryptohopper
ADVERTISEMENT

“These guys have real-time capabilities of soliciting any input from the victim they need to get into their Coinbase account,” Holden said.

Pressing the “Send Info” button prompted visitors to supply additional personal information, including their name, date of birth, and street address. Armed with the target’s mobile number, they could also click “Send verification SMS” with a text message prompting them to text back a one-time code.

SIFTING COINBASE FOR ACTIVE USERS

Holden said the phishing group appears to have identified Italian Coinbase users by attempting to sign up new accounts under the email addresses of more than 2.5 million Italians. His team also managed to recover the username and password data that victims submitted to the site, and virtually all of the submitted email addresses ended in “.it”.

But the phishers in this case likely weren’t interested in registering any accounts. Rather, the bad guys understood that any attempts to sign up using an email address tied to an existing Coinbase account would fail. After doing that several million times, the phishers would then take the email addresses that failed new account signups and target them with Coinbase-themed phishing emails.

Holden’s data shows this phishing gang conducted hundreds of thousands of halfhearted account signup attempts daily. For example, on Oct. 10 the scammers checked more than 216,000 email addresses against Coinbase’s systems. The following day, they attempted to register 174,000 new Coinbase accounts.

In an emailed statement shared with KrebsOnSecurity, Coinbase said it takes “extensive security measures to ensure our platform and customer accounts remain as safe as possible.” Here’s the rest of their statement:

“Like all major online platforms, Coinbase sees attempted automated attacks performed on a regular basis. Coinbase is able to automatically neutralize the overwhelming majority of these attacks, using a mixture of in-house machine learning models and partnerships with industry-leading bot detection and abuse prevention vendors. We continuously tune these models to block new techniques as we discover them. Coinbase’s Threat Intelligence and Trust & Safety teams also work to monitor new automated abuse techniques, develop and apply mitigations, and aggressively pursue takedowns against malicious infrastructure. We recognize that attackers (and attack techniques) will continue to evolve, which is why we take a multi-layered approach to combating automated abuse.”

Last month, Coinbase disclosed that malicious hackers stole cryptocurrency from 6,000 customers after using a vulnerability to bypass the company’s SMS multi-factor authentication security feature.

“To conduct the attack, Coinbase says the attackers needed to know the customer’s email address, password, and phone number associated with their Coinbase account and have access to the victim’s email account,” Bleeping Computer’s Lawrence Abrams wrote. “While it is unknown how the threat actors gained access to this information, Coinbase believes it was through phishing campaigns targeting Coinbase customers to steal account credentials, which have become common.”

This phishing scheme is another example of how crooks are coming up with increasingly ingenious methods for circumventing popular multi-factor authentication options, such as one-time passwords. Last month, KrebsOnSecurity highlighted research into several new services based on Telegram-based bots that make it relatively easy for crooks to phish OTPs from targets using automated phone calls and text messages.These OTP phishing services all assume the customer already has the target’s login credentials through some means — such as through a phishing site like the one examined in this story.

Savvy readers here no doubt already know this, but to find the true domain referenced in a link, look to the right of “http(s)://” until you encounter the first slash (/). The domain directly to the left of that first slash is the true destination; anything that precedes the second dot to the left of that first slash is a subdomain and should be ignored for the purposes of determining the true domain name.

In the phishing domain at issue here — coinbase.com.password-reset[.]com — password-reset[.]com is the destination domain, and the “coinbase.com” is just an arbitrary subdomain of password-reset[.]com. However, when viewed in a mobile device, many visitors to such a domain may only see the subdomain portion of the URL in their mobile browser’s address bar.

The best advice to sidestep phishing scams is to avoid clicking on links that arrive unbidden in emails, text messages or other media. Most phishing scams invoke a temporal element that warns of dire consequences should you fail to respond or act quickly. If you’re unsure whether the message is legitimate, take a deep breath and visit the site or service in question manually — ideally, using a browser bookmark so as to avoid potential typosquatting sites.

Also, never provide any information in response to an unsolicited phone call. It doesn’t matter who claims to be calling: If you didn’t initiate the contact, hang up. Don’t put them on hold while you call your bank; the scammers can get around that, too. Just hang up. Then you can call your bank or wherever else you need.

By the way, when was the last time you reviewed your multi-factor settings and options at the various websites entrusted with your most precious personal and financial information? It might be worth paying a visit to 2fa.directory (formerly twofactorauth[.]org) for a checkup.

*** This is a Security Bloggers Network syndicated blog from Krebs on Security authored by BrianKrebs. Read the original post at: https://krebsonsecurity.com/2021/10/how-coinbase-phishers-steal-one-time-passwords/

Credit: Source link

Tags: CoinbaseOneTimePasswordsPhishersSteal
Share76Tweet47
Ledger Nano X - The secure hardware wallet
Previous Post

Why Is Polkadot Exploding While Bitcoin And Others Are Trading Flat Today? – Polkadot – United States Dollar ($DOT)

Next Post

Bitcoin Mining After the China Ban: US Dominance Is Set to Continue

Related Posts

Polkadot Price Likely to Crash xx% Despite Recent Protocol Upgrade

Polkadot Price Likely to Crash xx% Despite Recent Protocol Upgrade

30 July 2024
0

Polkadot price suffers bearish pressure despite continued network developments. The latest in the blockchain upgrade is the asynchronous backing which...

Here’s Why UNI and Polkadot (DOT) Holders Are Flocking To Rollblock

Here’s Why UNI and Polkadot (DOT) Holders Are Flocking To Rollblock

28 July 2024
0

Though some investors are content with 2-10x returns, the vast majority of investors enter the crypto marketplace to make parabolic...

Dotcoin Tap-to-Play Game Set to Launch on Venom

Dotcoin Tap-to-Play Game Set to Launch on Venom

26 July 2024
0

One of the most popular tap-to-play games on Telegram, Dotcoin, is launching on the Venom blockchain. Dotcoin, with over 20...

Is Polkadot (DOT) a Millionaire Maker?

Is Polkadot (DOT) a Millionaire Maker?

24 July 2024
0

Is Polkadot the next big thing in crypto? Find out what the future holds for this harbinger and enabler of...

BlockDAG’s M Presale Boost, Tied with UFC Champ Alex Pereira, Disrupts Polkadot and Litecoin Market Predictions

BlockDAG’s $60M Presale Boost, Tied with UFC Champ Alex Pereira, Disrupts Polkadot and Litecoin Market Predictions

22 July 2024
0

Polkadot and Litecoin are navigating through turbulent market waters, facing bearish predictions. In this challenging environment, BlockDAG has emerged as...

Load More
Next Post

Bitcoin Mining After the China Ban: US Dominance Is Set to Continue

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Plugin Install : Widget Tab Post needs JNews - View Counter to be installed
  • Trending
  • Comments
  • Latest
Ethereum Price Prediction; Solana Latest News & Which Is Voted As The Top Crypto To Buy Today – CoinCentral

Ethereum Price Prediction; Solana Latest News & Which Is Voted As The Top Crypto To Buy Today – CoinCentral

10 September 2025
BNB hits new all-time high of 7 amid Binance partnering with Franklin Templeton for tokenization – CryptoSlate

BNB hits new all-time high of $907 amid Binance partnering with Franklin Templeton for tokenization – CryptoSlate

10 September 2025
Solana Hits 7-Month High Price as Bitwise Exec Foresees 'Epic End-of-Year Run' – Decrypt

Solana Hits 7-Month High Price as Bitwise Exec Foresees 'Epic End-of-Year Run' – Decrypt

10 September 2025
Solana Hits 7-Month High Price as Bitwise Exec Foresees 'Epic End-of-Year Run' – Yahoo Finance

Solana Hits 7-Month High Price as Bitwise Exec Foresees 'Epic End-of-Year Run' – Yahoo Finance

10 September 2025

About Us

We publish a comprehensive news feed covering all news relevant to the crypto user, covering main industry news, politics and regulation as well as consumer-level “news you can use” (practical stuff), including handy DIY tips, links to useful tools, unbiased reviews and opinions revolving around cryptocurrency. Simple logic and real-world examples are preferred before technical jargon and personal rants.

Categories

  • Altcoin
  • ApeCoin
  • Bitcoin
  • Blockchain
  • BNB
  • Cardano
  • Cryptocurrency
  • DOGE
  • DOT
  • Ethereum
  • HBAR
  • Litecoin
  • Market
  • Meta News
  • Mining
  • NFT
  • QNT
  • Regulation
  • SHIBA
  • Solano
  • Tether
  • Uncategorized
  • XDC
  • XLM
  • XRP

What’s New Here!

  • Ethereum Price Prediction; Solana Latest News & Which Is Voted As The Top Crypto To Buy Today – CoinCentral
  • BNB hits new all-time high of $907 amid Binance partnering with Franklin Templeton for tokenization – CryptoSlate
  • Solana Hits 7-Month High Price as Bitwise Exec Foresees 'Epic End-of-Year Run' – Decrypt
  • Solana Hits 7-Month High Price as Bitwise Exec Foresees 'Epic End-of-Year Run' – Yahoo Finance
  • Forget Shiba Inu (SHIB), Here’s the Meme Coin With 25,000% Growth Potential to Flip $700 into $175,000

Subscribe Now

Our Partner

Round Main Logo
  • About Us
  • Privacy Policy
  • Contact Us

© 2022-2025 coin24h.com

No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining

© 2020 coin24h.com

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • bitcoinBitcoin (BTC) $ 113,980.00
  • ethereumEthereum (ETH) $ 4,351.66
  • xrpXRP (XRP) $ 2.99
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 893.36
  • solanaSolana (SOL) $ 223.76
  • usd-coinUSDC (USDC) $ 0.999804
  • staked-etherLido Staked Ether (STETH) $ 4,345.59
  • dogecoinDogecoin (DOGE) $ 0.244379
  • cardanoCardano (ADA) $ 0.886747
  • tronTRON (TRX) $ 0.338930
  • wrapped-stethWrapped stETH (WSTETH) $ 5,271.43
  • chainlinkChainlink (LINK) $ 23.60
  • hyperliquidHyperliquid (HYPE) $ 55.45
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,692.94
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 113,905.00
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • suiSui (SUI) $ 3.61
  • avalanche-2Avalanche (AVAX) $ 29.12
  • figure-helocFigure Heloc (FIGR_HELOC) $ 0.992553
  • stellarStellar (XLM) $ 0.382788
  • wrapped-eethWrapped eETH (WEETH) $ 4,677.48
  • bitcoin-cashBitcoin Cash (BCH) $ 581.65
  • wethWETH (WETH) $ 4,351.66
  • hedera-hashgraphHedera (HBAR) $ 0.233515
  • litecoinLitecoin (LTC) $ 116.34
  • leo-tokenLEO Token (LEO) $ 9.56
  • crypto-com-chainCronos (CRO) $ 0.259379
  • the-open-networkToncoin (TON) $ 3.15
  • usdsUSDS (USDS) $ 0.999393
  • shiba-inuShiba Inu (SHIB) $ 0.000013
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 114,024.00
  • polkadotPolkadot (DOT) $ 4.22
  • whitebitWhiteBIT Coin (WBT) $ 43.18
  • uniswapUniswap (UNI) $ 9.75
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.200299
  • ethenaEthena (ENA) $ 0.783201
  • moneroMonero (XMR) $ 268.99
  • mantleMantle (MNT) $ 1.49
  • aaveAave (AAVE) $ 300.64
  • bitget-tokenBitget Token (BGB) $ 4.92
  • daiDai (DAI) $ 0.999779
  • pepePepe (PEPE) $ 0.000011
  • okbOKB (OKB) $ 193.25
  • worldcoin-wldWorldcoin (WLD) $ 1.84
  • memecoreMemeCore (M) $ 2.06
  • nearNEAR Protocol (NEAR) $ 2.71
  • bittensorBittensor (TAO) $ 344.82