Scam Alert: Fake Coinbase ERC20 Support Email Attempts to Phish Private Keys

Published on by Cryptoslate | Published on

Mentioned in this article
A new phishing email targeting Coinbase users has recently emerged, and appears to be one of the most sophisticated Coinbase phishing attempts to date.

Reports from the cryptocurrency community show that the new scam email is attempting to capitalize on Coinbase's recent announcement of ERC20 token support.

Coinbase announced its intent to integrate ERC20 tokens in a medium post last month, stating that support for the technical standard would be implemented in the "Coming months." The scam email attempts to lure less technically adept crypto investors and traders with a fake announcement that Coinbase ERC20 support is now here, presenting Coinbase users with a complex and convincing phishing operation that is likely to succeed in duping many readers.

"Users are now able to import their ERC-20 tokens to their Coinbase accounts, after which you will also be able to trade them on the GDAX exchange. To begin importing your tokens please follow the steps provided."

The scammers behind the Coinbase phishing email have even included a direct link to the Coinbase blog ERC20 support announcement, which reinforces the credibility of the email.

Following the link provided within the email leads Coinbase users to a process that attempts to "Import private keys" - a process that will definitely result in the loss of any tokens contained within associated wallets.

More concerningly, the fraudulent email links Coinbase users to a well-constructed phishing website that is nearly indistinguishable from the real thing - "Coínbasé" dot com, instead of Coinbase.

Although it should be common sense, it's important to note that you should definitely not provide your Coinbase login details or private key data to either the site linked in the fake Coinbase email or during the fraudulent "Token importing process".

As of this report, there have been no official statements from Coinbase regarding the scam email.

It should be noted that the email has been received by individuals that don't possess a Coinbase account or to emails that aren't associated with Coinbase accounts, so at this stage it's unlikely that the campaign is a result of a data leak from Coinbase itself.

x