Highlights:
- Coibase hacker moved $42.5M in crypto and mocked ZachXBT with a message.
- Coinbase breach hit 69,400 users after hacker bribed a support agent.
- U.S. officials are now investigating as Coinbase warns of big losses.
The individual responsible for one of the Coinbase hacks has resurfaced with a bold set of transactions. According to onchain sleuth and blockchain analyst ZachXBT, the hacker swapped $42.5 million worth of Bitcoin (BTC) for Ethereum (ETH) on May 22 using Thorchain, a decentralized protocol that enables cross-chain swaps without intermediaries.
According to ZachXBT, the hacker accused of stealing Coinbase user data swapped approximately $42.5 million worth of BTC for ETH via Thorchain and left a taunting message on-chain. The hacker had previously bribed a customer service agent to obtain information on nearly 97,000…
— Wu Blockchain (@WuBlockchain) May 22, 2025
Hacker Taunts ZachXBT
In the crypto community, ZachXBT is well known for exposing hacks, frauds, and scams. The latest activity was first shared by ZachXBT through a post on the Investigations Telegram channel. The hacker posted an on-chain message saying “L bozo,” seemingly directed at ZachXBT.
The term blends online slang, where “L” means loser and “bozo” refers to a silly or foolish person. The hacker appeared to mock ZachXBT by placing this message on the blockchain. It was also likely meant as a sign of disrespect toward those trying to catch them. The message also included a link to a YouTube meme video featuring NBA legend James Worthy smoking a cigar, further emphasizing the taunting nature of the act.
The hacker swapped 8,698 ETH for $22.12 million in DAI, a stablecoin tied to the US dollar. This happened soon after exchanging BTC for ETH. The move helped the hacker secure their funds’ value. It also started discussions about privacy and money laundering on the blockchain.
#PeckShieldAlert The threat actor who stole $300M+ from #Coinbase users by bribing customer support and sending #ZachXBT on-chain msg has swapped 8,697 $ETH for 22M DAI.
Another highly relevant address, which received 9,081 $ETH from #THORChain, has swapped them for 23M DAI. pic.twitter.com/nUWZbCfz0R— PeckShieldAlert (@PeckShieldAlert) May 22, 2025
Despite increased monitoring and advanced tools to track cryptocurrency transfers, the attacker continues moving large amounts of money undetected. This situation underscores the difficulties in recovering stolen funds and the limitations in enforcing rules within decentralized finance (DeFi) systems.
Coinbase Data Breach Exposes 69,461 Users
Last week, Coinbase revealed a hacker bribed a customer service agent to access user accounts. The stolen data included government-issued IDs and possibly email addresses. Passwords and private keys remained safe and were not compromised. After gaining access, the hacker demanded a $20 million ransom.
The attacker threatened to sell the data or use it for phishing and social engineering attacks. Coinbase declined to pay and offered a $20 million bounty to catch the hacker. Last week, Coinbase admitted that more than 69,461 users were affected by a data breach in December last year. The company found the breach on May 11, as stated in a report to the Maine Attorney General’s office.
BREAKING: 🇺🇸 COINBASE REVEALS 69,461 USERS WERE IMPACTED BY A DATA BREACH IN DECEMBER 2024 🔐 pic.twitter.com/W6j7jjeery
— The Moon Show (@TheMoonShow) May 21, 2025
At the same time, the U.S. Department of Justice has launched an official investigation into the Coinbase security breach. Coinbase believes the breach may result in up to $400 million in combined direct and indirect losses.
Paul Grewal, Coinbase’s chief legal officer (CLO), said:
“We have notified and are working with the DOJ and other US and international law enforcement agencies and welcome law enforcement’s pursuit of criminal charges against these bad actors.”
Best Crypto Exchange
- Over 90 top cryptos to trade
- Regulated by top-tier entities
- User-friendly trading app
- 30+ million users
eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.