Highlights:
- A New York man posed as Coinbase support and stole over $4 million by tricking users into using fake seed phrases.
- ZachXBT linked the stolen funds to Roobet, where the scammer gambled away most of the crypto using a known alias.
- Coinbase added stricter ID checks and wallet approval delays after a data breach exposed thousands of user accounts.
A New York-based scammer has been accused of stealing over $4 million from Coinbase users using deceptive phone calls and fake support tactics. Blockchain investigator ZachXBT identified the man as Christian Nieves, known online as “Daytwo” and “PawsOnHips.” He reportedly ran a phone-based scam that targeted unsuspecting users by pretending to be from Coinbase.
1/ An investigation into how the New York based social engineering scammer Daytwo/PawsOnHips (Christian Nieves) stole $4M+ from Coinbase users by impersonating customer support, bought luxury goods, and lost most of the funds gambling at casinos. pic.twitter.com/7PsP8ymPtO
— ZachXBT (@zachxbt) June 23, 2025
Nieves operated a small call center and made direct calls to victims. He warned them about fake suspicious activity on their accounts and advised them to act quickly. During the calls, he instructed users to create new Coinbase wallets using seed phrases that he provided. Once funds were deposited, the scammer drained the wallets almost immediately.
Many users believed they were protecting their crypto. In reality, they gave full control to the scammers. One victim lost $240,000 in a single call, which was recorded through Discord. ZachXBT reported that more than 30 victims were affected in total. The fraudster did not use code-based malware. Instead, he used persuasive language and gave real-time instructions. Users performed the transfers directly, so Coinbase’s internal systems did not flag the transactions as suspicious.
Roobet Gambling Trail Unmasks Coinbase Phishing Scam Operator
ZachXBT investigated the list and linked it directly to a Roobet casino account with the username pawsonhips. A blockchain trail indicated that the stolen crypto went into this account. The similarity between the unique username and one Nieves used on Discord helped the investigator connect his online identity to his Roobet account.
Nieves did not seem concerned that he would be recognized. He would appear in the Discord calls frequently and share photos in luxury clothes on social media. Analysts used on-chain data to link the purchases to the stolen crypto funds. ZachXBT found out that Nieves usually gambled with the stolen funds through Discord voice chats. He made huge bets in real time by using the money of victims unhesitantly. The wallet activity analysis revealed that he transferred the money rapidly and lost it within minutes.
He converted the unspent money into Monero, a privacy coin. He used this to conceal the origin of the funds, but the deposit address on Roobet still linked the activity to Nieves. Overlapping usernames and repeated wallet behavior made the tracing process more straightforward.
Coinbase Strengthens Security After Data Breach
Coinbase introduced new security steps last month after it faced a large data breach involving over 69,000 users. The platform reported that rogue support agents from a third-party vendor had leaked sensitive customer information. Coinbase reacted by instituting increased restrictions on account withdrawals and user identification.
The firm has introduced additional identity verification for large transfers. It also prompts users to turn on the delay in approvals and their allowlisting of wallets. The purpose of these procedures is to ensure scammers cannot transfer money fast after they obtain access. The Coinbase phishing scam showed the vulnerability of technical systems to social strategies.
Best Crypto Exchange
- Over 90 top cryptos to trade
- Regulated by top-tier entities
- User-friendly trading app
- 30+ million users
eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.