On-chain data shows continued movement of funds associated with long-running social engineering campaigns that have targeted Coinbase users. An investigator posted details of recent transfers from a consolidation address that multiple analysts have publicly linked to these thefts.
On October 8, 2026, investigator VAL, posting as @osint_based, reported activity from the address 0xC84C…Ab84. According to the post, roughly $1.11 million was moved from one associated consolidation wallet, swapped into ETH, and sent to Tornado Cash three days earlier.
Separately, 8.3 ETH moved to another wallet and was bridged to Hyperliquid, where it purchased the spot token XMR1. The same address still holds about $16 million that has sat untouched for roughly a year.
Data tracked by Arkham shows several transactions from about three days prior, including multiple 100 ETH deposits to Tornado Cash Router contracts and the 8.3 ETH transfer. The same address is viewable on Etherscan, where historical counterparties and token movements can be checked directly. Earlier in 2025 the address drew notice when analysts recorded large ETH sales and an on-chain message directed at another investigator.
Tornado Cash operates as a non-custodial protocol whose smart contracts accept fixed-size deposits and later permit withdrawals that break the direct on-chain connection between the depositing and withdrawing addresses.
U.S. Treasury sanctions placed on the protocol in 2022 were removed in March 2025 after a review of the legal and policy questions involved, according to the Treasury announcement.
Scale of Social Engineering Losses Reported by Investigators
The wallet activity occurs against estimates published by on-chain analyst ZachXBT. In a February 3, 2025 thread, ZachXBT stated that Coinbase users were losing more than $300 million per year to social engineering scams. The thread included a table estimating $65 million taken between December 2024 and January 2025, drawn from direct messages and on-chain withdrawals reviewed by the analyst and a collaborator. The described methods involved callers using spoofed numbers and personal details from data breaches, then steering victims toward cloned sites or Coinbase Wallet flows that transferred control of the assets.
Later updates on Telegram from the same analyst in March 2025 cited further losses above $46 million in one month, including sizable Bitcoin transfers. These amounts reflect cumulative estimates across many separate incidents rather than a single confirmed total controlled by one identified person. Coinbase has noted its work with law enforcement on specific impersonation cases and has described social engineering as the source of most customer losses.
Separate cases have produced criminal outcomes. In September 2026 a Brooklyn man received a sentence of four to twelve years after pleading guilty in a scheme prosecutors said took nearly $16 million from about 100 Coinbase users through support impersonation, as covered in reporting on the Brooklyn sentencing.
Indian authorities have also followed proceeds from fake Coinbase sites in other matters, detailed in an account of the ₹64.55 crore tracing. These actions show that some operators face charges while larger volumes remain observable on public addresses.
Privacy Protocols and Remaining Traceability
Deposits into Tornado Cash and the bridge to Hyperliquid for an XMR1 purchase match patterns analysts often see when parties try to reduce the visibility of later transfers. XMR1 trades against USDC on Hyperliquid; the purchase itself does not reveal the final location of the funds. Because Tornado Cash pools combine deposits of the same size, a later withdrawal cannot be matched to a specific deposit from on-chain data alone.
Consolidation addresses, repeated wallet use, and bridging steps stay visible on public ledgers. Analysts have continued to flag the same clusters months or years after the initial losses. Coinbase has stated that it cooperates with investigators and law enforcement to trace funds in impersonation cases, including a public note on assistance provided in one Brooklyn matter.
The combination of ongoing ledger monitoring and occasional prosecutions has produced asset recovery in particular cases alongside continued movement from addresses investigators still associate with the wider activity.
The transfers reported on October 8 do not show that the full annual loss estimate has been gathered in one location, nor do they settle how much of the historically cited volume remains with the original actors. They do confirm that addresses previously highlighted in connection with these campaigns continue to execute swaps, mixer deposits, and cross-chain moves that appear in real time on public blockchains.
Also read: SlowMist Flags BitBay and EtherVista Hacks as Attackers Drain $32,600 From DeFi Vault & Pool
