BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Policy

Coinbase text scam: the withdrawal code that cost $57,000

The most dangerous thing about the Coinbase text scam is that the code in the message is real. Not spoofed, not fabricated — a genuine Coinbase withdrawal code, generated seconds earlier beca

AnonymousCryptoCompass newsroom
July 24, 2026
13 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for policy coverage.

5 Signs AI Phishing Has Compromised Your Web3 Social Media Account

The most dangerous thing about the Coinbase text scam is that the code in the message is real. Not spoofed, not fabricated — a genuine Coinbase withdrawal code, generated seconds earlier because the attacker already had your email and password and triggered it themselves. Every guide telling you to "look for the fake code" has the mechanism backwards, and that misunderstanding is why the attack works on people who consider themselves careful. If you receive an unexpected Coinbase withdrawal code by SMS, the correct response is not to inspect it. It is to assume your credentials are already compromised, ignore any phone number in the message, open the Coinbase app yourself, and change your password. Coinbase does not send unsolicited withdrawal codes, and it never asks you to read one back to a support agent.

Here is the part the security coverage has missed, and it is visible in search data rather than incident reports. Americans now run roughly 98,000 searches a month across the four main variants of this query — 38,000 for "coinbase text scam", 33,000 for "coinbase withdrawal code text", 14,000 for "coinbase scam text" and 13,000 for "coinbase withdrawal code" (Ahrefs, US, July 2026). That is a real-time fraud telemetry feed, and it is running roughly eighteen months ahead of the official statistics: the Federal Trade Commission's imposter-scam report published in June 2026 covers calendar-year 2025. Meanwhile the supply of defensive information is close to zero. The two YouTube videos specifically targeting the query, published on 1 and 2 July 2026, have 3 views and 14 views between them. Search demand is screaming and the answer side is empty — a gap that, in every other fraud wave, has been filled by the scammers themselves.

Key facts

• Americans lost $3.5 billion to imposter scams in 2025, with reported losses up nearly threefold since 2020 — FTC, June 2026 • Nearly one in three fraud reports to the FTC in 2025 were imposter scams — FTC • Coinbase customers lost $65 million to social-engineering scams in the two months from December 2024 to January 2025, and an estimated $150 million across the prior year — ZachXBT via Benzinga, February 2025 • Individual documented losses include $850,000 from one victim and 110 cbBTC (about $11.5 million) from another — ZachXBT • Crypto-ATM scam losses rose 1,000% between 2020 and 2023 and reached $388 million in 2025 alone — FTC • A single victim of the fake Coinbase customer-care variant lost $57,000, documented on 6 July 2026 — DeepWatch Forensics • UK banks reimbursed 88% of money stolen through authorised push payment fraud — about £112 million — between 7 October 2024 and 30 June 2025 under mandatory rules. Crypto has no equivalent — PSR data via Edgar Dunn

What is actually happening, step by step

The attack has four stages, and only the first is technical.

Stage one: the attacker already has your credentials. They come from a prior breach, a credential-stuffing list, or an earlier phishing capture. This is why the scam feels so convincing — the criminal is not guessing that you have a Coinbase account, they know.

Stage two: they trigger a real withdrawal. Logging in with the stolen credentials, they initiate a withdrawal. Coinbase's systems do exactly what they should and send you a genuine verification code by SMS. From your side, an unexpected but authentic message from a real short code arrives on your phone.

Stage three: the manufactured panic. Seconds later, a second text — this one from the attacker — tells you a withdrawal is in progress and gives a number to call "to cancel". The urgency is the weapon. The victim is now frightened, holding a real code from a real company, and looking at a phone number that appears to be the way out.

Stage four: the read-back. The fake agent is calm, professional and reassuring. They ask you to confirm the code "to verify your identity and stop the transfer". Reading it aloud authorises the very withdrawal you are trying to stop.

The tell that actually works is structural rather than cosmetic. Legitimate Coinbase security messages arrive from short codes or official channels; the callback texts come from ordinary ten-digit mobile numbers. But the more reliable rule requires no forensics at all: no legitimate financial institution will ever ask you to read a security code back to a human being. A code exists precisely to prove that you, and only you, are holding the device.

This is the same structural pattern we documented when Robinhood users were hit by a phishing campaign exploiting a Gmail address quirk — the attacker does not break the security control, they recruit the victim to operate it on their behalf.

Quick take: The code is real. The urgency is fake. The number is the attack. If you did not initiate a withdrawal, the message is not a warning — it is evidence that someone already has your password.

What Coinbase and the wider industry are actually doing

Coinbase has moved on this, and its own security leadership has been unusually direct in public. Philip Martin, the exchange's Chief Security Officer, reduces the defence to two sentences that work regardless of how sophisticated the pretext becomes.

"When in doubt, don't act. Verify first."

Philip Martin, Chief Security Officer, Coinbase

The company has also pushed the problem outside its own perimeter, joining the Tech Against Scams coalition alongside Meta, Kraken and Ripple to attack fraud across social platforms, dating apps and job boards — the acquisition channels where victims are identified long before a text is ever sent. Martin's framing of that effort is that "the more we work together, the harder it becomes for scammers to succeed." In May 2025 the exchange also put a $20 million bounty on the group behind an extortion attempt tied to stolen customer data, and in June 2026 it joined a Department of Justice-led operation, which we covered when Coinbase helped freeze $3 million tied to a Southeast Asian scam network.

That is a genuine institutional response. It is also, on the evidence, not yet sufficient — and the most credible criticism comes from the on-chain investigator whose work first quantified the losses.

"Coinbase has struggled to implement effective countermeasures, leaving users vulnerable to the growing threats. Despite the scale of these attacks, Coinbase's response has been inadequate."

ZachXBT, blockchain investigator (Benzinga, February 2025)

His specific charges are operational rather than rhetorical: victims reported cases unresolved for weeks and generic or absent support responses, while the exchange's internal risk models produced aggressive restrictions on legitimate accounts without stopping the scams. He also found that theft addresses were not consistently flagged in compliance tooling, letting the same wallets keep receiving proceeds.

The asymmetry there is the real story for anyone running a platform. Risk systems tuned to block anomalous behaviour by legitimate users are close to useless against a transaction the account holder has personally authorised under duress. The attacker is not evading the control. The customer is opening the door.

The data: why crypto absorbs a loss that banking now refunds

Put the two regimes side by side and the divergence is stark. Both sectors face the same attack structure — a victim, socially engineered, authorising their own irreversible transfer. Only one has decided who pays.

 UK banking (APP fraud)US crypto exchangesAttack structureVictim authorises push payment under false pretextVictim authorises withdrawal under false pretextReimbursementMandatory since 7 October 2024None — treated as an authorised user actionCap£85,000 per claimn/aWho pays50/50 between sending and receiving firmThe victimSpeed5 business days (35 with investigation)n/aMeasured outcome88% of stolen funds returned (~£112m, Oct 2024–Jun 2025)$65m lost in two months, largely unrecovered

Sources: PSR reimbursement data; ZachXBT loss estimates. Figures cover different jurisdictions and periods and are not directly comparable; they are set against each other to show the liability structure, not to equate the markets.

The synthesis nobody has stated plainly: the UK did not solve authorised push payment fraud by teaching consumers to spot it. It solved a large share of the loss by moving liability onto the firms best placed to detect the pattern — and recovered 88% of stolen funds in the first nine months. Consumer education did not produce that number. Reallocated liability did.

Crypto's counter-argument is that an on-chain withdrawal is irreversible in a way a bank transfer is not, which is true at the settlement layer and mostly irrelevant at the decision layer. The moment the intervention needs to happen is before the withdrawal executes, not after — and exchanges hold exactly the signals that would allow it: a password change, a new device, a first-time withdrawal address, and a support call, all within a few minutes.

That combination is not subtle. It is the highest-confidence fraud signature available anywhere in consumer finance, and it currently triggers a verification code rather than a hold. For context on how the losses aggregate across the sector, see our reporting on how crypto exploits topped $370 million in January.

Quick take: UK banks recovered 88% of push-payment fraud losses by changing who pays, not by changing how carefully customers read texts. Crypto has not had that argument yet.

The regulatory tension

The FTC's June 2026 data makes the direction of travel unmistakable: $3.5 billion lost to imposter scams in 2025, reported losses up roughly threefold since 2020, and nearly one in three fraud reports now falling into the category. The agency singles out the exact pattern used here, noting that some of the costliest impersonation scams begin with a fake security alert that convinces people to move money in order to "protect" it — with losses "often limited only by their available funds."

That last clause is why crypto exposure is disproportionate. A bank account has a balance and a daily transfer limit. A self-custody-capable exchange account can be emptied in one instruction.

The tension is jurisdictional. The UK's Payment Systems Regulator imposed mandatory reimbursement on payment firms from 7 October 2024 with an £85,000 cap and a 50/50 split between sending and receiving institutions. The United States has no equivalent for crypto, and the FTC's authority is largely enforcement and education after the fact rather than a duty to reimburse. Government imposter reports rose 40% even so, driven partly by spoofed toll-payment messages — evidence that awareness campaigns are losing ground to volume.

There is a reasonable case against simply importing the UK model. Mandatory reimbursement creates moral hazard, invites first-party fraud, and imposes costs that ultimately reach honest customers. The £15.3 million that remained permanently unreturned even under the UK regime shows it is not a complete fix. But the current US position — that a code read aloud under duress constitutes informed authorisation — is not a considered policy. It is the absence of one.

What happens next

Three predictions, with the reasoning attached.

The SMS channel gets abandoned for withdrawal confirmation, and sooner than expected. The read-back attack works because a code can be spoken. Passkeys and in-app approvals cannot be read aloud down a phone line, which removes the vector rather than mitigating it. Expect major exchanges to make app-based approval the default for withdrawals within the next 12–18 months, with SMS retained only as an account-recovery fallback. The trigger will be a single large publicised loss, not a regulation.

Withdrawal delays become a competitive feature rather than a friction cost. A mandatory hold on a first-time withdrawal address following a recent password change costs an exchange almost nothing in legitimate volume and breaks this attack entirely. The firm that ships it will market it. The economics already favour it: reputational damage plus support load from a single six-figure loss exceeds the revenue from the delayed transactions many times over.

US reimbursement pressure arrives through litigation before legislation. With no statutory duty, the pathway runs through the courts — and the template already exists, as when an investor sued over losses tied to a phishing attack. Expect the argument to shift from "was the user negligent" to "did the platform ignore a detectable fraud signature", which is a much harder question for exchanges to answer given the signals they hold.

For the individual reader, none of that helps this week. The rule that does: an unexpected withdrawal code is not a warning to act on, it is proof that someone already has your password. Close the message, open the app yourself, and change it.

Frequently asked questions

Is the Coinbase withdrawal code text a scam? The text containing the code is usually genuine — Coinbase sent it because someone triggered a withdrawal using your credentials. The scam is the second message urging you to call a number to cancel. Coinbase does not send unsolicited withdrawal codes and never asks you to read one back to an agent.

What should I do if I get a Coinbase scam text? Do not call any number in the message. Open the Coinbase app or type the address yourself, change your password immediately, and check active sessions and withdrawal addresses. Assume your credentials are already compromised, because a genuine withdrawal code means someone logged in successfully.

How do I spot a fake Coinbase text? Legitimate Coinbase security messages come from short codes or official channels, not ordinary ten-digit mobile numbers. But the reliable rule needs no inspection: no financial institution will ever ask you to read a security code aloud. A code proves you hold the device, so sharing it defeats its only purpose.

How much money is being lost to these scams? Coinbase customers lost an estimated $65 million to social-engineering scams in the two months from December 2024 to January 2025, and about $150 million over the prior year, according to investigator ZachXBT. Across all imposter scams, the FTC recorded $3.5 billion in US losses during 2025.

Will Coinbase refund a scam withdrawal? Generally no. Because the victim authorises the transaction, exchanges treat it as a legitimate user instruction. This differs sharply from UK banking, where mandatory reimbursement rules since October 2024 returned 88% of authorised push payment fraud losses. No equivalent obligation exists for US crypto platforms.

Why do scammers ask for the code instead of stealing it? They cannot intercept it. The code is sent to your device by Coinbase, so the only route is persuading you to hand it over. That is why the pretext always involves urgency and a callback number — the entire operation exists to get you to speak six digits aloud.