Flash News

Bitcoin Holder Loses $750,000 After Google Account Hacked Following Transfer from Coldcard to Exchange

According to GoPlus monitoring, a Bitcoin holder safely transferred assets from a Coldcard MK4 hardware wallet to a centralized exchange, avoiding the risk of the hardware wallet itself being stolen.

Less than 12 hours after the transfer was completed, their Google account was hacked due to enabling Google verification cloud sync, leading to the exchange account being logged into and approximately $750,000 in Bitcoin being emptied.

GoPlus pointed out that such attacks typically do not rely on brute force but are achieved through social engineering phishing and weak password cracking.

Common pathways include: phishing pages inducing input of Google passwords, malicious browser plugins or cracking software stealing cookies and passwords, weak password reuse being cracked, and recovery email or phone number being taken over to reset passwords.

GoPlus recommends enabling hardware keys or Passkeys for Google accounts, disabling verification cloud sync, using a dedicated email for exchanges, and enabling withdrawal whitelists.

At the market mechanism level, the risk avoidance of hardware wallets concentrates assets in centralized exchanges, amplifying account takeover risks. Fund flows emphasize the importance of multiple independent verifications and offline 2FA security practices. The incident drives users to reassess cloud sync and password management, with both hardware wallets and exchanges under pressure for end-to-end security education.

Supplementary data shows that this case coincided with recent risk events related to Coldcard firmware, highlighting the secondary attack surface during the transfer process.

Source: Public Information

ABAB AI Insight

GoPlus, as an on-chain security monitoring agency, continues to track the cross risks between hardware wallets and centralized exchanges, having previously warned multiple times about 2FA and account takeover issues. Historical behavior shows its focus has expanded from contract risks to user operation links.

In terms of capital pathways, users migrate assets to exchanges to avoid potential vulnerabilities in hardware wallets, but the Google verification cloud sync creates a single point of failure. The motivation lies in pursuing convenience and liquidity, strategically neglecting the isolation of account systems and asset custody.

Similar cases can be seen where users hurriedly transfer assets due to vulnerabilities in other hardware wallets, leading to secondary losses, as well as exchange emptying incidents caused by Google account phishing. Current crypto security is transitioning from single-device protection to full-link account isolation.

The structural judgment belongs to technical substitution: because cloud sync 2FA rebinds originally independent verification factors to an account system vulnerable to social engineering attacks, it effectively nullifies the offline advantages of hardware wallets after transfer, forcing security practices to shift from device-level to strict separation of accounts and recovery pathways.

ABAB News · Cognitive Law

  1. Risks do not end after transfer completion
  2. Cloud sync turns 2FA into a single point of failure
  3. Social engineering phishing is more efficient than brute force attacks.

Source

·ABAB News
·
4 min read
·1d ago
分享: