Bitcoin Forum

Economy => Service Discussion => Topic started by: ajw7989 on April 08, 2015, 06:37:42 PM



Title: Coinbase Investment fund email?
Post by: ajw7989 on April 08, 2015, 06:37:42 PM
Anyone else just get an email from news@coinbase.com about an investment fund? Sounds too good to be true.

Code:
In This Issue:
        Get 150% profit with Coinbase Invest Fund

Dear ajw7989,

We're happy to announce a new product - Coinbase Invest Fund, reliable platform for
small and medium scale investments. Fund assets are diversified among emerging Forex
positions at Coinbase Exchange. Deposits are risk-free insured by institutions such as the New
York Stock Exchange.

Want to become a professional investor?
Our first short-term investment program starts today - GET 150% FOR A 10-DAY DEPOSIT.

Investment offer is active from 20th of April 12:00 AM Pacific until 30th of April.
Coinbase offers you a fixed return with a 50% growth for a 10 day period.
You can deposit today from $100. Maximum deposit amount per one person
or legal entity is 60 Bitcoins. That's an astonishing opportunity to earn up to $8,500 per 10 days!

Investors who want to apply, please make a deposit to

         1LzobTyP2RpfgBq8H59E25dibtNpKvb69J or click the link below
         https://blockchain.info/qr?data=1LzobTyP2RpfgBq8H59E25dibtNpKvb69J&size=400

Once a payment is made you will get an e-mail about successful participation.
Please note: Initial deposit amounts exceeding +30 Bitcoins will qualify your membership for a 2nd level upgrade.

We will return your initial deposit with dividends on 1st of May, 2015 12:00 AM Pacific Time.
(for example: investing 10 Bitcoins today will return 15 Bitcoins in a 10 day period)
Profits are withdrawn without any delay and Coinbase waives all fees for 1st level investments.

Hurry up! This is a limited, one-time opportunity.

Kind regards,
The Coinbase Invest Fund Team

Do not reply to this e-mail


Title: Re: Coinbase Investment fund email?
Post by: marcotheminer on April 08, 2015, 06:45:28 PM
Seems really sketchy, absolutely not from CoinBase.

What annoys me is how did these scammers get access to CoinBase's users' emails (CoinBase's fault?).


Title: Re: Coinbase Investment fund email?
Post by: bernard75 on April 08, 2015, 06:51:17 PM
It is not their database that was hacked.
I use this mail for sensitive things only but i never registered at Coinbase.


Title: Re: Coinbase Investment fund email?
Post by: Morton Bitcoin Management on April 08, 2015, 06:55:59 PM
I received the same email too ???


Title: Re: Coinbase Investment fund email?
Post by: SirChiko on April 08, 2015, 06:58:01 PM
It isn't from coinbase...tons of users got it.
I just don't get how come that i use coinbase too but i didn't get that e-mail.


Title: Re: Coinbase Investment fund email?
Post by: Zombie123 on April 08, 2015, 06:59:51 PM
Yea I got it too. Obviously fraud


Title: Re: Coinbase Investment fund email?
Post by: ajw7989 on April 08, 2015, 07:01:28 PM
The red flag for me and any phishing emails is the fact that they addressed me by my username but whenever you make a deposit or withdrawal you get a confirmation email which uses your first name. What is strange though is its from news@coinbase.com but if you dig deeper it says mailed by    em.coinbase.com and signed by    coinbase.com when the other emails are both mailed and signed by coinbase.com


Title: Re: Coinbase Investment fund email?
Post by: tjwebb on April 08, 2015, 07:04:49 PM
I got the same email. Seems legit. LOL

Also, excuse me while I move all my coin out of coinbase...


Title: Re: Coinbase Investment fund email?
Post by: allyouracid on April 08, 2015, 07:06:52 PM
The red flag for me and any phishing emails is the fact that they addressed me by my username but whenever you make a deposit or withdrawal you get a confirmation email which uses your first name. What is strange though is its from news@coinbase.com but if you dig deeper it says mailed by    em.coinbase.com and signed by    coinbase.com when the other emails are both mailed and signed by coinbase.com
It's strange, indeed. I wonder where they have my full name (firstname+lastname) from. I may have registered at coinbase, but I never used it, because it's not supported in Germany.

I think we all must have something in common, here. Any service we have registered to, which maybe sells the data of its users, or maybe was hacked… ideas, anyone?


.edit:
Too bad they're using different BTC addresses for each recipient. Would be interesting to see how much money they got, already. Seems that some guys were not as stupid as most other scammers here!


Title: Re: Coinbase Investment fund email?
Post by: LongJohnJake on April 08, 2015, 07:08:19 PM
Seems really sketchy, absolutely not from CoinBase.

What annoys me is how did these scammers get access to CoinBase's users' emails (CoinBase's fault?).


Following is from Coinbase online chat.  Cannot believe how nonchalant they are about this whole incident!

"Now Chatting
Seth: Hi there! What can I help you with today?
→Got your News message about the investment product. Please supply more information, such as a Prospectus.
Seth: That appears to be a scam email. It's not from us.
→So how did they get my username and your domain?
Seth: That is beyond my technical understanding, I'm afraid.
→Good god, man!! Your site got hacked and that's the best you can say!!
→Wait til I blog that moronic response!
Seth: I do not believe our site has been hacked. But feel free to do what you want. Have a nice day!"


Title: Re: Coinbase Investment fund email?
Post by: allyouracid on April 08, 2015, 07:10:47 PM
Seems really sketchy, absolutely not from CoinBase.

What annoys me is how did these scammers get access to CoinBase's users' emails (CoinBase's fault?).


Following is from Coinbase online chat.  Cannot believe how nonchalant they are about this whole incident!

"Now Chatting
Seth: Hi there! What can I help you with today?
→Got your News message about the investment product. Please supply more information, such as a Prospectus.
Seth: That appears to be a scam email. It's not from us.
→So how did they get my username and your domain?
Seth: That is beyond my technical understanding, I'm afraid.
→Good god, man!! Your site got hacked and that's the best you can say!!
→Wait til I blog that moronic response!
Seth: I do not believe our site has been hacked. But feel free to do what you want. Have a nice day!"
If someone ranted to me in such a threatening tone, without even knowing the facts, I wouldn't have been more kindly, either, to be honest.


Title: Re: Coinbase Investment fund email?
Post by: jus341 on April 08, 2015, 07:17:56 PM
Response I got from Coinbase:
Quote
Hi there,

My apologies for the inconvenience here, we are currently investigating this and are in the process of getting it shut down. This is NOT an official Coinbase email, please DO NOT click any links or otherwise engage with this communication. Thank you for forwarding.

-Alex H
Supervisor


Title: Re: Coinbase Investment fund email?
Post by: lexico on April 08, 2015, 07:20:26 PM
got it too.
Never registered at coinbase.
The only btc related stuff I registered to with that email address is Bitcointalk, Localbitcoins and Kraken (and havent used these in more than a year).  
[edit: perhaps Gox. not sure...]
So it is probably one of these that had their memberslist leaked/hacked.
(Or.. one of these fuckers sold their data)


Title: Re: Coinbase Investment fund email?
Post by: dboldt on April 08, 2015, 07:22:34 PM
I used to get a lot of random 1 satashi deposits from people I didn't know.  I think if someone sends you BTC on coinbase they can then see your email address and username.  I suspect someone sent out millions of 'free' satashis to harvest their email addresses and usernames.


Title: Re: Coinbase Investment fund email?
Post by: crazyivan on April 08, 2015, 07:23:06 PM
100% scam. I guess we have all registered for something and its not coinbase. Can anyone guess what that might be?


Title: Re: Coinbase Investment fund email?
Post by: bernard75 on April 08, 2015, 07:24:29 PM
Never registered at coinbase.
The only btc related stuff I registered to with that email address is Bitcointalk, Localbitcoins and Kraken (and havent used these in more than a year).  
So it is probably one of these that had their memberslist leaked/hacked.
(Or.. one of these fuckers sold their data)

I havent used this mail for any of those.


Title: Re: Coinbase Investment fund email?
Post by: erik__ on April 08, 2015, 07:31:50 PM
Received it on my gmail account.  Obvious scam.  The only thing I wonder about is how it managed to dodge Google's spam/scam filters.


Title: Re: Coinbase Investment fund email?
Post by: lexico on April 08, 2015, 07:38:17 PM
Received it on my gmail account.  Obvious scam.  The only thing I wonder about is how it managed to dodge Google's spam/scam filters.

Check the email headers.
I don't know how DNS spoofing/hacking works, so I cant tell the details, But from here it it looks like this actually comes from coinbase servers.


Title: Re: Coinbase Investment fund email?
Post by: OnkelPaul on April 08, 2015, 07:41:07 PM
Extremely interesting - they seem to be using coinbase's mail infrastructure, here are some headers from the mail that I got:

Received: from o1.em.coinbase.com (o1.em.coinbase.com [50.31.37.137])
   (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits))
   (No client certificate requested)
   by xxx (mail service) with ESMTPS id xxxx
   for <xxx>; Wed,  8 Apr 2015 xx:xx:xx +xxxx (xxx)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed; d=coinbase.com;
   h=content-type:mime-version:content-transfer-encoding:from:to:subject;
   s=smtpapi; bh=xxxx; b=xxxx
Received: by filterxxx.sendgrid.net with SMTP id filterxxxx
        2015-04-08 xx:xx:xx.xxxxxxxx +0000 UTC
Received: from xxxx (unknown [5.101.xx.xx])
   by ismtpd-008 (SG) with HTTP id xxxx
   for <xxx>; Wed, 08 Apr 2015 xx:xx:xx +0000 (UTC)

(xxx'd all identifying information)

Maybe a hacked coinbase employee mail account?
The original source of the HTTP request is a DigitalOcean IP address, presumably a VPS. I don't know whether the whole run was sent from that IP, if it was, xxxing does not make much sense of course as it is not specific to me.

Onkel Paul


Title: Re: Coinbase Investment fund email?
Post by: lexico on April 08, 2015, 07:46:15 PM
...

mine looks the same.

hacked user account (news@coinbase.com) is an option.
Still the question of how they got my emailaddress.


Title: Re: Coinbase Investment fund email?
Post by: allyouracid on April 08, 2015, 07:47:30 PM
got it too.
Never registered at coinbase.
The only btc related stuff I registered to with that email address is Bitcointalk, Localbitcoins and Kraken (and havent used these in more than a year).  
So it is probably one of these that had their memberslist leaked/hacked.
(Or.. one of these fuckers sold their data)
I am registered here (as you can see), but they don't have my first- and/or lastname, I think. I might have an account at localbitcoins, maybe with my name. I am not registered at Kraken.

Was there anything else? BTCJam maybe? Or any other exchange, Mt.Gox maybe? Their database is publicly available.


Title: Re: Coinbase Investment fund email?
Post by: to3m on April 08, 2015, 07:48:09 PM
I got one of these today. It was sent to my BTC-E email address. (I have my own domain, so I sign up with every service under a different email address.)

I wonder how they got hold of that?

--Tom


Title: Re: Coinbase Investment fund email?
Post by: bernard75 on April 08, 2015, 07:49:07 PM
got it too.
Never registered at coinbase.
The only btc related stuff I registered to with that email address is Bitcointalk, Localbitcoins and Kraken (and havent used these in more than a year).  
So it is probably one of these that had their memberslist leaked/hacked.
(Or.. one of these fuckers sold their data)
I am registered here (as you can see), but they don't have my first- and/or lastname, I think. I might have an account at localbitcoins, maybe with my name. I am not registered at Kraken.

Was there anything else? BTCJam maybe? Or any other exchange, Mt.Gox maybe? Their database is publicly available.

Goxed again.  >:(


Title: Re: Coinbase Investment fund email?
Post by: allyouracid on April 08, 2015, 07:51:14 PM
I got one of these today. It was sent to my BTC-E email address. (I have my own domain, so I sign up with every service under a different email address.)

I wonder how they got hold of that?

--Tom
Very clever!
This would make the origin of the problem pretty much clear. On the other hand, while BTCe is a bit shady, I cannot explain how the connection to the mails being sent through coinbase servers can be drawn…


Title: Re: Coinbase Investment fund email?
Post by: bernard75 on April 08, 2015, 07:56:26 PM
I got one of these today. It was sent to my BTC-E email address. (I have my own domain, so I sign up with every service under a different email address.)

I wonder how they got hold of that?

--Tom

Never registered at coinbase.
The only btc related stuff I registered to with that email address is Bitcointalk, Localbitcoins and Kraken (and havent used these in more than a year).  
So it is probably one of these that had their memberslist leaked/hacked.
(Or.. one of these fuckers sold their data)

I havent used this mail for any of those, including BTCJam.
I used it for Gox though.
It must be multiple sources.


Title: Re: Coinbase Investment fund email?
Post by: to3m on April 08, 2015, 07:59:34 PM
I got one of these today. It was sent to my BTC-E email address. (I have my own domain, so I sign up with every service under a different email address.)

I wonder how they got hold of that?

--Tom
Very clever!
This would make the origin of the problem pretty much clear. On the other hand, while BTCe is a bit shady, I cannot explain how the connection to the mails being sent through coinbase servers can be drawn…

Yes, you're right - there are one or two very obvious explanations for this :) But I have no opinion about what has actually happened here.

I've sent a support request to BTC-E, which seems like an obvious first thing to do. If I hear anything back, I'll post here.

--Tom


Title: Re: Coinbase Investment fund email?
Post by: timeofmind on April 08, 2015, 08:06:38 PM
"Authentication-Results: mx.google.com;
       spf=pass (google.com: domain of bounces+1604765-1070-timeofmind=gmail.com@em.coinbase.com designates 50.31.37.137 as permitted sender)"

Either coinbase mail server was used, or the their DNS server was accessed and SPF record altered.


Title: Re: Coinbase Investment fund email?
Post by: gbl08ma on April 08, 2015, 08:18:19 PM
I too received the email (went into Gmail spam, with a note about being flagged as spam by other users but nothing about phishing). Just like others have reported, as far as the headers are concerned, it looks like it was sent by the legitimate Coinbase servers.
 - The email address where I received the message was "leaked" by a stupid Bitcoin-related service some months ago when they sent an email to all of their users and put everyone's email in the "to" field (endless spam since then);
 - I don't have a BTC-e account with this email address;
 - I have a Coinbase account, with this email address, which I created for the sole purpose of receiving the free BTC they were giving away at launch, and is abandoned since then;
 - I had a (never used) MtGox account on this email address.

Since there are people reporting to have received the phishing mail on a address used solely for BTC-E, but I don't have a BTC-E account on the address where I received it, probably whoever sent the emails is using a list built from various sources.


Title: Re: Coinbase Investment fund email?
Post by: GH on April 08, 2015, 08:25:31 PM
I received two mails. The sources of the recipient addresses are 100% clear in my case, as I also use one-time accounts.
First one was to my btcjam account, second one to bitcoin-24(!).


Title: Re: Coinbase Investment fund email?
Post by: bernard75 on April 08, 2015, 08:28:08 PM
Yup, used it for btc24, too.
This dirtbag will do anything to pump the community...


Title: Re: Coinbase Investment fund email?
Post by: Azzot88 on April 08, 2015, 08:29:04 PM
Hi! Im received same email. I have  account at BTC-E and i received this wallet to send 1GX1tPvy4Y3PUeHzzpvtkWeyzhskVKTpf6

What wallet you are received? Maybe we will find correlation between exchanges and wallets from scam emails?


Title: Re: Coinbase Investment fund email?
Post by: bernard75 on April 08, 2015, 08:30:13 PM
Everybody gets different wallets, at least in my 2 cases.


Title: Re: Coinbase Investment fund email?
Post by: allyouracid on April 08, 2015, 08:33:53 PM
I got one of these today. It was sent to my BTC-E email address. (I have my own domain, so I sign up with every service under a different email address.)

I wonder how they got hold of that?

--Tom
Very clever!
This would make the origin of the problem pretty much clear. On the other hand, while BTCe is a bit shady, I cannot explain how the connection to the mails being sent through coinbase servers can be drawn…

Yes, you're right - there are one or two very obvious explanations for this :) But I have no opinion about what has actually happened here.

I've sent a support request to BTC-E, which seems like an obvious first thing to do. If I hear anything back, I'll post here.

--Tom
That would be very much appreciated. Would be nice if we get this solved… I don't like the idea of my data moving around uncontrollably (yes… the internet, but I guess you know what I mean). :)


Title: Re: Coinbase Investment fund email?
Post by: tunnez777 on April 08, 2015, 09:30:39 PM
I received the same email, this is scammers, if Coinbase have any business opportunity related to btc they whould have post it on their official website.


Title: Re: Coinbase Investment fund email?
Post by: TheButterZone on April 08, 2015, 09:35:49 PM
Spamcop.net reported my copy to abuse@cox.net based on the sender's IP.


Title: Re: Coinbase Investment fund email?
Post by: nearmint on April 08, 2015, 10:47:51 PM
I also find it very interesting that the attacker is able to aggregate the e-mail addresses from different [database] sources. Doesn't this mean he has direct access to multiple bitcoin-related databases or at least some indirect way to extract e-mail addresses from the databases?



Title: Re: Coinbase Investment fund email?
Post by: bernard75 on April 08, 2015, 10:54:28 PM
Well the Gox database is practically open source, but some people insist they used their mail exclusively for BTCe, BTC24 or LBC, so its probably several databases that have been compromised.


Title: Re: Coinbase Investment fund email?
Post by: waterpile on April 08, 2015, 11:17:08 PM
I wonder if someone invested to it :(


Title: Re: Coinbase Investment fund email?
Post by: plasma1010 on April 08, 2015, 11:36:27 PM
Why isn't Coinbase issuing an email to all it's clients to watch out for the scam ? That's my problem with the whole thing, they should be informing everyone who is signed up at Coinbase right now not to invest in this scam.

The kicker for me was that the email didn't route to Coinbase actual website, just some random deposit link. I mean, I guess if you're brand new to Bitcoin you might fall for it.


Title: Re: Coinbase Investment fund email?
Post by: ajw7989 on April 09, 2015, 12:48:59 AM
Why isn't Coinbase issuing an email to all it's clients to watch out for the scam ? That's my problem with the whole thing, they should be informing everyone who is signed up at Coinbase right now not to invest in this scam.

The kicker for me was that the email didn't route to Coinbase actual website, just some random deposit link. I mean, I guess if you're brand new to Bitcoin you might fall for it.

I agree with this. Safety for its customers should be the number 1 priority. At least make a notification on the site itself


Title: Re: Coinbase Investment fund email?
Post by: MacDuro on April 09, 2015, 01:16:22 AM
Why isn't Coinbase issuing an email to all it's clients to watch out for the scam ? That's my problem with the whole thing, they should be informing everyone who is signed up at Coinbase right now not to invest in this scam.

The kicker for me was that the email didn't route to Coinbase actual website, just some random deposit link. I mean, I guess if you're brand new to Bitcoin you might fall for it.


Totally agree ... for me Coinbase is dead , that lack of action to prevent his users is inacceptable.


Title: Re: Coinbase Investment fund email?
Post by: dznuts85 on April 09, 2015, 03:00:47 AM
i recieved this email too. but fortunately i didnt click on any links i found on the message..


Title: Re: Coinbase Investment fund email?
Post by: to3m on April 09, 2015, 07:54:51 AM
That would be very much appreciated. Would be nice if we get this solved… I don't like the idea of my data moving around uncontrollably (yes… the internet, but I guess you know what I mean). :)

BTC-E said: "Thank you for contacting BTC-e. We can not assume where hackers have received your e-mail address We have no information leaks." Well, true or not (I have no opinion), they've at least been told.

So: case unsolved!

--Tom


Title: Re: Coinbase Investment fund email?
Post by: crazyivan on April 09, 2015, 08:41:52 AM
i recieved this email too. but fortunately i didnt click on any links i found on the message..

Its not about links. Its about people who actually send BTC. If there is anyone that stupid and I m sure there is. It s also about the source of emails, where did they all these addresses from?


Title: Re: Coinbase Investment fund email?
Post by: sp00ner on April 09, 2015, 08:52:09 AM
My two cents: I received that email on an address I used exclusively for Localbitcoins.com.


Title: Re: Coinbase Investment fund email?
Post by: OnkelPaul on April 09, 2015, 09:16:09 AM
It s also about the source of emails, where did they all these addresses from?

Yes that's the real question here. I don't know where they got mine, sadly I did not use individual addresses for different services, but I'm sure that I did not register at BTC-e and I think I never left my address at MtGox or Localbitcoins (although I'm not entirely sure of that).

If they were able to siphon off addresses from different services, and managed to hack a coinbase account, they are either pretty good at hacking, have very good social engineering skills, or have placed people within several organizations. I don't know what to think of this.

Onkel Paul


Title: Re: Coinbase Investment fund email?
Post by: allyouracid on April 09, 2015, 09:16:27 AM
i recieved this email too. but fortunately i didnt click on any links i found on the message..

Its not about links. Its about people who actually send BTC. If there is anyone that stupid and I m sure there is. It s also about the source of emails, where did they all these addresses from?
Exactly this.
Though I still have the feeling that the leaked Mt.Gox database at least plays a role in that.

.edit:
Plus, I'm also pretty certain that different websites do sell our user data. I mean, who did not yet register with his email on one of the thousand Bit- and altcoin faucets, or at some random news page or other site promising anything that looks like profit.
We're in crypto here, any anything evil imagineable has to be expected. We're in an unregulated world, and such things even happen in the regulated one. The white sheep are the absolute exception, here!


Title: Re: Coinbase Investment fund email?
Post by: sgk on April 11, 2015, 04:40:41 AM
I got one of these today. It was sent to my BTC-E email address. (I have my own domain, so I sign up with every service under a different email address.)

I wonder how they got hold of that?

--Tom
Very clever!
This would make the origin of the problem pretty much clear. On the other hand, while BTCe is a bit shady, I cannot explain how the connection to the mails being sent through coinbase servers can be drawn…

I don't have account on BTCe or Coinbase. Still I received the phishing email.
In the email, they're not using my BitcoinTalk forum username, so I'm sure they got my email address from somewhere else. From where, that's beyond my understanding.

They're giving unique deposit address to everyone. They gave me 1MFqqNRtRHKfuejDR1wF8BkkmUaGypXc8L which is different from what someone else has posted earlier in this thread.
This makes it difficut to taint a single address as scam.

https://i.imgur.com/ZiwL9U0.png


Title: Re: Coinbase Investment fund email?
Post by: TheButterZone on April 11, 2015, 09:43:09 AM
The address they gave me: 1PCkmoYFCLo8qX1Lt1opxCjs8cDbW5dm7g

Scammers not reusing addresses, LOL, they're ahead of 99% of bitcoindom.


Title: Re: Coinbase Investment fund email?
Post by: r4vani on April 11, 2015, 06:35:41 PM
new way for scam, absolutely not from CoinBase.  ;)


https://i.imgur.com/M3hWic9.png


Title: Re: Coinbase Investment fund email?
Post by: ajareselde on April 12, 2015, 03:20:57 AM
i get a ton of theese, from wide spread of "resources" , this was the newest

"
Update Required!!   
   Dear paypal user,

For your safety some information on your account appears to be missing or incorrect.
Please update your information promptly so that you can continue to enjoy
all the benefits of your PayPal account.
If you don't update your information within 2 days, we'll limit and suspend your paypal account.
sorry for any inconvenience caused by our security measurements

update
If you need help logging in, go to our Help Center by clicking the Help link located in the upper right-hand corner of any PayPal page. .
Sincerely,
PayPal

 
Please do not reply to this email. We are unable to respond to inquiries sent to this address. For immediate answers to your questions, visit our Help Center by clicking "Help" at the top of any PayPal page.
Copyright � 2015 PayPal Inc. All rights reserved. PayPal is located at 2211 N. First St., San Jose, CA 95131.   "

i just lol, and extend my blacklist ^^

cheers


Title: Re: Coinbase Investment fund email?
Post by: Xiaoxiao on April 14, 2015, 02:34:39 PM
They sent this to my other email not registered with Coinbase.  And they figure out your real name.  Likely they compromised your information from other businesses such as BTC jam in order to obtain your full name and email address.  Obviously they know you're interested in bitcoin some how.


Title: Re: Coinbase Investment fund email?
Post by: Mikestang on April 14, 2015, 10:05:04 PM
I couldn't decide which was a better deal, this Coinbase investment, or the chance to help import $42,000,000 from a Nigerian prince.  I'm still trying to decide which investment to pursue with all of my ponzi income.