A user lost 750,000 USD in BTC from their CEX account due to a Google verification cloud sync issue
According to GoPlus monitoring, a Bitcoin holder just securely transferred assets from a Coldcard MK4 hardware wallet to a centralized exchange, avoiding the risk of the hardware wallet itself being stolen. However, within less than 12 hours after the transfer was completed, their Google account was hacked. Due to enabling Google verification cloud synchronization, the exchange account was logged into, and approximately $750,000 worth of Bitcoin was emptied.
GoPlus pointed out that such attacks typically do not rely on brute force but are achieved through social engineering phishing and weak password cracking. Common methods include: phishing pages inducing the input of Google passwords, malicious browser plugins or cracking software stealing cookies and passwords, weak password reuse being cracked, and password resets after recovery email or phone number takeover.






