Exchange Ledger

Crypto exchanges compared on fees, limits and availability

News

Brooklyn Man Jailed Over Coinbase Phishing Scheme

Illustration of a courthouse column next to a phone screen showing a phishing hook and a padlock, symbolizing a Coinbase phishing court case
A US court case over a Coinbase phishing scheme is a reminder to check your own account security settings.

A federal court in the United States sentenced a Brooklyn man to prison after he was convicted of running a phishing scheme that stole an eight-figure sum from Coinbase account holders, according to CoinDesk. If you keep funds on Coinbase, or any exchange, this is worth ten minutes of your time to check your own account settings.

In short

  • A Brooklyn resident was sentenced to a prison term measured in years, not months, for a phishing scheme targeting Coinbase customers, per CoinDesk's reporting.
  • The scheme relied on tricking account holders directly, not on breaking into Coinbase's own servers.
  • Coinbase enforces a daily withdrawal limit of €100,000 per day, which is one of several account-level controls that slow down anyone who gains unauthorized access.
  • US-based Coinbase users are the most directly affected group, since the case ran through US federal courts and involved US victims.
  • The practical response is the same regardless of which exchange you use: tighten two-factor authentication, question unsolicited support contact, and know your withdrawal limits.

Key facts

Coinbase
Fees—
LimitsDaily withdrawal limit: €100,000 per day
Deposit methods—
Country availability—

What changed

A federal court sentenced a man from Brooklyn to prison for a phishing scheme that drained Coinbase customer accounts of an eight-figure sum, CoinDesk reported. The sentence runs well past a decade, which places it among the longer terms handed down in a US crypto fraud case tied to a single exchange's user base.

The mechanics matter more than the headline number. Phishing schemes against exchange users generally do not involve breaking into the exchange's own infrastructure. They target the account holder instead. Common patterns prosecutors describe in these cases include:

  • Fake support calls or texts claiming to be from Coinbase, asking a victim to "verify" a login or read out a one-time code.
  • Spoofed emails that mimic Coinbase's design and push a login link to a lookalike domain.
  • Convincing a victim to approve a withdrawal or move funds to a "safe wallet" that the attacker controls.
  • SIM-swapping, where an attacker takes over a victim's phone number to intercept SMS-based two-factor codes.

Once an attacker has a session, a code, or a signed transaction, the exchange has no easy way to tell a legitimate withdrawal from a fraudulent one. That's the core problem this case illustrates: the theft happened through the front door, using credentials or approvals the victims themselves handed over under pressure.

CoinDesk's report frames this as a criminal prosecution outcome, not a change to Coinbase's platform, policies, or fee structure. Coinbase was the venue where the stolen funds sat, not the party found at fault.

Takeaway: the sentence closes a criminal case; it does not signal any new Coinbase policy or system change.

Who is affected

This is a US case, run through US federal courts, involving a US-based defendant and reportedly US-based victims. That makes it most directly relevant to Coinbase customers inside the United States, though the phishing playbook described in the case gets reused against exchange users in other countries too.

Within that group, some account profiles carry more exposure than others. None of this is specific to Coinbase; it applies to account security on any centralized exchange.

Risk factor Why it matters
SMS-based two-factor authentication Vulnerable to SIM-swap attacks that intercept codes
Reused passwords across sites One leaked password elsewhere can unlock an exchange account
Answering unsolicited "support" calls or texts Real exchange support rarely initiates contact by phone first
No withdrawal address allowlist Any address can receive funds if credentials are compromised
Large balances left on an exchange rather than in self-custody More funds sit exposed to a single account takeover

People who have never set up hardware-based two-factor authentication, who use the same phone number tied to their exchange account for everything else, or who have previously received a call claiming to be from exchange support are the ones who should read the next section closely.

Anyone comparing exchanges on limits and fees rather than just this incident can check our breakdown in Coinbase News: Fees And Limits Compared With Binance, which covers how withdrawal caps and verification tiers differ across platforms.

Takeaway: the exposure here is account-level, tied to habits and settings, not to a flaw in Coinbase's platform itself.

What to do now

None of the steps below require waiting on Coinbase, a court, or a regulator. They're account settings you control today.

Immediate checks

  1. Switch off SMS-based two-factor authentication if it's still your only method. Move to an authenticator app or a hardware security key.
  2. Set up a withdrawal address allowlist if the exchange offers one, so funds can only leave to addresses you've already approved.
  3. Check your account's recovery phone number and email for anything you don't recognize.
  4. Never act on a phone call or text claiming to be exchange support that asks for a code, password, or remote screen access. Hang up and contact support through the official app or website instead.
  5. Know your daily withdrawal limit. Coinbase's daily withdrawal limit sits at €100,000 per day, which is a ceiling worth knowing so you notice quickly if it's ever been changed or exhausted without your action.

Why the withdrawal limit matters

A daily cap doesn't stop a determined attacker outright, but it does two useful things: it caps single-day losses if an account is compromised, and it creates a pause where a fraud alert or a second verification step has a chance to catch unusual activity. Comparing that cap against limits on other platforms is useful context, which is why we track it separately in our Coinbase News: Fees And Limits Compared With Binance guide.

If you think you've already been targeted

Situation Action
You gave out a one-time code by phone Change your password and two-factor method immediately, then contact official support
You clicked a link and entered credentials on an unfamiliar page Assume the account is compromised; reset credentials and check withdrawal history
You approved a transaction you didn't intend to Document it and report to support and to law enforcement; recovery odds drop fast once funds move off-exchange
Your exchange account looks frozen or restricted after a fraud report Read what a frozen or restricted account status usually means in our guide on Coinbase Down? What Exchange Outages Mean for You

Longer-term habits

  • Treat any unsolicited contact claiming to be from an exchange as suspicious by default.
  • Keep large, long-term holdings off exchanges in self-custody wallets where practical.
  • Review your account's active sessions and connected apps periodically, not just after a headline.
  • Use a password manager so credentials aren't shared across sites.

Takeaway: the fastest defense against this exact scheme is refusing to act on unsolicited contact and locking down two-factor authentication before anyone asks you to.

References

#SourceReliabilityChecked
1 help.coinbase.com — Daily withdrawal limit Official source 2026-09-18