Exchange Ledger

Crypto exchanges compared on fees, limits and availability

News

Brooklyn Man Sentenced Over Coinbase Social Engineering Scheme

Illustration of a phone-based scam targeting a crypto exchange account holder, with courthouse imagery in the background
Social engineering, not a platform hack, was at the center of the Brooklyn sentencing.

A Brooklyn man was sentenced to a lengthy prison term for running a social engineering scheme against Coinbase customers, not for hacking Coinbase itself. If you hold funds on any exchange, especially Coinbase, and have ever gotten an unexpected call about your account, keep reading.

In short

  • A Brooklyn resident received a lengthy federal prison sentence for a Coinbase-related social engineering scheme reported to involve eight figures in stolen funds.
  • The scheme worked through impersonation and manipulation of account holders, not a breach of Coinbase's own systems or code.
  • Coinbase enforces a daily withdrawal limit of €100,000 per day, which slows unauthorized transfers but does not stop a victim who is talked into approving one.
  • The most effective defense against this class of fraud is refusing to share one-time codes or passwords with anyone contacting you first, by phone, text, or email.
  • This case sits alongside a broader pattern of account-level fraud aimed at individual crypto users rather than exchange infrastructure or compliance failures.

Key facts

Coinbase
Fees—
LimitsDaily withdrawal limit: €100,000 per day
Deposit methods—
Country availability—

What changed

A federal court in Brooklyn, New York, sentenced a man to a prison term described as up to a dozen years for orchestrating a social engineering scheme that targeted Coinbase account holders, according to a report from The Block. Prosecutors said the scheme extracted roughly sixteen million dollars from victims by getting them to hand over account access voluntarily, not by breaching Coinbase's servers or exploiting a flaw in its software.

The mechanics follow a familiar script. Someone contacts an account holder posing as exchange support or a security team member, warns of an urgent compromise, and walks the victim through steps that end with funds moving to a wallet the scammer controls. Sometimes it is a phone call. Sometimes it is a text message that looks like a fraud alert. The common thread is that the exchange's technical defenses are never the target — the person holding the account is.

Coinbase was not accused of a security failure in connection with this case. That distinction matters for how readers should interpret it. This is not a story about a platform getting breached, in the way a smart contract exploit or an exchange outage is a platform-side event. For context on how exchange-side incidents differ from account-level fraud, see our piece on what it means when Coinbase goes down versus when an individual account is drained.

One-line takeaway: the sentence punishes a person who manipulated account holders — Coinbase's own systems were not the point of failure.

Who is affected

Nobody's balance on Coinbase changes because of a sentencing decision in a Brooklyn courtroom. But the underlying pattern is relevant to a specific set of readers, and it is worth being blunt about who should pay closer attention.

  • Anyone holding a meaningful balance on Coinbase who has received an unsolicited call, text, or email claiming to be from Coinbase support or security.
  • Older account holders, since this class of fraud consistently skews toward people who are more inclined to trust a phone call over an in-app notification.
  • Anyone who has linked a bank account or debit card for instant buys, since those transfer rails can move faster than a standard crypto withdrawal once someone gains access.
  • Readers comparing exchanges primarily on fee schedules or support quality, since social engineering exploits the human side of account recovery, not a line item on a fee table.
  • People who assume the main risk in crypto right now is regulatory action against an exchange, such as the ongoing scrutiny covered in our coverage of the Manhattan US Attorney's probe into Binance's Iran compliance. Account-level fraud aimed at individuals is a separate risk category, and arguably a more common one for ordinary users than exchange-level compliance trouble.

It is also worth noting who is not really affected: Coinbase's product roadmap, its fee structure, or features like the recently filed single-stock perpetuals on Apple, Tesla, and Nvidia have nothing to do with this case. This is a story about account security hygiene, not product strategy.

One-line takeaway: the exposure here sits with individual account holders and their habits, not with Coinbase's platform or its product lineup.

What to do now

Coinbase, like other custodial exchanges, does not call customers out of the blue to fix a problem. Legitimate support contact almost always starts with an action you take inside the app or on the official site, not with an inbound call, text, or email asking you to act immediately.

A quick way to tell the difference

Signal Legitimate Coinbase contact Scam pattern
Who starts the conversation You initiate it through the app or official site Someone contacts you first, unprompted
Urgency Issues get resolved through your account, on your schedule Constant pressure to act immediately
Requests Never asks for your password or a one-time code Asks you to read out a code or share your screen
Fund movement Never instructs you to move funds to a "safe" wallet Instructs a transfer "for protection" or "verification"

Practical steps

  • Treat any inbound call, text, or email about your Coinbase account as suspicious by default. Hang up or ignore it, then log in independently to check for genuine alerts.
  • Never read a two-factor code to anyone, even someone who already seems to know your name, email, or partial account details. Knowing those details is not proof of legitimacy.
  • Turn on withdrawal allowlisting if it is available for your account type, so funds can only move to addresses you have already approved in advance.
  • Remember that daily withdrawal caps are a backstop, not a shield. Coinbase's limit of €100,000 per day can slow a determined scammer, but it does nothing to stop a transfer that you approve yourself after being talked into it.
  • If you suspect you have already shared access, change your password, revoke connected apps and API keys immediately, and contact Coinbase support only through the official app, not through a number or link someone sent you.

For readers weighing exchanges on more than security posture, our side-by-side of Coinbase's fees and limits against Binance covers the numbers side of that decision. Security habits and fee schedules are separate questions, and this case is a reminder that the cheaper exchange on paper does not matter much if the account behind it gets talked away from you.

One-line takeaway: no withdrawal limit, allowlist, or app feature replaces the habit of never sharing a one-time code with anyone who contacts you first.

References

#SourceReliabilityChecked
1 help.coinbase.com — Daily withdrawal limit Official source 2026-09-18