Brooklyn Man Sentenced to Up to 12 Years for $16M Coinbase Phishing Scheme
A 23-year-old Brooklyn resident received a 4-to-12-year prison term after stealing nearly $16 million from approximately 100 Coinbase users.
A 23-year-old resident of Brooklyn has been sentenced to serve between four and 12 years in state prison for executing an extensive social engineering operation that targeted crypto investors. As reported by U.Today, the perpetrator orchestrated a series of fraudulent schemes that successfully drained roughly $16 million from approximately 100 Coinbase account holders.
The criminal operation utilized deceptive communications, SIM swapping, and sophisticated phishing websites that impersonated the centralized exchange's security support services. By tricking victims into divulging their two-factor authentication credentials and login details, the attacker gained unauthorized entry to exchange accounts, immediately transferring digital assets to un-hosted external wallets under criminal control.
Social engineering attacks remain one of the most prevalent attack vectors across the digital asset space, frequently exploiting human error rather than cryptographic vulnerabilities in the blockchain. The substantial sum involved highlights the growing sophistication of consumer-facing scams and the persistent vulnerability of centralized exchange accounts relying on standard multi-factor authentication methods.
Legal authorities emphasized that the sentencing serves as a stark warning to cybercriminals exploiting decentralized technology for illicit gain. However, recovery of stolen cryptocurrency remains a difficult task for law enforcement, leaving many victims with limited recourse to recoup their funds once on-chain laundering techniques and mixing services are employed.
Industry security experts advise retail investors to transition away from SMS-based two-factor authentication toward hardware security keys and multi-signature custodial solutions. Market watchers expect centralized exchanges to implement stricter withdrawal verification delays and advanced behavioral monitoring to detect unauthorized account takeovers before transfers settle.
Key takeaways
- A 23-year-old was sentenced to 4 to 12 years in prison for a $16 million crypto phishing scam.
- The social engineering scheme targeted nearly 100 Coinbase users using fake support portals.
- Security professionals recommend hardware-based authentication to prevent account takeovers.
