A large-scale cryptocurrency fraud scheme built around fake Coinbase websites has resulted in losses of more than $20 million from hundreds of victims worldwide, according to the U.S. Department of Justice. The case highlights how phishing infrastructure, social engineering, and fake customer support tactics can be combined to compromise exchange accounts and drain digital assets in a matter of minutes.
U.S. prosecutors said Indian national Chirag Tomar was sentenced to five years in prison for his role in the operation. Authorities described the scheme as a coordinated effort involving fraudulent websites designed to imitate Coinbase, especially the former Coinbase Pro platform used by more advanced traders. Victims were tricked into handing over login credentials and two-factor authentication codes, giving the attackers direct access to their real accounts.
A phishing operation disguised as a trusted exchange
According to the DOJ, the scam dates back to June 2021. The attackers allegedly created websites and URLs that closely resembled legitimate Coinbase pages. That similarity was central to the fraud: users believed they were logging into an authentic exchange interface, but were instead submitting their credentials to criminals.
Once victims entered usernames, passwords, or verification details, the attackers intercepted that information and used it to access genuine Coinbase accounts. In some incidents, the scheme went beyond simple phishing. Victims were persuaded to install remote access tools, allowing the fraudsters to take control of their computers directly. That gave the attackers a much broader window into account activity and, in some cases, enabled them to complete transfers from the victim’s own device.
The DOJ said the fraud targeted victims in the United States and abroad. In court filings, authorities characterized the operation as an effort to steal millions in cryptocurrency from hundreds of individuals around the world.
Fake customer support played a central role
A key component of the scheme involved impersonating Coinbase support personnel. Victims were either directed to call fraudulent support lines or received unsolicited calls from scammers posing as customer service representatives. During those interactions, victims were convinced to share two-factor authentication codes, which are often the final barrier preventing unauthorized access.
This method proved especially effective because it exploited urgency and confusion. A user who believed an account had been locked, compromised, or flagged for suspicious activity was more likely to trust a supposed support agent. By combining a fake website with a convincing support script, the attackers turned what looked like a routine account recovery process into a theft operation.
Once inside the accounts, the criminals moved quickly. Authorities said stolen funds were transferred to wallets under the group’s control, routed through multiple addresses, and then converted into cash. This layering process made tracking more difficult and helped distance the perpetrators from the original theft.
Lavish spending and a documented victim case
Federal authorities said the proceeds of the scam were used to finance Tomar’s luxury lifestyle. Court records cited expenditures on high-end vehicles, expensive watches, and international travel. Those details were included as part of the government’s broader account of how the stolen funds were used after victims’ crypto holdings were drained.
One example outlined in the case involved a resident of North Carolina in February 2022. The victim attempted to log in through a fake Coinbase website and then believed the account had become locked. After contacting a fraudulent representative, the individual unknowingly shared authentication codes. The result was a loss of more than $240,000 in cryptocurrency.
That case illustrates the mechanics of the broader fraud: first, a deceptive entry point through a spoofed site; second, an engineered support interaction; and finally, rapid asset extraction once trust had been gained and account defenses had been bypassed.
Arrest, guilty plea, and sentencing
Tomar was arrested in December 2023 at the Atlanta airport, according to the DOJ. He later pleaded guilty in May 2024 to conspiracy to commit wire fraud. Before being transferred to federal prison, he will remain in custody.
The investigation involved both the U.S. Secret Service and the Federal Bureau of Investigation, which authorities credited with helping dismantle the operation. The case underscores the increasing sophistication of crypto-related fraud, particularly schemes that combine technical deception with human manipulation rather than relying solely on code exploits or exchange vulnerabilities.
What the case means for crypto users
The incident is a reminder that the biggest risks in digital asset security do not always come from blockchain failures or protocol hacks. In many cases, attackers exploit users directly through lookalike domains, fake support channels, and pressure tactics designed to extract credentials and one-time codes.
For exchange users, the lessons are straightforward but critical: verify the exact domain before logging in, do not share authentication codes with anyone claiming to be support staff, and avoid installing remote desktop software at the request of unknown parties. Even strong account security can fail if social engineering succeeds.
As crypto adoption expands, the branding power of large exchanges such as Coinbase also makes them attractive targets for impersonation. The Tomar case shows how familiar names can be weaponized in phishing campaigns and how a single moment of trust can lead to devastating losses. For regulators and law enforcement, it is another high-profile example of why cross-border cooperation remains essential in investigating and prosecuting crypto-enabled financial crime.

