Security News > 2024 > May > Indian man stole $37 million in crypto using fake Coinbase Pro site
An Indian national pleaded guilty to wire fraud conspiracy for stealing over $37 million through a fake Coinbase website used to steal credentials.
Tomar and his co-conspirators created a fake website to mimic the Coinbase Pro website in June 2021 using the "Coinbasepro.com" domain.
The site was created to trick legitimate Coinbase customers into entering their login credentials and two-factor authentication codes, thinking it was the actual site.
Coinbase Pro is a now-defunct platform designed for professional cryptocurrency traders and investors, offering advanced features like real-time order books and detailed charting.
The phishing process involved social engineering, with a fake login error prompting the victims to call a supposed Coinbase representative, who then breached the victim's computer using remote access software.
"Other times, victims were tricked into allowing fake Coinbase representatives into executing remote desktop software, which enabled fraudsters to gain control of victims' computers and access their legitimate Coinbase accounts," reads the DOJ's announcement.