Key points

  • Ronald Spektor received a prison sentence of four to 12 years after pleading guilty to all 31 counts in the indictment.
  • The Brooklyn District Attorney said the scheme stole about $15.94 million from roughly 100 U.S. Coinbase users.
  • The case involved impersonation and social engineering, not a reported breach of Coinbase's systems.

A Brooklyn man has been sentenced to four to 12 years in prison after pleading guilty to a cryptocurrency phishing scheme that stole nearly $16 million from about 100 people across the United States. The Brooklyn District Attorney's Office said Ronald Spektor, 23, impersonated Coinbase representatives and persuaded users to move assets into wallets he could access. The sentence follows a September 2 guilty plea to the entire 31-count indictment.

A fake security warning drove the transfers

According to prosecutors, victims were contacted by someone claiming to represent Coinbase and were told a hacker had put their assets at risk. They were instructed to move cryptocurrency to what was presented as a secure new wallet. The users believed they alone controlled those wallets, but prosecutors said Spektor also had access and emptied them. The District Attorney put the approximate loss at $15.944 million after a year-long investigation by its Virtual Currency Unit.

Related reporting: Brevo SSO flaw enabled phishing email to 347,000 Trezor subscribers

The case centered on social engineering

The reported method is important because the case was not described as a compromise of Coinbase's systems. It relied on impersonation, urgency and a request for users to authorize transfers themselves. That distinction places the security failure at the point where a customer evaluates a message or call, rather than in the exchange's trading or custody infrastructure. CoinDesk independently reported the sentencing and the scale of the losses on September 24.

Blockchain records helped trace the proceeds

The District Attorney said investigators used transaction records, blockchain analysis, digital forensics and evidence recovered through search warrants. Spektor's home internet address was linked to wallets that received stolen cryptocurrency, according to the release. Prosecutors also said he recruited other social engineers through online forums and discussed the scheme on encrypted messaging services. The assets were moved through exchanges, swapping and mixing services, gambling platforms and other cash-out channels before being converted or spent. Some victims lost $1 million or more, prosecutors said. Their locations spanned the country, underscoring that a remote impersonation operation can reach customers far beyond the jurisdiction where it is run.

Restitution and forfeiture accompany the sentence

Brooklyn Supreme Court Justice Danny Chun imposed the four-to-12-year term. Spektor was also ordered to make restitution of almost $16 million and forfeit cash, cryptocurrency and personal property worth more than $500,000. The District Attorney said it had sought a sentence of seven to 21 years and objected to the promised term attached to the guilty plea. That difference does not change the conviction, but it shows the court's sentence was below the range prosecutors requested.

What users should take from the case

The District Attorney warned that Coinbase and most other companies will not call customers and ask them to transfer crypto to a so-called safe wallet. It also advised users not to trust caller ID, sender names or lookalike domains without independent verification. The practical signal is the request itself: an unsolicited demand to move assets urgently should be treated as a potential fraud attempt, even when the caller appears to know account details. Independent verification should begin through an official app or a separately located support channel, not a link or number supplied by the caller. Pausing also gives a user time to consult another person before authorizing an irreversible transaction. The case illustrates how cross-platform laundering can amplify losses once a victim acts on a false security warning.

Sources

AI-generated editorial image; not a photograph of the reported event. Prepared with AI assistance and source verification.