TL;DR:
- Ronald Spektor was sentenced to four to 12 years for a Coinbase phishing scheme that stole nearly $16 million from about 100 victims.
- The fraud relied on fake Coinbase support, urgency and “safe wallet” transfers, while funds moved through exchanges, mixers, gambling platforms and cash-out points.
- Spektor must forfeit more than $500,000 and pay $16 million in restitution after investigators linked him through blockchain analysis, forensics and IP evidence.
Ronald Spektor, 23, of Brooklyn has been sentenced to four to 12 years in prison after pleading guilty to a 31-count indictment tied to a Coinbase phishing scheme that stole nearly $16 million from 100 U.S. victims. In its official statement, the Brooklyn District Attorney’s Office said Spektor impersonated Coinbase representatives and convinced users their assets were at risk. The scheme relied on social engineering rather than a breach of Coinbase’s systems, persuading victims to move crypto into wallets accessible to Spektor.
Social Engineering Powered the $16M Coinbase Scam
The operation ran for about a year and caused losses totaling $15.944 million. Victims were told hackers had compromised their assets and were instructed to transfer funds into safer wallets. Once the transfers were completed, Spektor emptied the accounts. The fraud exploited trust in customer support and urgency around account security, a pattern seen in other Coinbase phishing schemes. Some victims lost $1 million or more.

Investigators followed the stolen assets as they moved through exchanges, swapping services, mixers, gambling platforms and online storefronts before reaching cash-out points. Spektor’s home IP address was linked to wallets containing stolen crypto, while blockchain analysis, transaction records, digital forensics and search-warrant evidence helped identify him directly. The case shows how laundering across multiple crypto services can complicate recovery without erasing the digital trail. Similar recovery disputes have emerged after phishing thefts involving traced funds.
Spektor also used the Telegram handle “@lolimfeelingevil” and ran a channel called “Blockchain enemies,” where investigators said he bragged about his activity and recruited others as social engineers. Messages indicated he had lost $6 million in crypto through gambling. His online behavior became part of the evidence linking the operation to a real-world defendant. The case underscores why social engineering remains a major crypto security risk.
Spektor pleaded guilty on September 2 to charges including first-degree money laundering, grand larceny and criminal possession of stolen property. He was ordered to forfeit more than $500,000 in cash, crypto and personal property and pay nearly $16 million in restitution. The sentence closes a major prosecution, but the broader threat remains active as attackers continue impersonating trusted platforms to pressure users into moving funds. Coinbase and other companies generally do not ask customers to transfer crypto to “safe wallets,” making independent verification critical when urgent security messages appear.





