How Did the Coinbase Phishing Scheme Work?

A Brooklyn man who stole nearly $16 million from about 100 Coinbase users through a yearlong phishing and social engineering operation has been sentenced to four to 12 years in prison.

Ronald Spektor, 23, of Sheepshead Bay, pleaded guilty on September 2 to a 31-count indictment that included first-degree money laundering, first-degree grand larceny and first-degree criminal possession of stolen property, according to the Brooklyn District Attorney’s Office. The case had previously resulted in Spektor’s indictment in December 2025.

Prosecutors said Spektor impersonated Coinbase representatives and contacted customers with warnings that hackers were threatening their assets. Victims were instructed to move their crypto into new wallets that they believed were under their own control. Spektor could access those wallets and then remove the assets.

The operation generated losses of approximately $15.94 million across roughly 100 victims throughout the U.S. Some individuals lost at least $1 million.

After gaining control of the crypto, Spektor repeatedly moved the assets through exchanges, swapping services and other platforms before consolidating funds at locations where they could be converted, gambled, exchanged for cash or used to buy gift cards and digital assets.

“The investigation further revealed that the stolen assets were then laundered by swapping them multiple times through different crypto exchanges until they were eventually consolidated at ‘cash-out points’ where they could be converted to other types of cryptocurrencies, wagered in bets, converted to cash, and used to purchase gift cards or digital assets,” prosecutors said.

How Did Investigators Trace the Stolen Crypto?

The case shows how blockchain transactions can provide investigators with a trail even when criminals move funds across multiple services.

Authorities said transaction records, blockchain analysis, digital forensics and evidence obtained through multiple search warrants connected Spektor to the thefts. His home IP address was linked to several wallets that received stolen cryptocurrency.

Investigators also recovered evidence that Spektor recruited other people through online forums to participate in social engineering activity. He used the Telegram handle @lolimfeelingevil and operated a channel called “Blockchain enemies,” where prosecutors said he discussed his activities.

Messages recovered during the investigation indicated that Spektor claimed to have made millions of dollars from scams and had lost roughly $6 million worth of cryptocurrency through gambling. Investigators also found messages indicating that he disposed of a hardware wallet and obtained another after fraud allegations began circulating online.

Spektor was ordered to forfeit cash, cryptocurrency and personal property worth more than $500,000. He must also pay almost $16 million in restitution. Prosecutors had requested a sentence of seven to 21 years, but his guilty plea carried a promised sentence of four to 12 years over the district attorney’s objection.

Investor Takeaway

The theft did not depend on exploiting Coinbase’s blockchain infrastructure. It relied on convincing customers that a fraudulent support representative was legitimate. That distinction matters because stronger exchange security cannot fully eliminate losses when users are persuaded to authorize transfers themselves.

Why Are Coinbase Users Frequent Phishing Targets?

Coinbase’s size and brand recognition make it an attractive identity for scammers attempting to impersonate customer support. Similar campaigns have repeatedly targeted exchange users through phone calls, text messages, emails and fraudulent websites.

Earlier phishing activity linked to Coinbase users included more than $46 million in suspected losses during a March 2025 wave, according to onchain investigations at the time.

The risks increased further after Coinbase disclosed in 2025 that criminals had bribed overseas customer-support personnel to obtain customer information. The company said the incident affected less than 1% of monthly transacting users and did not expose passwords, private keys or customer funds, but the stolen information could be used to make social engineering attempts more convincing. Coinbase estimated that remediation and voluntary customer reimbursements tied to the breach could cost $180 million to $400 million.

A later filing indicated that more than 69,000 Coinbase customers had data exposed through the insider-related breach.

What Does the $16 Million Case Show About Crypto Fraud?

Spektor’s operation required neither a smart-contract exploit nor direct access to Coinbase’s core systems. The attack targeted the person controlling the wallet.

That makes social engineering particularly difficult to stop through technical security alone. A victim can have working authentication controls and still lose assets if a scammer persuades them to voluntarily transfer crypto to an attacker-controlled address.

The Brooklyn District Attorney’s Office advises users to independently verify unexpected support contacts and warns that legitimate crypto companies generally will not call customers and instruct them to move assets into a supposedly “safe” wallet.

For exchanges, the case adds pressure to improve fraud detection around customer communications and suspicious transfers. For users, the central risk remains simpler: a transaction authorized under false pretenses can be just as final as one initiated after a technical compromise.