Brooklyn man sent to prison for 12 years for stealing $16M in a Coinbase phishing scheme
The fraudster managed to scam about 100 people across the United States, convincing them of transferring funds to him, claiming their accounts had been hacked.
A Brooklyn resident is headed to prison for 12 years after pleading guilty to scamming nearly 100 Coinbase users out of roughly $16 million dollars, a New York district attorney said Wednesday.
Ronald Spektor, 23, ran a phishing and social engineering scheme for over a year, convincing his victims that they had been hacked and that they should transfer funds to accounts he controlled, said Eric Gonzalez, a New York district attorney.
Social engineering scams topped crypto threats in 2025 and are getting worse this year. WhiteBIT said nearly 41% of all crypto security incidents last year involved fraudsters deceiving victims. Earlier this month, a 22-year-old Singaporean pleaded guilty to a network of criminals that netted $245 million mostly from social engineering scams. A Chainalysis report noted that criminals were increasingly targeting individuals rather than infrastructure.
“Today’s sentencing holds the defendant accountable for a brazen, long-running social engineering scam that amounted to a digital robbery of nearly 100 victims,” Gonzalez said. “Our Virtual Currency Unit painstakingly pieced together the digital proof that identified the defendant behind this sophisticated scheme, followed the money that he stole and compiled iron-clad evidence against him.”
The attorney general’s office has also ordered Spektor to forfeit cash, cryptocurrency and personal property with an estimated value of more than half a million dollars and make restitution of almost $16 million.
The investigation into Spektor’s criminal activities revealed he laundered the digital assets by swapping them across multiple crypto exchanges and consolidating them at “cash-out points.” He then converted them into other cryptocurrencies and placed bets, before converting them into cash with which he purchased gift cards or additional digital assets.
“Coinbase and most other companies will never call customers or ask to transfer crypto to a ‘safe wallet’. Don’t trust caller ID, sender names or lookalike domains that can be spoofed,” Gonzalez said, adding that scammers rely on urgency and pressure, so “never move money in a rush.”
As stablecoins move into regulated finance, APAC is becoming a key proving ground. This report maps the region’s rules, use cases, and RLUSD’s role.
Asanat Analysis — Why it matters
A 12-year sentence for a $16M phishing operation represents significant federal enforcement against cryptocurrency theft, signaling that exchanges and law enforcement now treat account takeover schemes with the severity reserved for large-scale financial crimes. The 100-victim scope suggests this wasn't opportunistic—it was an organized operation that succeeded by exploiting the gap between exchange security and user verification, a pattern that persists despite industry improvements to 2FA and account recovery protocols.
Coinbase's brand recognition became the attack vector itself; scammers rely on users' trust in the platform name to lower scrutiny. The conviction may deter copycats through precedent, but it also highlights why exchange-level email compromise and SMS intercept attacks remain viable: users still treat direct messages claiming account compromise as legitimate. This case underscores that custody solutions (self-custody, institutional vaults) reduce phishing surface area—a structural argument for non-custodial platforms gaining adoption in higher-risk demographics.