Brooklyn resident Ronald Spektor, 23, received a four-to-12-year prison sentence after pleading guilty to stealing nearly $16 million from about 100 Coinbase users. Prosecutors said Spektor posed as a Coinbase representative, warned victims that hackers were targeting their accounts, and directed them to wallets he secretly controlled. Some victims lost more than $1 million.
Why it matters
The operation relied on social engineering rather than a direct breach of Coinbase systems. Victims made the transfers themselves after receiving spoofed two-factor authentication messages or calls from people claiming to work in Coinbase security. In one case, a Pennsylvania man moved his assets after a caller using the name “Fred Wilson” warned of an attempted transfer, losing about $53,150.
Prosecutors said Spektor moved stolen crypto through token swaps, exchanges and mixing services before converting funds through gambling platforms, online stores, gift cards and other digital assets. Blockchain analysis, transaction records, search warrants and an IP address linked him to wallets associated with the thefts. Investigators also said he recruited other social engineers through online forums.
Market impact
The case adds legal pressure to a security problem that exchanges cannot solve through account controls alone. Coinbase warns customers that its support staff will never ask them to move funds to a new wallet, reveal seed phrases, or provide passwords and authentication codes.
The court ordered Spektor to forfeit more than $500,000 in cash, crypto and personal property and pay nearly $16 million in restitution. Prosecutors did not say how much stolen crypto had been recovered or distributed, leaving the recovery picture unresolved. The sentence came below the Brooklyn district attorney’s request for seven to 21 years, after the judge upheld a four-to-12-year commitment tied to Spektor’s guilty plea.
Frequently asked questions
-
How did Spektor steal crypto from Coinbase users?
Spektor posed as a Coinbase representative, warned victims about supposed account threats, and directed them to wallets he secretly controlled. Victims authorized the transfers themselves.
-
How many people were targeted in the Coinbase scam?
Prosecutors said the operation targeted about 100 people across the United States. Some victims lost more than $1 million.
-
How did investigators connect Spektor to the stolen crypto?
Investigators used blockchain analysis, transaction records and search warrants. Prosecutors also linked his home IP address to wallets associated with stolen funds.
-
What sentence did Ronald Spektor receive?
Spektor received a four-to-12-year prison sentence after pleading guilty to a 31-count indictment. The judge upheld the sentence tied to his plea agreement.
-
What restitution and forfeiture did the court order?
The court ordered Spektor to forfeit more than $500,000 in cash, crypto and personal property and pay nearly $16 million in restitution. The amount recovered for victims was not disclosed.
CryptoSlate