Brooklyn man sentenced to up to 12 years in $16M Coinbase support scam
Brooklyn man sentenced over fake Coinbase support scheme
A Brooklyn man has been sentenced to as much as 12 years in prison for a scam in which he pretended to be Coinbase customer support and tricked users into moving their own crypto to wallets he controlled.
Ronald Spektor, 23, received a four-to-12-year sentence on Sept. 23, according to the Brooklyn District Attorney's Office. Prosecutors said the scheme took nearly $16 million from around 100 people across the United States.
A crypto wallet is software or a device used to hold digital assets. Prosecutors said the wallets victims were told to use looked secure but were secretly accessible to Spektor.
Key numbers from the case
- Spektor was 23 and lived in Brooklyn.
- His sentence was four to 12 years.
- Prosecutors put the total losses at about $15.944 million.
- Some victims lost more than $1 million each.
How the fake support calls worked
Prosecutors said Spektor posed as a Coinbase representative and warned users that hackers were threatening their accounts. He then told them to move their crypto to wallets that were described as safe.
The victims carried out the transfers themselves after being convinced their assets were in immediate danger, prosecutors said.
In one case, a man in Pennsylvania received spoofed two-factor authentication messages. Spoofed messages are fake messages made to look like they come from a real company. A caller who identified himself as 'Fred Wilson' from Coinbase security then warned of an attempted crypto transfer. The victim moved his assets and lost about $53,150.
What the Brooklyn District Attorney's Office said
The charges were announced in December 2025, when investigators had interviewed more than 70 victims. The sentencing release raised the estimated number of victims to about 100 nationwide.
Spektor pleaded guilty on Sept. 2 to a 31-count indictment. The charges included first-degree money laundering, grand larceny and criminal possession of stolen property.
How prosecutors say the stolen crypto was moved
Prosecutors said the stolen crypto passed through repeated swaps and exchanges and through mixing services before it reached cash-out points. Mixing services are tools that blend transactions to make them harder to trace.
The funds were converted into other tokens, sent to gambling platforms and used at online storefronts, including for gift cards and digital assets.
Blockchain analysis, transaction records and search warrants tied Spektor to the operation, prosecutors said. His home IP address was linked to several wallets connected to stolen funds.
Investigators also found evidence that he recruited other social engineers through online forums and ran a Telegram channel under the handle @lolimfeelingevil, where prosecutors said he boasted about thefts. Messages recovered from his phone showed he got rid of one hardware wallet, a physical device used to store crypto, after fraud allegations surfaced online, and bought another.
Judge keeps the four-to-12-year plea deal
Spektor pleaded guilty to the full indictment in exchange for a promised sentence of four to 12 years. The district attorney's office objected and asked Justice Danny Chun to impose seven to 21 years. The judge upheld the earlier commitment.
The court also ordered Spektor to forfeit more than $500,000 in cash, cryptocurrency and personal property, and to pay nearly $16 million in restitution.
Victim recovery remains unresolved
The forfeiture represents only a fraction of the estimated losses. Prosecutors did not say how much of the stolen crypto has been recovered or how much victims have received.
What Coinbase tells customers about support scams
Coinbase warns customers that its support staff will never ask them to transfer funds to a new wallet, to disclose a seed phrase, or to provide passwords and authentication codes. A seed phrase is a set of words that can be used to recover a crypto wallet.
The CryptoSlate report notes that the case points to a harder problem for exchanges: stopping impersonation scams that succeed before a user ever contacts official support.