Ronald Spektor, a 23-year-old Brooklyn resident, was sentenced to up to 12 years in prison after pleading guilty to stealing nearly $16 million from almost 100 Coinbase users through a phishing and social engineering scheme spanning more than a year, the New York district attorney's office said Wednesday.
Spektor impersonated a Coinbase customer service representative and persuaded victims they had been hacked, convincing them to transfer cryptocurrency to accounts he controlled. He then laundered the stolen assets by swapping them across multiple exchanges, consolidating funds at cash-out points, converting them into other cryptocurrencies, placing bets, and finally purchasing gift cards or additional digital assets.
The attorney general's office has ordered Spektor to pay approximately $16 million in restitution and forfeit more than $500,000 in assets, including cash, cryptocurrency, and personal property.
"Today's sentencing holds the defendant accountable for a brazen, long-running social engineering scam that amounted to a digital robbery of nearly 100 victims," New York District Attorney Eric Gonzalez said. "Our Virtual Currency Unit painstakingly pieced together the digital proof that identified the defendant behind this sophisticated scheme, followed the money that he stole and compiled iron-clad evidence against him."
Social engineering scams topped crypto threats in 2025, according to data from the crypto exchange WhiteBIT, which reported that nearly 41% of all crypto security incidents that year involved fraudsters deceiving victims directly. Earlier this month, authorities also charged a 22-year-old Singaporean with operating a criminal network that netted $245 million mostly through social engineering schemes.
A recent Chainalysis report noted that criminals are increasingly targeting individual cryptocurrency holders rather than platform infrastructure, a trend underscored by the breadth of Spektor's operation.
Gonzalez warned the public about the tactics employed by such scammers. "Coinbase and most other companies will never call customers or ask to transfer crypto to a 'safe wallet.' Don't trust caller ID, sender names or lookalike domains that can be spoofed," he said, adding that social engineering relies on urgency and pressure, so "never move money in a rush."











