Coinbase impersonator gets up to 12 years for $16 million crypto scam

- Ronald Spektor, 23, of Brooklyn was sentenced to four to 12 years for impersonating Coinbase support.
- Spektor must forfeit over $500,000 and repay almost $16 million after stealing nearly $16 million from about 100 users.
- Coinbase suffered a May 2025 breach in which bribed overseas support agents leaked customer data.
The Brooklyn District Attorney’s office has announced that Ronald Spektor, a 23-year-old Brooklyn resident who ran a year-long Coinbase support scam that drained roughly $16 million in crypto from about 100 victims, received a four-to-ten-year prison sentence on Wednesday, September 23.
The prison sentence closes one of the larger social engineering cases tied to the Coinbase exchange, which became the subject of many phishing scams and support impersonation schemes in late 2025 and early 2026 after a May 2025 breach where overseas support agents leaked customer data for bribes.
Brooklyn sends Coinbase impersonator to prison
Brooklyn Supreme Court Justice Danny Chun sentenced the defendant, identified as Ronald Spektor by Brooklyn District Attorney Eric Gonzalez, to a prison term of four to 12 years. The Sheepshead Bay native, who lived with his father in the borough, pleaded guilty to all 31 counts the Brooklyn DA’s office brought against him on September 2.
Spektor faced charges including first-degree money laundering, first-degree grand larceny and first-degree criminal possession of stolen property.
Prosecutors objected to the court’s ruling on prison time after initially pushing for Spektor to be sentenced to seven to 21 years in prison.
Cash, crypto and personal property valued above $500,000 were confiscated from Spektor, who was also ordered to make almost $16 million in restitution payments.
How did Spektor’s Coinbase scam work?
Spektor’s operation did not involve a lot of technicality.
The scheme started by connecting with Coinbase customers via old-school phone calls, while claiming to be an exchange representative. Then Spektor would warn them that their assets were at risk of being stolen by hackers unless they moved them into a fresh, safe wallet.
Spektor would then walk them through sending the tokens into a new wallet that he has access to. From there, he clears the wallet and leaves the victims counting losses that ran above $1 million in some cases.
The indictment also described how Spektor tried to obfuscate the money trail through an on-chain laundering cycle involving multiple swaps across different exchanges before they end up at “cash-out points.”
The DA’s office said much of the stolen funds flowed to gambling services and online storefronts.
How was Spektor caught?
Transaction records, blockchain analysis, digital forensics and material seized under multiple search warrants led to Spektor’s arrest by the DA’s Virtual Currency Unit, led by Assistant District Attorney Alona Katz. Prosecutors also connected his home IP address to several of the wallets from which victims were robbed.
Spektor also brought the spotlight on himself, bragging about his exploits on his “Blockchain enemies” Telegram channel, under the @lolimfeelingevil handle. He also flaunted his wealth on Discord as well.
Recovered messages showed him claiming he had blown six million dollars gambling and hinting he had made millions from scamming. Investigators said he also recruited others through online forums to act as social engineers, and that after fraud allegations surfaced online, he dumped one crypto hardware wallet and bought a replacement.
“This case should put crypto scammers on notice: we will follow the digital trail wherever it leads,” Gonzalez said in the announcement.
Coinbase’s long-running impersonation problem
Cryptopolitan reported in December 2025 that on-chain investigator ZachXBT traced roughly $2 million in thefts to a single Canadian scammer working the same customer-support impersonation playbook.
Many of these schemes trace back to a May 2025 breach in which bribed overseas support agents leaked customer data; Coinbase has said that incident touched under 1% of its monthly transacting users and exposed no passwords, private keys or funds.
The exchange has also been on the enforcement side. Fortune reported this week that Coinbase and Microsoft helped dismantle EvilTokens, an AI-assisted phishing-as-a-service network, an investigation that led UK police to arrest two men on September 11.
The smartest crypto minds already read our newsletter. Want in? Join them.
FAQs
Who is Ronald Spektor and what did he do?
Spektor is a 23-year-old from Sheepshead Bay, Brooklyn who posed as a Coinbase representative, told users their assets were at risk, and tricked about 100 people into moving crypto into wallets he secretly controlled, stealing nearly $16 million.
What sentence did he receive?
Brooklyn Supreme Court Justice Danny Chun sentenced him on Wednesday to four to 12 years in prison after he pleaded guilty on September 2 to a 31-count indictment; he was also ordered to forfeit more than $500,000 and pay close to $16 million in restitution.
How did investigators identify him?
The Brooklyn DA's Virtual Currency Unit linked Spektor through transaction records, blockchain analysis, digital forensics and search-warrant evidence, including his home IP address connecting to several of the drained wallets and his own online bragging under the handle @lolimfeelingevil.
Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Hannah Collymore
Hannah is a writer and editor with nearly a decade of blog writing and event reporting experience in the crypto space. At Cryptopolitan, Hannah contributes to the news page, reporting and analyzing the latest developments in DeFi, RWA, crypto regulation, AI and frontier tech industries. She graduated from Arcadia university with a degree in Business Administration.
















