Skip to content

A Coinbase Phishing Scheme Stole $16 Million. Digital Forensics Traced It to a 23-Year-Old

Ronald Spektor, a 23-year-old from the Sheepshead Bay neighborhood of Brooklyn, will spend four to twelve years in prison for a phishing scheme that drained nearly $16 million from about a hundred Coinbase users across the United States. The sentence, handed down by Brooklyn Supreme Court Justice Danny Chun, closes a case built on a single social-engineering trick: convincing victims their accounts were already under attack.

How the scheme worked

Over roughly a year, Spektor contacted Coinbase customers while posing as a representative of the exchange. The pitch was always a version of the same lie: their assets were at risk from a hacker, and they needed to move funds to a new wallet immediately — one that, victims were told, would be theirs alone.

It was not. The address was actually controlled by Spektor, who emptied each wallet the moment funds arrived. Prosecutors traced about $15.94 million in losses to roughly 100 people nationwide, some of whom lost $1 million or more. The individual steps look like ordinary customer-service fraud, but their repeatable, automated nature turned the scam into theft at scale.

A laundering trail built for speed

Once the funds landed, Spektor routed them through swapping and mixing services and into gambling platforms, where portions were consolidated and converted into cash, gift cards, and other digital assets. That is a standard way to break the connection between stolen crypto and whoever took it.

Yet the same trail became the evidence against him. Investigators in the district attorney’s Virtual Currency Unit combined transaction records, blockchain analysis, digital forensics, and material from multiple search warrants to link Spektor’s home IP address to wallets from which cryptocurrency had been stolen.

The bragging that helped the case

Spektor did not keep a low profile. He used the Telegram handle @lolimfeelingevil and ran a channel called “Blockchain enemies,” where prosecutors said he boasted about the heists and wrote that he had gambled away $6 million while making millions more through scamming. He also recruited accomplices on online forums and, after fraud allegations surfaced, discarded a hardware wallet and bought a new one — a detail recovered from text messages on his phone.

The sentence and the warning

Spektor pleaded guilty on September 2 to all 31 counts, including first-degree money laundering, first-degree grand larceny, and criminal possession of stolen property. District Attorney Eric Gonzalez’s office had sought seven to twenty-one years; Justice Chun instead accepted the negotiated sentence of four to twelve. Spektor was also ordered to forfeit cash, cryptocurrency, and property worth more than $500,000 and to pay restitution of almost $16 million.

The DA framed the case as a message. “We will follow the digital trail wherever it leads and aggressively pursue those responsible,” Gonzalez said. His office repeated a warning worth remembering: Coinbase and most other companies will never call customers or ask them to move crypto to a “safe wallet.” The manufactured urgency — the “act now before you lose everything” pressure that makes phishing work — is precisely what should make a careful user pause.

Adapted from Brooklyn Man Sentenced to Up to 12 Years for $16M Coinbase Phishing Scheme.