A Brooklyn man has received a prison sentence of four to 12 years after he admitted to a crypto scam that took almost $16 million from about 100 Coinbase users.
The case came to light on September 24, 2026, after The Block reported the sentence of Ronald Spektor, a 23-year-old Brooklyn resident. Prosecutors said Spektor posed as a Coinbase representative and used a fake security warning to trick users into moving their crypto to wallets that he could control. The total loss was $15.944 million, according to the Brooklyn District Attorney’s Office.
The case shows how crypto theft does not always require a complex attack on blockchain code. In this case, the main tool was deception. Victims were made to believe that their funds faced danger. They were then persuaded to take steps that gave the scammer access to their assets.
Spektor pleaded guilty on September 2 to a 31-count indictment. The charges included first-degree money laundering, first-degree grand larceny and first-degree criminal possession of stolen property.
How the Fake Coinbase Support Scam Worked
The scheme relied on a simple idea: make a victim believe that someone else had already attacked their Coinbase account.
According to prosecutors, Spektor posed as a Coinbase representative. He told users that their crypto was at risk from a hacker. The warning created fear and urgency.
He then persuaded the victims to move their digital assets to a new wallet. The victims believed the wallet was under their own control. In reality, prosecutors said Spektor could access the wallet.
This type of fraud is known as social engineering. Instead of trying to defeat a computer system directly, the criminal tries to persuade a person to take an action that helps the theft.
That method can be especially dangerous in crypto because a completed blockchain transaction can be very hard to reverse.
Nearly 100 People Lost Crypto
The case affected about 100 Coinbase users across the United States. The victims came from different backgrounds, and some lost $1 million or more, according to the Brooklyn District Attorney’s Office.
The total loss reached $15,944,000 during the roughly one-year scheme.
That figure is important because it shows the scale of the operation. This was not a single victim or a one-time theft. Prosecutors described a campaign that lasted about a year and targeted many people.
For each victim, the first step was trust. The scam depended on the person believing that the caller or contact was connected to Coinbase.
Once that trust was established, the victim could be persuaded to move funds.
Why Crypto Can Be a Target
Crypto has some features that can make this type of fraud especially painful.
A normal bank transfer may sometimes be stopped or reversed after a fraud report. Crypto transfers often work differently. Once a transaction is confirmed on a blockchain, it can be difficult or impossible to reverse through the network itself.
This does not mean crypto transactions are unsafe by nature. It means users must take extra care when someone asks them to move funds.
A real support representative should not need a customer to send crypto to a wallet controlled by an unknown person. Users also need to be careful with messages that create fear or demand immediate action.
The Spektor case shows why these basic checks matter.
The Money Did Not Stay in One Wallet
The stolen assets did not simply sit in one wallet after the theft.
Prosecutors said the crypto was moved through different exchanges and changed several times. The assets were eventually taken to what prosecutors called “cash-out points.”
At those points, the stolen crypto could be converted into other forms of cryptocurrency, used for bets, converted to cash or used to buy gift cards and digital assets.
This process made the money trail more complex.
Crypto transactions are recorded on public blockchains, but a wallet address does not automatically show the real-world identity of its owner. Investigators can still follow the movement of funds and combine blockchain records with other evidence.
That was important in this case.
Blockchain Analysis Helped Investigators
Investigators used several forms of evidence to connect Spektor to the stolen crypto.
The investigation included transaction records, blockchain analysis, digital forensics and evidence from multiple search warrants, according to prosecutors.
Investigators also linked Spektor’s home IP address to several wallets that received stolen crypto.
This is an important part of the case because it shows that crypto does not provide automatic anonymity.
Bitcoin and other blockchains can allow people to use wallet addresses rather than names, but the transaction history remains visible on the network. When investigators obtain other information, they can sometimes connect those addresses to people and physical locations.
The public nature of many blockchains can therefore work against criminals who believe crypto transactions cannot be traced.
A Guilty Plea Came Before the Sentence
Spektor pleaded guilty on September 2, 2026, to all 31 counts in the indictment.
His guilty plea meant that the case did not require a full trial on the charges. He later received a sentence of four to 12 years in prison.
The Brooklyn District Attorney’s Office had sought a sentence of seven to 21 years. However, Spektor’s plea deal carried a sentence of four to 12 years, even though the prosecution objected to that arrangement.
The final sentence was therefore lower than the term sought by prosecutors.
The case also carried major financial penalties beyond prison.
Nearly $16M in Restitution
Spektor was ordered to pay nearly $16 million in restitution.
He was also ordered to forfeit more than $500,000 in cash, cryptocurrency and personal property.
Restitution is separate from the prison sentence. Its purpose is to require a person convicted of a crime to repay victims for their losses.
The amount in this case is close to the full value of the crypto that prosecutors said victims lost.
Whether every victim can recover all of their money is a separate issue. A restitution order does not automatically mean that all stolen funds are immediately available.
Some Victims Lost More Than $1 Million
The scale of individual losses adds another serious part to the case.
According to prosecutors, some victims lost $1 million or more.
For a person with such a loss, the damage can extend far beyond the value of the crypto itself. The money may represent years of savings, investment gains or funds set aside for a major life goal.
A scam based on a fake security warning can be especially effective because the victim may believe that moving the money is the safest option.
The victim is not told, in effect, “give me your money.” Instead, the victim is told that the money is already in danger and that a transfer will protect it.
That difference can make the fraud much harder to spot.
Coinbase Has Faced Phishing Threats Before
Coinbase is one of the largest cryptocurrency exchanges in the United States, and its users have long faced phishing and social engineering attacks.
These attacks can take many forms. A criminal may pretend to be a company employee through a phone call, text message or email. Some scams also use websites that look similar to real company pages.
The goal is often to obtain sensitive information or persuade a customer to move funds.
The company also disclosed a separate security incident last year. Coinbase said criminals had bribed and recruited overseas customer support workers to obtain customer data for social engineering attacks. The company said the incident affected less than 1% of its monthly transacting users and that passwords, private keys and customer funds were not exposed in that incident.
That case was separate from the Brooklyn theft.
The Biggest Lesson Is Trust
The Spektor case highlights one of the hardest parts of online security: the technology does not have to fail for a theft to succeed.
A user can have a strong password and still lose crypto if a criminal convinces that person to send the assets to the wrong wallet.
This is why social engineering remains a serious problem across financial services.
The criminal does not always need to break into the victim’s account. The criminal may instead convince the victim to open the door.
Crypto can make this problem more serious because transfers are often final.
A user who sends coins to a scammer’s wallet may have very few options after the transaction receives confirmation.
Why Fake Security Warnings Work
Fear can make people act faster than they normally would.
A message that says an account has been hacked can cause a person to focus on protection rather than verification. If the person believes that money could disappear within minutes, they may follow instructions without checking whether the person on the other side is genuine.
That is the basic idea behind many social engineering attacks.
A fake support representative may sound professional. The person may know the victim’s name or some basic account information. The scammer may also use official company terms to make the story appear real.
But a familiar name, phone number or message does not prove that the contact is genuine.
Crypto Users Need to Check Before They Move Funds
The case also highlights a simple rule for crypto users: never rush a transfer because someone claims that an account is under attack.
If a person receives a warning about suspicious activity, the safest step is to contact the exchange through its official website or app. Users should not rely on a phone number, link or wallet address supplied by the person who contacted them.
They should also avoid sharing private keys, recovery phrases or other sensitive wallet information.
A legitimate security process should not require a customer to send assets to a stranger’s wallet.
These steps cannot stop every type of fraud, but they can make many social engineering attacks much harder.
Crypto Transactions Can Leave a Trail
The case also challenges the idea that stolen crypto simply disappears.
The blockchain records transactions. Investigators can examine those records and follow the movement of assets from one wallet to another.
That does not mean every wallet can be linked to a real person. It does mean blockchain evidence can become useful when investigators combine it with information from devices, exchanges, IP addresses, search warrants and financial records.
In Spektor’s case, prosecutors said blockchain analysis formed part of the evidence that helped connect him to the theft.
The public record of transactions can therefore provide investigators with a valuable source of evidence after a crime.
The Case Sends a Wider Message
The sentence comes at a time when crypto fraud remains a major concern for exchanges, regulators, law enforcement and users.
The value of digital assets can make them attractive targets. At the same time, the global nature of crypto can make it difficult to recover stolen funds once they move through multiple wallets and platforms.
The Spektor case shows that law enforcement can still trace complex transactions when investigators have enough evidence.
The sentence also shows that social engineering can lead to serious criminal consequences even when the theft begins with a conversation rather than a technical attack.
A $16M Warning for Crypto Users
The case of Ronald Spektor is now one of the latest major crypto crime stories in the United States.
A 23-year-old Brooklyn man received a sentence of four to 12 years after he pleaded guilty to a scheme that prosecutors said stole $15.944 million from about 100 Coinbase users. Some victims lost $1 million or more.
Prosecutors said Spektor posed as a Coinbase representative and warned users that hackers had placed their funds at risk. He then persuaded them to move their crypto to wallets that he could access.
The stolen assets were later moved through different crypto exchanges and other channels. Prosecutors said some funds were used for bets, cash conversion, gift cards and digital assets.
Investigators used blockchain analysis, transaction records, digital forensics and other evidence to connect Spektor to the crime. He must also forfeit more than $500,000 in assets and pay nearly $16 million in restitution.
The case offers a clear warning for anyone who owns crypto. A scam does not always look like a theft. Sometimes it looks like help.
A caller may claim to protect your money. A message may warn of a hacker. A support agent may ask you to move your funds.
That is exactly when caution matters most.
When a person asks for an urgent crypto transfer, the safest choice is to stop, verify the contact through an official channel and never send assets to a wallet just because someone claims it will protect them. The blockchain may record the transfer forever, but the stolen money may be very difficult to recover.
Also Read – Why ETF Discounts Widen During Market Panics