Ronald Spektor Jailed Up to 12 Years for $16 Million Coinbase Bitcoin (BTC) Theft

Ronald Spektor, 23, got 4–12 years for a $15.9M Coinbase impersonation scam hitting ~100 US users; court ordered $500K forfeiture and near-full restitution.

(08:44 AM UTC)
4 min read
AI SummaryAI
  • Spektor pleaded guilty Sept. 2 to all 31 counts including money laundering and grand larceny.
  • Court ordered forfeiture of over $500,000 and restitution approaching $16 million.
  • Spektor's home IP address was linked to multiple wallets receiving stolen funds.
  • Investigators seized roughly $105,000 in cash and $400,000 in cryptocurrency during the probe.
d2mv6ykl

Four to 12 Years in Brooklyn Supreme Court

A Brooklyn court has sentenced 23-year-old Ronald Spektor to an indeterminate prison term of four to 12 years for stealing nearly $16 million from roughly 100 Coinbase users. The sentencing was announced Sept. 23 in a public statement from the District Attorney's office, which said Brooklyn Supreme Court Justice Danny Chun imposed the term after Spektor pleaded guilty on Sept. 2 to all 31 counts of his indictment — first-degree money laundering, first-degree grand larceny and first-degree criminal possession of stolen property among them. Prosecutors had asked for substantially more, seeking seven to 21 years; the defense had earlier disputed the case as resting on incomplete information before the guilty plea ended that argument. Spektor was arrested in December 2025 and initially entered a not-guilty plea.

The case capped a yearlong investigation by the District Attorney's Virtual Currency Unit, which put losses at approximately $15.944 million and interviewed more than 70 victims. District Attorney Eric Gonzalez described the operation as “a digital robbery of nearly 100 victims.” Critically, Coinbase's infrastructure was never breached: this was social engineering rather than a code exploit — no smart-contract drain, no maximal extractable value manipulation — only a voice on the phone that sounded official enough to move funds.

Inside the Impersonation Playbook

Prosecutors said Spektor contacted victims while pretending to work for Coinbase, warning that hackers had compromised — or were about to compromise — their accounts. The pressure worked: users were instructed to shift assets into a supposedly secure wallet they believed they alone controlled. In reality, Spektor could access every transfer the moment it landed, and in some instances victims surrendered their seed phrases outright, after which their holdings were withdrawn and routed through wallets linked to him.

The indictment's examples show how that trust was manufactured. One Pennsylvania victim lost roughly $53,150 after spoofed two-factor authentication messages — appearing to come from Coinbase and Google — arrived just before a caller presenting himself as “Fred Wilson” from Coinbase security. A California user lost more than $1 million, a Virginia resident more than $900,000, and a Maryland victim about $38,750 after emails from a self-described employee named “James Wilson.” Impersonation plays like this typically lean on lookalike branding and fake blockchain domains mirroring official support pages, and the pattern reaches well beyond one exchange's user base — similar rings have targeted holders of everything from Bitcoin to Algorand (ALGO).

Following the Money On-Chain

The money trail closed through on-chain forensics. The District Attorney's Office said investigators combined transaction records, blockchain analysis, digital forensics and evidence from multiple search warrants — and connected Spektor's home IP address to multiple wallets that received stolen funds. Per the December indictment, he operated online as @lolimfeelingevil, ran a Telegram channel named “Blockchain enemies” and used Discord to discuss successful thefts and recruit other social engineers. Recovered messages suggested he had gambled away about $6 million in cryptocurrency, and phone evidence showed he discarded a hardware wallet after fraud allegations surfaced and obtained a replacement.

Stolen assets moved fast: repeatedly swapped for other cryptocurrencies, converted to cash, then spent — with large portions landing at gambling services and online storefronts. Authorities seized roughly $105,000 in cash and $400,000 in crypto during the original probe, while Coinbase assisted in identifying affected customers, collecting evidence and tracing funds. The Sept. 23 order layers on forfeiture of cash, crypto and property valued above $500,000, plus restitution approaching the full loss — a recovery outcome that remains rare for social-engineering victims, since no policy protects them the way niche DeFi insurance covers select protocol failures. Readers tracking the market in real time can follow live spot and futures prices on Bybit.

The Warning Coinbase Keeps Repeating

COINOTAG's reading: the arc across this case is a warning the industry keeps failing to internalize. No exploit, no bridge hack, no platform fault — just manufactured urgency and a caller who knew the right vocabulary. Coinbase's official security guidance states its support staff will never ask users to move funds to a new wallet, disclose a seed phrase or share two-factor codes, and tells anyone receiving such requests to end contact immediately. Forensics delivered — home IP, wallet clustering, warrants — but the cheapest defense sits at the user's end of the call. Readers vetting venues should consult our guide to the best crypto exchanges and treat unsolicited support calls as hostile by default.

COINOTAG News Desk

COINOTAG News Desk

COINOTAG's editorial and research desk.

How our News Desk works
AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.