Ronald Spektor: The Fake Coinbase Agent Who Took $16M
A Brooklyn man posed as Coinbase security, took $15.9M from about 100 people and bragged on Telegram. He got 4 to 12 years.

Key numbers
$15.9M
Stolen
About 100
Victims
4 to 12 years
Sentence
$500K+
Forfeited
In September 2024 a man in Pennsylvania watched his phone fill up with security codes he had not asked for. Some appeared to come from Coinbase, the largest cryptocurrency exchange in the United States, a company that works much like an online stockbroker for digital money. Others appeared to come from Google. Then the phone rang. The caller introduced himself as Fred Wilson from Coinbase security and said someone had just tried to move money out of the man's account. By the time the conversation was over, about $53,150 of his crypto was gone.
He was one of about 100 people across the United States who took a call, a text or an email like that between April 2023 and December 2024. Brooklyn prosecutors put the combined loss at $15,944,000. A California resident lost more than $1 million and a Virginia resident more than $900,000, according to the Brooklyn District Attorney's Office, the prosecutor for Kings County. Another Californian lost about $6 million in October 2024, ABC7 New York and Business Insider reported from the case papers. Brooklyn District Attorney Eric Gonzalez said many victims had handed over their life savings.
The man behind the scheme was Ronald Spektor, 23, who lived with his father in Sheepshead Bay, Brooklyn, and bragged about his thefts on a Telegram channel called "Blockchain enemies" under the handle @lolimfeelingevil. On 23 September 2026, Justice Danny Chun of the Brooklyn Supreme Court (in New York, despite the name, the ordinary trial court for serious crimes) sentenced him to four to 12 years in prison. He had pleaded guilty on 2 September to all 31 counts in the indictment, including first-degree grand larceny, first-degree money laundering and first-degree criminal possession of stolen property.
Live DeFi agents
Watch four AI agents manage money in public.
Stablecoins across Base, Arbitrum, Optimism, Polygon and Avalanche. Every decision is on-chain.
Subscription opening soon. Not financial advice.
- BASE
- ARB
- OP
- POL
- AVAX
How the con worked
Nobody broke into Coinbase. The scheme was social engineering, a form of phishing, which means conning a person rather than hacking a computer. It is the crypto version of the call from "your bank's fraud team" that ends with a customer moving their own savings to the fraudster. Crypto makes it worse in one way: a transfer on a blockchain, the shared public ledger that records every payment, cannot be reversed by a bank or a broker once it has gone.
Victims described the same sequence to investigators. First came the alarm: a burst of texts that looked like login codes or security warnings, sent in bulk by automated software. Then came the call from "Coinbase security", which seemed to confirm what the texts suggested: a hacker was trying to get in. A woman in Maryland, who lost about $38,750, received an email from a "James Wilson" who claimed to work for Coinbase.
Then came the fix. The money was not safe where it was, the caller said, and had to be moved to a new wallet. A crypto wallet works like a safe-deposit box that only opens with one particular key. The victims were led to believe the new box was theirs alone. It was not. In the words of the District Attorney's office, it was "actually accessible by the defendant".
The District Attorney's releases do not say exactly how he kept a copy of the key. In scams of this type the usual method is for the caller to supply the wallet's recovery phrase, the list of 12 or 24 words that acts as its master key, so that the "safe" wallet belongs to the scammer from the start. Either way, once the victim pressed send, the crypto was his.
Following the money
The stolen coins were then swapped many times across different crypto exchanges, the way someone might change dollars into euros, then yen, then back again to muddy the paper trail. Some went through mixing services, which pool coins from many users and pay out different ones, much as a cash-heavy business can blend dirty notes with clean takings. The money was then gathered at what prosecutors called "cash-out points", where it was bet on crypto gambling sites, turned into cash, or spent on gift cards and at online shops. In messages recovered by investigators, Spektor wrote in slang that he had lost $6 million gambling.
He did not keep quiet. Besides the Telegram channel, he used Discord, a chat app popular with gamers, and online forums where, prosecutors said, he recruited other people to work for him as callers. The District Attorney's releases name none of them.
The bragging drew attention. In November 2024, a month after the large California theft, ZachXBT, an independent investigator who traces stolen crypto on public blockchains, published a thread naming "Ronaldd" as Ronald Spektor and linking him to a $6.5 million theft from a single victim who had been called by someone posing as Coinbase support. Texts later recovered from Spektor's phone show that after he became the subject of online fraud allegations, he got rid of a hardware wallet (a device about the size of a USB stick that stores crypto keys offline) and had a new one bought.
The case against him was built by the District Attorney's Virtual Currency Unit, led by Assistant District Attorney Alona Katz, over roughly a year. Investigators interviewed more than 70 victims and used transaction records, blockchain analysis and several search warrants. His home internet address, which works like a return address on an envelope, was linked to multiple wallets the crypto was stolen from. Coinbase helped identify him and the customers he defrauded, its chief legal officer Paul Grewal said, and the District Attorney also thanked the threat intelligence firm Flashpoint.
Arrest, plea and sentence
Spektor was arrested on 4 December 2025, a year after the scheme stopped, and arraigned on 19 December on the 31-count indictment. He pleaded not guilty. Bail was set at $500,000 cash or a $1 million bond, and he was held at Rikers Island. ABC7 New York reported that the judge refused money his father offered for bail because its source could not be accounted for. His lawyer at the time, Todd Spodek, told reporters: "These are all user-initiated actions."
Nine months later Spektor pleaded guilty to everything. Justice Chun promised the four-to-12-year sentence in return for the plea, over the objection of the District Attorney's office, which wanted seven to 21 years. In New York a sentence like this sets a minimum and a maximum, and the parole board can consider release once the minimum has been served.
The money is the grim part. Investigators seized about $105,000 in cash and roughly $400,000 in crypto, and Spektor was ordered to forfeit cash, crypto and property worth more than $500,000 in total. That is about 3 cents for every dollar taken. The court also ordered restitution of almost $16 million, a debt he now owes his victims. Whether much of it will ever be paid by a man who wrote that he had gambled away $6 million is another question.

The call to hang up on
The District Attorney's advice is short. Coinbase and most other companies never call customers or ask them to move crypto to a "safe wallet". Caller ID, sender names and lookalike website addresses can all be faked. Contact a company only through its own app. Slow down, because the urgency is the weapon. One rule is not on the list but covers most of these scams: a recovery phrase supplied by someone else is someone else's key.
Spektor was one operator in a crowded trade. The SEE Crew ran the same script, with callers posing as exchange security teams, and ZachXBT has tied Dritan Kapllani to similar social engineering thefts. In February 2025 ZachXBT estimated that Coinbase users were losing more than $300 million a year to this kind of scam, including about $65 million in December 2024 and January 2025 alone. Three months later Coinbase disclosed that criminals had bribed overseas customer support staff to hand over the personal details of about 69,000 customers, exactly the raw material these callers need. Chief executive Brian Armstrong refused a $20 million ransom demand and offered a $20 million reward instead. The company estimated the cost at $180 million to $400 million. Spektor's scheme had ended before that breach, and prosecutors have not linked him to it.
His victims were never hacked. They were helped, by a man who said he was from security.
The aftermath
Spektor was sentenced on 23 September 2026 to four to 12 years in state prison, a lighter range than the seven to 21 years the Brooklyn District Attorney's office asked for. Justice Danny Chun had promised that sentence in return for a guilty plea to all 31 counts, and imposed it over the prosecutors' objection. Under New York's indeterminate sentencing, the parole board can consider him for release once the four-year minimum has been served.
He was ordered to forfeit cash, crypto and personal property worth more than $500,000 and to pay restitution of almost $16 million. Set against losses of $15,944,000, the seized assets cover roughly 3 per cent. His own recovered messages said he had lost $6 million gambling, which makes full repayment unlikely. The District Attorney's release did not say how much, if anything, has yet reached individual victims.
No accomplice has been named. Prosecutors said Spektor recruited other people as callers through online forums, but neither of the District Attorney's releases identifies any of them or says whether anyone else has been charged.
The wider problem has not gone away. ZachXBT's estimate of more than $300 million a year in losses among Coinbase users alone, and Coinbase's own May 2025 disclosure that bribed support staff leaked the details of about 69,000 customers, mean the lists these callers work from are larger than ever.
What this teaches
- Coinbase and most other companies never call customers or ask them to move crypto to a "safe wallet". A call that says otherwise is the scam.
- Caller ID, text sender names and email addresses can all be faked. A burst of security codes followed by a helpful phone call is a script, not a coincidence.
- A recovery phrase supplied by someone else is someone else's key. Any wallet set up with words a caller provided can be emptied by that caller.
- Crypto transfers cannot be reversed. Of $15.9 million taken, investigators seized about $505,000, roughly 3 cents on the dollar.
- Bragging leaves a trail. Spektor's Telegram channel, his home internet address and an investigator's public thread all pointed at him long before his arrest.

COMMENTS