A Brooklyn man was sentenced on Wednesday to up to 12 years in prison for stealing nearly $16 million from almost 100 Coinbase users through a phishing and social engineering scheme.

Ronald Spektor, 23, ran the scheme for over a year. He contacted victims, told them their accounts had been hacked, and walked them into transferring their own crypto into wallets he controlled, New York District Attorney Eric Gonzalez said in announcing the sentence.

For you, if you keep any of your portfolio on Coinbase, the case is worth a minute of attention, because Spektor did not break into the exchange. He broke into the people using it.

How the scheme worked

Spektor’s targets were individual Coinbase customers. The script was social, not technical: convince the victim the account had been compromised, then talk them through moving funds to a “safer” wallet that Spektor actually controlled. Over more than a year, that script pulled in nearly $16 million from almost 100 people.

Once he had the funds, the laundering chain was layered. Spektor swapped the assets across multiple crypto exchanges, consolidated them at “cash-out points”, converted them into other cryptocurrencies, placed bets, and finally converted them into cash used to buy gift cards or additional digital assets, the DA’s office said. Every leg is traceable on chain, but the entry point was a phone call.

What Spektor gives up

Alongside the prison term, Spektor was ordered to pay nearly $16 million in restitution and to forfeit more than $500,000 in cash, cryptocurrency and personal property. The forfeiture is the easier piece to enforce. Whether the restitution actually reaches the victims is the part they will be watching.

A wider pattern, not a one-off

The Spektor sentencing lands inside a year that has been unusually heavy on social engineering. WhiteBIT data shows nearly 41% of all crypto security incidents in 2025 involved fraudsters deceiving victims, and that the share has continued to grow in 2026. A separate Chainalysis report noted that criminals are increasingly targeting individuals rather than infrastructure.

This month, a 22-year-old Singaporean pleaded guilty to running a criminal network that netted $245 million, mostly from social engineering scams. Two cases, two continents, the same shape: contact the person, convince them they have been hacked, take the money.

What the DA wants you to take away

Gonzalez used the announcement to push a short list of rules that apply to anyone holding crypto on any exchange, not just Coinbase. Coinbase, he said, and most other companies, will never call customers or ask them to transfer crypto to a “safe wallet”. Caller ID, sender names and lookalike domains can all be spoofed. And the most important one: do not move money in a rush.

If a call, a text or a pop-up is pushing you to act right now, that pressure is the scam.

The information discussed by Altcoin Buzz is not financial advice. This is for educational, entertainment, and informational purposes only. Any information or strategies are thoughts and opinions relevant to the accepted levels of risk tolerance of the writer/reviewers and their risk tolerance may be different than yours. We are not responsible for any losses that you may incur as a result of any investments directly or indirectly related to the information provided. Bitcoin and other cryptocurrencies are high-risk investments so please do your due diligence.

Copyright Altcoin Buzz Pte Ltd.