Man impersonating Coinbase customer service sentenced for defrauding $16 million
A 23-year-old man, Ronald Spektor, from Brooklyn, New York, impersonated customer service personnel from the cryptocurrency exchange Coinbase, defrauding nearly 100 American users of approximately $16 million in crypto assets. He was sentenced to 4 to 12 years in prison by Brooklyn Supreme Court Judge Danny Chun after pleading guilty to all 31 counts in the indictment.
His method was a typical social engineering attack. Using aliases like "Fred Wilson" and "James Wilson," he claimed to be an employee of Coinbase's security department, contacting users via phone and email, falsely stating that their accounts were facing hacking attempts. To gain trust, he spoofed caller IDs and email addresses, and impersonated Coinbase and Google to send fake two-factor authentication texts, directing victims to transfer assets to a so-called "new wallet." Victims believed they controlled the wallet, but he held access, subsequently draining it. The crimes occurred from April 2023 to December 2024.
Victims were spread across the U.S., with several losing over $1 million, totaling approximately $15.944 million in losses. One California resident lost over $1 million, a Virginia resident lost over $900,000, a Pennsylvania man lost about $53,150, and a Maryland woman lost about $38,750. He also operated a Telegram channel named "Blockchain enemies."
The laundering path of the stolen funds is clear. He repeatedly exchanged cryptocurrencies across multiple exchanges, then pooled the funds into "cash-out points," before dispersing them to crypto gambling platforms, mixing services, online stores, or purchasing gift cards and cash. Seized chat records show he lost about $6 million at crypto casinos. Investigators seized about $105,000 in cash and approximately $400,000 in cryptocurrency, with Coinbase stating that over $600,000 has been recovered so far.
The sentence was lower than the prosecution's request. The prosecution sought a sentence of 7 to 21 years, but the court ultimately sentenced him to 4 to 12 years and ordered him to pay approximately $16 million in restitution, along with the forfeiture of over $500,000 in cash, cryptocurrency, and personal property. Charges included first-degree money laundering, first-degree grand larceny, and first-degree possession of stolen property. The prosecution stated there was no evidence that the customer data he used came from a Coinbase data breach.
In terms of market mechanisms, funds flowed along the path from "victims to the scammer's wallet, exchanged across exchanges and mixed, then to casinos, gift cards, and cash," with crypto casinos being the most direct recipients, losing about $6 million just from gambling losses. Beneficiaries include on-chain tracking analysis companies and independent investigators: In November 2024, on-chain detective ZachXBT publicly investigated at the request of a victim who lost $6 million, helping to identify the suspect. The pressured party is Coinbase: the exchange's customer service channels were used as a facade for the scam, requiring it to invest more compliance costs in identity verification, user education, and cooperation with law enforcement, while also suffering from damaged brand trust.
Supplementary data: According to ZachXBT, Coinbase users lost over $65 million due to social engineering scams in just two months at the beginning of 2025. In May 2025, Coinbase disclosed a data breach affecting nearly 70,000 users, with estimated losses of $180 million to $400 million.
Source: Public information
ABAB AI Insight
Impersonating customer service in crypto scams has developed into a mature technique. In August 2024, a Genesis creditor was defrauded of about $243 million in Bitcoin by a gang impersonating Google and Genesis customer service; ZachXBT tracked the on-chain funds, leading to the suspects' arrest in the U.S. In May 2025, Coinbase disclosed that hackers bribed its overseas outsourced customer service personnel to steal user names, addresses, and account balances, demanding a $20 million ransom; Coinbase refused to pay and instead offered a $20 million reward for the attackers' capture. The pioneer of social engineering is hacker Kevin Mitnick from the 1990s, who primarily relied on phone calls to impersonate internal employees to gain system access rather than writing code. Thirty years later, this method has been directly transferred to the crypto world.
There are two paths at the funding level. One is the attackers' money laundering chain: cross-chain bridges, decentralized exchanges, mixers, and crypto casinos form an unlicensed "underground clearing system." The U.S. Treasury sanctioned the mixer Tornado Cash in 2022, but related sanctions were lifted in 2025, leaving the tools intact while regulatory boundaries continue to fluctuate. The other path is the defensive investments: Coinbase, as the largest compliant exchange and publicly traded company in the U.S., is allocating resources towards customer identity verification, on-chain monitoring, and law enforcement collaboration, while on-chain analysis companies like Chainalysis and TRM Labs are turning "fraud tracking" into a paid service for law enforcement and exchanges.
Among similar cases, the largest was in February 2025 when the North Korean hacker group Lazarus stole approximately $1.5 billion from Bybit, with the entry point not being a blockchain hack but breaching the front-end interface and personnel of a multi-signature wallet. Data from the FBI's Internet Crime Complaint Center shows that in 2024, Americans lost about $9.3 billion to cryptocurrency scams, a 66% increase year-on-year, with the 60+ age group losing about $2.8 billion, making seniors a primary target for impersonation scams. The industry is in a phase of "institutional expansion": the listing of spot Bitcoin ETFs and large-scale entry of traditional funds, while retail users' security capabilities have not improved in sync.
The essence is a technological replacement; more accurately, the attack surface has shifted from technical systems to people. The mechanism is that the cryptographic security of blockchains is already strong enough, making direct cracking extremely costly; however, ownership of crypto assets is entirely determined by private keys, and transfers are irreversible, lacking the freezing and recovery mechanisms of banks. Attackers thus choose the lowest-cost link, which is users' trust in "official customer service." The cost of spoofing calls and texts is nearly zero, and a single successful deception can yield all assets. Traditional finance relies on intermediaries to bear risks, while crypto finance directly transfers risks to individuals; as asset scales expand to the general public, social engineering has become the most profitable attack method.
ABAB News · Cognitive Law
- The strongest cryptography falls to a phone call.
- Self-custody means freedom, but it also means no one can reverse for you.
- Scams never attack systems, only the entry points of trust.
Notes:
- Title sentencing: The court sentenced 4 to 12 years; the original push only wrote "up to 12 years," so the title states "sentenced," with the sentencing period in the body.
- Unverified background: The contents in the AI interpretation come from publicly available English information I possess; this round has not been cross-verified online, so it is recommended to confirm again before publication:
- Amount in the Genesis case
- Changes in Tornado Cash sanctions
- Amount stolen from Bybit
- FBI statistics for 2024.