Coinbase Impersonator Stole $16M Through “Safe” Wallets

Daniel Zimmermann
5 Min Read
A telephone cord turns into a hand stealing cryptocurrency from a wallet.
A promise of safety can conceal a transfer to a wallet the caller controls.

A man who posed as Coinbase support and persuaded users to move cryptocurrency to supposedly safer wallets has been sentenced to four to 12 years in prison. Brooklyn prosecutors announced Ronald Spektor’s sentence on September 23, after a scheme that cost about 100 US users nearly $16 million. The promised rescue was the theft: the new wallets were accessible to the person offering help. [1]

The transfer that handed over control

According to the Brooklyn District Attorney’s Office, victims were told that a hacker threatened their assets. They transferred cryptocurrency to wallets they believed only they controlled. Spektor could access those wallets and emptied them. The release describes impersonation and deception, not a newly disclosed breach of Coinbase’s systems.

This is the critical distinction behind a “safe wallet” request. Seeing your money arrive at an address answers whether a transfer succeeded; it does not establish that nobody else can spend it. Checking a balance and checking exclusive control are different tasks. Our wallet-verification guide explains why a valid address, transaction history, or successful test transfer cannot authenticate the person directing a payment.

Four stages of the false-rescue scam, including the scammer’s access to the new wallet.
Explanation of the mechanism described by the Brooklyn District Attorney’s Office. The victim’s belief in exclusive control was false.

The diagram highlights the hidden condition: the wallet was never exclusively the victim’s. The prosecutor’s release does not specify how Spektor obtained access in every case, so it would be inaccurate to assign one seed-phrase or malware technique to all the victims.

The digital trail led back home

Prosecutors say stolen funds passed through exchanges and services used to swap, gamble, or cash out assets. Investigators combined blockchain analysis with transaction records, forensic evidence, and search warrants. Spektor’s home IP address was linked to several affected wallets; recovered messages also described his scamming and gambling. The finding depended on evidence from multiple sources, rather than a wallet address identifying a person by itself. [1]

Spektor pleaded guilty on September 2. The court also ordered forfeiture of more than $500,000 in assets and almost $16 million in restitution. Those orders do not establish how much victims have actually recovered.

A genuine wallet app cannot validate a caller

Coinbase’s separate February 2025 explanation of support scams shows why familiar software can make this deception convincing. In its illustrative scenario, a caller guides someone into a self-custody wallet, then supplies or obtains its recovery phrase. The victim sees incoming funds while the caller already has the means to take them. That is background guidance, not a reconstruction of each Spektor theft. [2]

The practical boundary is who chose the destination and who holds its secrets. A real app does not certify the caller’s identity, and authenticating to your exchange does not make an attacker’s payment request legitimate. The same distinction applies to other cryptocurrency impersonation scams.

Verify the request before moving anything

Coinbase’s current support guidance says its agents will not supply or request a wallet recovery phrase, ask for passwords or two-factor codes, or tell customers to transfer crypto to an external address. End a call making those requests and open support independently through the app or official Help Center. A displayed caller ID is not sufficient verification. [3]

If you suspect account compromise, use the service’s in-app account-lock option and contact official support. Preserve the conversation and transaction details for reporting. The lesson from this case is specific: a stranger’s instruction to move money “for protection” is itself the reason to stop, even when the wallet looks familiar.

References

  1. Brooklyn District Attorney’s Office. Brooklyn man sentenced for stealing nearly $16 million in cryptocurrency scheme. September 23, 2026.
  2. Coinbase. Hang up the Phone — Stop Social Engineering Scams. February 3, 2025.
  3. Coinbase Help. Technical support and impersonation scams. Accessed September 26, 2026.
Share This Article
With a strong background in consumer safety and fraud prevention, Daniel specializes in providing actionable tips and advice to users. His focus is on helping individuals understand the risks of interacting with fraudulent sites and services
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?