Ronald Spektor, a Brooklyn resident, was sentenced to up to 12 years in federal prison for orchestrating a phishing scheme that stolen nearly $16 million from Coinbase users, according to an announcement from the Brooklyn District Attorney's office.
Spektor used fraudulent emails and fake websites to trick victims into surrendering their login credentials, then transferred their cryptocurrency holdings to accounts he controlled. The scheme targeted Coinbase's customer base directly, exploiting trust in the platform's branding to gain unauthorized access to accounts holding digital assets.
The case represents one of the largest prosecutions to date for cryptocurrency theft via social engineering. In September 2026, federal prosecutors in New York secured convictions against multiple actors involved in stealing from exchange users, as phishing and credential-harvesting schemes have grown more sophisticated across the industry.
Coinbase has implemented additional security measures in recent years, including email authentication protocols and mandatory hardware security key verification for high-value accounts. The exchange did not comment on Spektor's case directly, but the company has previously stated that customer education around phishing remains a critical component of its fraud prevention strategy.

Federal law enforcement has prioritized cryptocurrency theft cases as digital asset holdings have grown. The Department of Justice has secured sentences ranging from three to fifteen years for similar schemes, depending on the amount stolen and whether victims' funds were recovered.
Spektor's 12-year sentence falls at the upper end of federal sentencing guidelines for wire fraud and computer intrusion offenses combined. The Brooklyn DA's office stated that restitution terms require Spektor to repay the stolen amount, though asset recovery efforts often recover only a fraction of funds from defendants in these cases.
The volume of phishing attacks targeting crypto platforms has not declined despite increased law enforcement actions. Industry security firms report that credential-harvesting emails impersonating major exchanges remain among the most common vectors for account compromise in the sector.