A 23-year-old Brooklyn resident who pulled off a $15.944 million Coinbase phishing scam will serve four to 12 years in state prison following his conviction on a 31-count indictment. Brooklyn Supreme Court Justice Danny Chun delivered the indeterminate sentence on Sept. 23, 2026, ending a yearlong investigation into social engineering attacks that drained accounts belonging to roughly 100 victimized investors across the United States. Brooklyn District Attorney Eric Gonzalez pursued the case through his Virtual Currency Unit, unravelling a network of impersonation tactics, spoofed two-factor authentication prompts, and high-stakes crypto gambling cash-outs.
How the Coinbase Phishing Scam Drained $16 Million
The operational framework of the heist relied on direct psychological manipulation rather than breaking cryptographic code. Spektor targeted account holders by placing direct phone calls and sending emails disguised as official communications from exchange support staff. In several instances, he employed the alias James Wilson while warning targets that unauthorized bad actors were actively compromising their accounts. To heighten urgency, he sent spoofed two-factor authentication security codes directly to their mobile devices. Panic did the rest.
Spektor instructed worried users to transfer their digital holdings into newly generated secondary wallets for safekeeping. Victims operated under the false assumption that they maintained sole administrative control over these emergency accounts. They were wrong. Spektor held full backend access. The moment deposits hit those destination addresses, he systematically emptied them. Stolen tokens were routed through automated swapping services, centralized exchanges, and crypto mixing protocols to sever ownership links before being cashed out. Some stolen funds were spent directly at online retailers, while millions flowed into crypto gambling platforms.
Court records detail severe financial losses suffered by individual targets. A single California investor lost more than $1 million during one incident. A Virginia resident surrendered over $900,000 after following bogus support instructions. In Pennsylvania, a victim lost $53,150 after responding to spoofed two-factor security alerts and a subsequent follow-up call. Another victim in Maryland transferred approximately $38,750 after receiving fraudulent emails warning that her assets were at risk. These attacks highlight how sophisticated phishing tactics targeting crypto users continue to exploit human trust rather than technical protocol vulnerabilities.
Digital Forensics and IP Logging Exposed Telegram Operations
Spektor’s online bravado ultimately dismantled his defense. Despite utilizing mixing services and multiple exchange accounts, digital forensics teams linked his home IP address in Sheepshead Bay, Brooklyn, directly to receiving wallets that collected stolen funds. Investigators uncovered an extensive digital footprint across Telegram and Discord, where Spektor operated under the online handle @lolimfeelingevil. He ran a public Telegram group named Blockchain enemies, using the venue to recruit accomplices and coordinate social engineering plays.
Recovered chat logs revealed Spektor openly boasting about his criminal earnings and gambling habit. In private messages, he claimed to have lost $6 million on cryptocurrency betting platforms while bragging about generating millions through fraudulent schemes. When public allegations regarding his online fraud surfaced, Spektor attempted physical cover-ups. Phone records showed he disposed of a hardware wallet and bought a replacement device in an attempt to thwart investigators. That effort failed. When law enforcement officers executed search warrants at his home during his initial indictment in December 2025, authorities seized $105,000 in physical cash and $400,000 in cryptocurrency.
Exchange investigators played a crucial role alongside law enforcement. Coinbase’s Virtual Currency Unit and legal team provided transaction logs, account histories, and technical identification data that enabled prosecutors to map fund movements across blockchains. Tracing unhosted wallet flows required analyzing thousands of transaction hashes across multiple chains, mirroring complex investigations into onchain asset movement and wallet tracing. Without exchange-level records matching IP addresses to endpoint transfers, pinning individual account drains on a single residential address would have proven far more difficult.
Plea Bargain Disagreements and Financial Restitution Realities
The legal arc of the case reveals sharp friction between prosecutors and the bench. Following his December 2025 indictment, Spektor initially pleaded not guilty. His defense attorney publicly claimed that the disputed transfers represented voluntary, user-initiated transactions rather than theft. That position fell apart in court. On Sept. 2, 2026, Spektor abandoned his defense and pleaded guilty to the entire 31-count indictment. The charges included first-degree money laundering, first-degree grand larceny, and first-degree criminal possession of stolen property.
District Attorney Eric Gonzalez fought for a significantly harsher punishment. Prosecutors demanded a prison sentence ranging from seven to 21 years and formally opposed the four-to-12-year indeterminate sentence attached to Spektor’s plea deal. Justice Chun overruled prosecutorial objections and imposed the shorter term. Alongside prison time, the court ordered Spektor to forfeit property valued at over $500,000 and issued a restitution order demanding $15.944 million to reimburse victims.
Whether victims ever see that $15.944 million remains doubtful. Seized physical cash and frozen cryptocurrency accounts total roughly $505,000—barely 3% of total calculated victim losses. If Spektor gambled away $6 million and squandered millions more on personal expenses, the money simply does not exist. Restitution judgments sound firm on court dockets. Enforcing them against an incarcerated 23-year-old with depleted assets is another matter entirely. Similar enforcement limits have appeared in judicial sentences in major crypto heist cases, where asset dissipation routinely leaves victims with pennies on the dollar.
Exchange Protections and the Persistence of Support Fraud
Impersonation fraud remains one of the most persistent threats facing retail cryptocurrency holders. Automated smart contract audits cannot protect a user who willingly transfers private keys or sends funds to an attacker's wallet under duress. Security researchers note that phone-based social engineering works precisely because attackers exploit urgency, fear, and authority. A professional-sounding caller claiming an account is actively being drained triggers immediate panic.
Major exchanges continue updating customer warning systems, emphasizing that support staff will never request money transfers, demand seed phrases, or ask for two-factor login codes over the phone or email. Yet attackers adapt. They buy targeted contact lists, deploy automated call spoofing tools, and hire native English speakers to run phone scripts. Spektor’s case proves that a single individual operating out of a bedroom can steal tens of millions using little more than spoofed caller ID and stolen customer records.
A four-year minimum state prison sentence sends a clear message to young cybercriminals operating on Telegram and Discord. But will prison terms for individual operators actually curb support impersonation scams, or will organized fraud networks simply absorb the risk and keep calling?







































