toobit
Buy crypto
Buy cryptoThe fastest path to your first trade
P2P tradingTrade at the best prices with multiple local payment options
Bank cardPay with Visa or Mastercard
Third-partyPay via MoonPay, Advcash, Simplex, and more
DepositTransfer from another wallet
Markets
OpportunitiesTrack market sentiment and top movers
OverviewReal-time prices for all trading pairs
Futures
USDT-M PerpetualContracts settled in USDT
USDC-M PerpetualContracts settled in USDC
Event ContractsTrade on the outcome of market events
Prediction MarketTurn insights into value
Lite PerpetualSimple contracts made for easy trading
Demo TradingPractice trading in a risk-free environment
Trading BotsAutomated grid and DCA strategies
TradFi
Trading
SpotBuy and sell cryptocurrencies
DEX +Trade popular on-chain Web3 tokens in seconds
LaunchpadAccess early-stage token listings
ConvertZero-fee instant asset swaps
API TradingAutomate trading strategies with custom scripts and apps
Toobit SynapseMarket insights driven by AI analysis
Toobit x TradingViewTrade directly from TradingView charts
Agent Trade KitEquip AI agents with trading and account skills
Rewards
Copy
Follow Lead TradersCopy trades from top-performing profiles
To be a Lead TraderShare your trades and earn commissions
More
Finance
EarnPut your idle assets to work
Partnerships
Broker ProgramMonetize API volume and trading infrastructure
Ambassador ProgramRepresent the exchange and earn monthly incentives
Toobit x Nova.MemeLaunch and trade memecoins with instant liquidity
Learn
AcademyTechnical analysis and crypto trading guides
Support CenterSelf-service help and 24/7 technical assistance
Announcement CenterLatest listings, campaigns, and official product news
NewsBreaking crypto news and market moves
BlogMarket insights and exchange updates
Explore
Toobit VIP ProgramEnjoy fee discounts and many exclusive rewards.
InsightsStay updated on the latest crypto news
Toobit CommunityConnect with The Hive, our global community of traders
3 years togetherCelebrate our journey and the community that built it
About usThe story behind the award-winning exchange
Suggestions & FeedbackShare your ideas to improve the exchange
Proof of ReservesTrust built on 100% reserves
Log in
Sign up
🔥BTC/USDT
Scan to download
iOS or Android app
More download options

Brooklyn scammer steals $16 million crypto

2026-09-24 08:26

Ronald Spektor, a Brooklyn resident, has been sentenced to four to 12 years in prison after pleading guilty to running a social-engineering scheme that prosecutors said stole nearly $16 million in cryptocurrency from about 100 people over roughly a year.

The Brooklyn District Attorney’s Office said Spektor was also ordered to forfeit more than $500,000 in assets and pay nearly $16 million in restitution. The sentence followed his Sept. 2 guilty plea to a 31-count indictment that included first-degree money laundering, first-degree grand larceny and first-degree criminal possession of stolen property.

Prosecutors had sought a prison term of seven to 21 years. The sentence imposed leaves Spektor facing a substantially shorter minimum term, while the maximum could keep him incarcerated for 12 years.

The case centers on a form of theft that has become one of the most persistent threats facing cryptocurrency holders: criminals posing as trusted customer-support workers, creating urgency around an alleged account compromise, and persuading targets to move their own funds.

Fake support calls led victims to transfer crypto

According to the Brooklyn District Attorney’s Office, Spektor contacted targets while posing as a customer service representative. He told them that a hacker had placed their cryptocurrency accounts at risk and offered a supposed solution: moving assets to a “new wallet.”

Victims believed they were transferring their cryptocurrency to addresses they controlled, prosecutors said. Instead, the new wallets were accessible to Spektor, allowing the assets to be moved and laundered after the transfers were completed.

The scheme generated total losses of $15,944,000, according to the district attorney’s office. Some victims lost $1 million or more.

The fraud did not depend on defeating the cryptography behind a wallet or breaking into an exchange’s internal systems. It relied on manipulating users during a stressful moment, turning a security warning into a prompt to authorize a transfer themselves. Cryptocurrency transactions are generally irreversible once confirmed on a blockchain, giving victims little opportunity to recover funds after a transfer reaches an address controlled by a scammer.

Blockchain records helped investigators trace the scheme

Investigators connected Spektor to the thefts through transaction records, blockchain analysis, digital forensics and evidence obtained under multiple search warrants, the Brooklyn District Attorney’s Office said.

Prosecutors said Spektor’s home IP address was tied to several wallets associated with the stolen cryptocurrency. The allegation illustrates a recurring tension in crypto crime: wallet addresses may be pseudonymous, but movements of funds are recorded publicly on many blockchains and can be examined alongside device, internet and account records.

Authorities said the stolen assets were laundered through repeated swaps across different cryptocurrency venues before being consolidated at “cash-out points.” The funds were then converted into other cryptocurrencies, used for wagers, turned into cash, or spent on gift cards and digital assets, prosecutors said.

Repeated swaps can make tracing more labor-intensive by spreading assets across services and token types. They do not erase the underlying transaction history, particularly when investigators can identify entry and exit points where digital assets interact with accounts, payments or other identifiable activity.

The case fits a larger social-engineering threat

The prosecution arrives amid continued concern over customer-support impersonation campaigns, which exploit the fact that many users expect help desks to contact them after a security alert.

In a separate disclosure last year, Coinbase said criminals had bribed and recruited overseas customer-support agents to obtain customer data for social-engineering attacks. Coinbase said the incident affected less than 1% of its monthly transacting users and that passwords, private keys and customer funds were not exposed.

Even where attackers do not obtain direct access to customer accounts, personal information can make an impersonation attempt more convincing. Details such as a user’s name, phone number, email address or account history can give criminals enough material to present a credible story about a compromised account.

The Federal Bureau of Investigation reported that people in the United States lost more than $11 billion to digital-asset fraud during 2025, according to the agency’s official data. That total covers several types of cryptocurrency crime, rather than customer-support impersonation alone, but it shows the scale of losses tied to fraud conducted through digital assets.

Account security often depends on resisting urgency

The Spektor case offers a practical reminder that an unexpected call, text message or email claiming an account has been compromised should be treated as unverified, even when the caller appears to know personal details.

Users can reduce exposure by ending the unsolicited contact and reaching a platform through the support page or phone number listed on its official website. Entering the company’s web address directly, rather than following a link in a message or relying on a search advertisement, can reduce the risk of being directed to a fraudulent support page.

No legitimate support representative needs a customer to disclose a recovery phrase, private key or wallet seed phrase. Those credentials provide control over a self-custody wallet, and anyone who obtains them can generally move the associated assets without further approval.

Hardware wallets can also limit some online risks by keeping private keys on a dedicated device, but they do not eliminate social engineering. A user who is persuaded to approve a malicious transaction, reveal a recovery phrase or send funds to a scam address can still lose assets. The most effective defense remains verifying any claimed emergency through an independent channel before moving cryptocurrency.


Worried about crypto scams? Learn essential protection steps in this social engineering security guide to safeguard your assets.

Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

About
About us
Terms of Use
Privacy Policy
Risk disclosure
Toobit Community
Announcement Center
Security solutions
Toobit Shield
Proof of Reserves
Services
Trading
Futures
Copy
Affiliate Program
API
Listing application
Bug bounty
Support
Support Center
Academy
Referral
Fee rate policy
Official verification
Network monitoring
Suggestions & Feedback
Buy crypto
Buy Bitcoin
Buy Ethereum
Buy Dogecoin
Buy TON
Buy SOL
Buy XRP
Contact
Customer Support
support@toobit.com
Business
listing@toobit.com
Overview
market@toobit.com
Legal
legal@toobit.com
Apps
Google Play
App Store
Android APK
Community
TwitterMediumYoutubeDiscordRedditFacebookCoinMarketCapCoinCodexCoinGeckoLinkedinQuoraThreads
Download app
Warning

© 2026 Toobit.com. All rights reserved.