Impersonating customer service, he made phone calls for twenty months—earning himself a sentence of twelve years.

A 23-year-old man from Brooklyn was sentenced to a maximum of twelve years in prison. Between April 2023 and December 2024, he impersonated the customer support of a trading platform, using the pretext that the account faced risk to trick about one hundred users into transferring their assets to wallets he controlled, involving nearly $16 million. The crimes took place over nearly two years, and the victims were spread across different states.

The sentencing occurred on September 23. Before that, he pleaded guilty to 31 counts, including major theft and money laundering. Prosecutors said he also bragged about these acts online under a pseudonym. The 31 charges show this was not a one-off incident, but an organized, continuous operation.

The structure of cases like this is worth noting. The attacks don’t rely on vulnerabilities; they rely on mimicking authority and exploiting fear of loss. Victims complete transfers within minutes, with almost no avenues for recourse afterward. Once a transfer is recorded on-chain, the chances of reversing it are virtually zero.

For platforms, interventions are limited but clear: customer support will not request recovery seed phrases and will not ask users to make transfers. This point needs to be emphasized repeatedly, because each successful social engineering attempt makes the next round of impersonation more accurate.

Phone calls impersonating customer service are cheaper than any vulnerability.

#安全 #law enforcement