cointelegraph.com Teen Scammer Pleads Guilty After Stealing $13M in Crypto for Lavish Lifestyle
Article Content
- •Trenton Richard Johnston stole over $13 million in crypto via social engineering scams.
- •He impersonated employees from Google and Trezor to access victims' accounts.
- •Johnston used stolen funds for luxury purchases, including cars and private jets.
Trenton Richard Johnston, a Canadian teen, stole over $13 million in cryptocurrency through social engineering scams. He impersonated employees from Google and Trezor to gain access to victims' crypto accounts. Johnston was arrested in March 2026 during a traffic stop, where investigators uncovered his fraud scheme. In May 2026, he was charged and recently pleaded guilty to conspiracy to commit money laundering. The stolen funds were used to finance a luxurious lifestyle, including luxury cars and private jet trips. Johnston's actions highlight the growing threat of social engineering in the cryptocurrency space. He has since returned approximately 53.16 Bitcoin and 275.23 Ether, valued at $3.7 million. Prosecutors recommend a sentence of 51 to 63 months in prison for Johnston.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Coinbase in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…