The oldest trick in the con artist’s handbook, updated for the crypto age: call someone pretending to be from a trusted institution, create enough panic, and walk away with their life savings. In this case, the life savings happened to be more than 4,100 Bitcoin, worth over $240 million at the time of the theft.
Malone Lam, a 22-year-old Singaporean national, is scheduled to appear in a U.S. federal court on September 9, 2026, to enter a guilty plea linked to one of the largest Bitcoin thefts ever prosecuted on American soil.
How the scheme worked
Lam and his associates allegedly impersonated representatives from both Google and the Gemini crypto exchange, contacting a wealthy investor based in Washington, D.C.
The goal was straightforward, even if the execution was elaborate: convince the target that his accounts were compromised, then talk him into handing over security codes and access credentials. Once inside, the group transferred his Bitcoin holdings out of his control entirely.
The theft occurred in August 2024, though the broader criminal operation had been running since approximately October 2023. By the time authorities dismantled it, the group had been linked to thefts totaling more than $263 million across multiple incidents stretching through March 2025.
The FBI arrested Lam in September 2024 at a mansion in Miami, a detail that says everything about how the stolen funds were being spent. Prosecutors allege the group converted Bitcoin into cash and then burned through it: dozens of sports cars, private jets, and a single nightclub visit in Los Angeles that reportedly ran to over $569,000.
A landmark prosecution
This case carries legal significance that extends well beyond the dollar amount. It marks the first time a Bitcoin-related prosecution has been brought under the Racketeer Influenced and Corrupt Organizations Act, better known as RICO, a statute historically associated with organized crime syndicates rather than crypto theft rings.
Eighteen people have been indicted in connection with the scheme. Ten have already pleaded guilty ahead of Lam’s scheduled hearing, suggesting prosecutors have built a durable case from the inside out. Lam himself faces a minimum sentencing guideline of 14 years in prison if the plea proceeds as expected.
The operation also had a physical dimension that investigators found notable. The group reportedly conducted home burglaries specifically to steal hardware wallets, the small USB-like devices that store crypto private keys offline.
What this means for crypto security
Exchanges invest heavily in technical infrastructure, multi-factor authentication, and blockchain-level security. None of that matters if an attacker can simply call your customer and impersonate your support team.
Gemini’s brand was used as a prop in this scheme, though the exchange itself was not compromised at the infrastructure level.
For individual holders of significant crypto assets, the case reinforces several uncomfortable realities. Legitimate exchanges and platforms do not initiate unsolicited calls asking for security codes. Any unexpected contact claiming to be from a financial institution or exchange, requesting credentials or urgent account action, should be treated as a red flag regardless of how official it sounds.
Ten guilty pleas already secured, a lead defendant scheduled to follow, and a case that federal prosecutors are framing as organized crime rather than opportunistic fraud.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

2 hours ago
26








English (US) ·