Malone Lam did not break Bitcoin. He called someone. On 18 August 2024, Lam and a co-conspirator phoned a Genesis creditor in Washington, D.C., posing first as Google support and then as Gemini support, and talked him into resetting his two factor authentication. Over 4,100 bitcoin moved out, worth more than $230 million that day. On 9 September 2026 Lam pleaded guilty to federal racketeering conspiracy. He faces up to 20 years.
Key Takeaways
- No smart contract was exploited, no private key was cracked, and no exchange was breached. The attack was a phone call and a screen share.
- The victim was a creditor of the collapsed lender Genesis, which means the attackers knew a large distribution had just landed. The target list came from a public bankruptcy process.
- 4,100 bitcoin left in a single session on 18 August 2024, valued above $230 million at the time and charged at over $245 million as the case developed.
- Arrests came 31 days later, on 18 September 2024, after on chain investigators traced the laundering.
- Eighteen people have been charged. Eleven have pleaded guilty, Lam being the eleventh, on 9 September 2026.
- The group used mixers, VPNs, peel chains, pass through wallets and multiple exchanges. None of it worked for a month.
- Roles included database hackers, target identifiers, callers, money launderers and residential burglars who went after hardware wallets in person.
Table Of Contents
- What Actually Happened On 18 August 2024
- How The Attack Worked
- Why This Victim, And Why That Week
- Where The Money Went, And Why It Did Not Stay Hidden
- The Network Behind It
- Where The Case Stands Now
- What This Changes If You Hold Crypto
- The Mistakes That Made It Possible
- Frequently Asked Questions
What Actually Happened On 18 August 2024
According to the indictment filed by the U.S. Attorney’s Office for the District of Columbia, Malone Lam, then 20 and a citizen of Singapore, and Jeandiel Serrano, then 21, fraudulently obtained access to a Washington, D.C. victim’s cryptocurrency accounts through communications with that victim, and moved more than 4,100 bitcoin out on 18 August 2024.
Lam operated online under the handles “Anne Hathaway,” “$$$” and “King Greavy.” Serrano used “VersaceGod” and “@SkidStar.” Both were arrested on 18 September 2024, Lam in Miami and Serrano in Los Angeles, 31 days after the theft.
| Date | Event |
|---|---|
| 18 August 2024 | Over 4,100 BTC moved from the victim’s accounts |
| 18 September 2024 | Lam arrested in Miami, Serrano in Los Angeles |
| October 2024 | Initial indictment filed, case 24-CR-417 |
| May 2025 | Superseding indictment expands the charges |
| 2025 to 2026 | Twelve further suspects charged, total reaches 18 |
| 9 September 2026 | Lam pleads guilty to RICO conspiracy |
| 8 December 2026 | Status hearing scheduled |
One correction worth making, because it is repeated constantly in coverage that has not been updated. Lam is no longer someone who “has been charged.” He entered a guilty plea on 9 September 2026. He was 20 at indictment and is 22 now. The $230 million figure is the value of the bitcoin on the day it was taken; the case has been described at over $245 million as charges expanded.
How The Attack Worked
Every technical control the victim had was working correctly. The attackers went around all of them by asking. Prosecutors and the investigators who traced the funds describe a sequence that is depressingly simple.
Step One: The Google Support Call
The first contact came as a call claiming to be Google support, warning of unauthorised access to the victim’s account. This is the part that does the real work. It reframes everything that follows as the victim defending himself, rather than being attacked. Every subsequent request sounds like help.
Step Two: The Exchange Call
A second caller then posed as a representative of the Gemini exchange. Two independent sources telling the same story is the oldest confidence technique there is, and it is far more convincing than one caller pushing harder.
Step Three: The Two Factor Reset
The objective was to get the victim to reset his own two factor authentication credential. Note the direction of that action. Nothing was bypassed and nothing was broken. The account holder was walked through disabling his own protection, on the understanding that he was securing the account.
Step Four: Access To Stored Credentials
Coverage of the plea describes the co-conspirators manipulating the victim into revealing Google Drive access and security codes. If keys, seed phrases or recovery material are stored in cloud documents, the cloud account is the wallet. Everything downstream of that point was bookkeeping.
There is no zero day in this chain. There is no chain level exploit. This is the same structural point I made about what actually got liquidated when the Clarity Act failed: the headline names the technology, but the mechanism is almost always human.
Why This Victim, And Why That Week
Because he was a Genesis creditor, and the distribution had just arrived. This is the detail most coverage skips, and it is the most important one in the entire case.
Genesis was the crypto lender that collapsed in the 2022 contagion. Its creditors went through bankruptcy proceedings, and those proceedings produced distributions. A bankruptcy is a public process. Filings name creditors. Schedules indicate scale. Distribution timing is announced. A large holder receiving a large payout is not a secret, it is a court record.
So the target was not selected at random and was not found by accident. The network is alleged to have identified people holding significant cryptocurrency through hacked databases, information purchased on the dark web, and phishing emails. A public creditor list is the cheapest version of the same input.
The operating lesson generalises well past crypto. Any event that publicly signals you have just come into money creates a window: a bankruptcy distribution, a funding round announcement, a property sale, an acquisition, a lawsuit settlement, a token unlock. The exposure is not the money. It is that the money was announced.
Where The Money Went, And Why It Did Not Stay Hidden
The Department of Justice describes the laundering stack directly: mixing services, virtual private networks, peel chains, pass through wallets and multiple exchanges. That is not an amateur list. Peel chains in particular are designed to defeat exactly the kind of analysis that caught them.
A peel chain takes a large balance and repeatedly splits off a small amount to a new address while the remainder moves on, again and again, so that the trail becomes thousands of small hops rather than one traceable transfer. It works against a human reading a block explorer. It does not work against clustering heuristics run at scale.
What broke the operation was not the laundering. It was the spending.
| Category | Reported Detail |
|---|---|
| Vehicles | Over 30 cars, including custom Porsches, Lamborghinis and Ferraris |
| Watches | A single watch reported at $2 million |
| Nightlife | $569,000 in one Los Angeles visit |
| Property | Rental mansions in Miami and Los Angeles |
| Other | International travel, jewellery, designer handbags |
On chain investigators, including the researcher who publishes as ZachXBT, flagged the movement publicly and characterised it as a sophisticated social engineering attack. Public attribution of that kind narrows a field fast, and the off chain behaviour did the rest. Nightclub tabs, car registrations and rental agreements are not anonymous. Thirty vehicles are not anonymous.
This is the part the people running these operations consistently get wrong. They treat the technical laundering as the whole problem and then convert the proceeds into the most conspicuous possible assets inside a month. The blockchain analysis identifies a cluster. The Lamborghini identifies a person.
The Network Behind It
This was not two people. It was an organisation, which is why the charge is racketeering. Prosecutors describe a structure with distinct functions: database hackers, organisers, target identifiers, callers, money launderers, and residential burglars who targeted hardware wallets in person.
That last role deserves a pause. A network built around phone calls also had people breaking into homes to take hardware wallets. The conspiracy is described as beginning in 2023 and reaching across California, Connecticut, New York, Florida and international locations, with members recruited through online gaming platforms.
A later round of charges named twelve additional suspects: Marlon Ferro, 19, of Santa Ana; Hamza Doost, 21, of Hayward; Conor Flansburg, 21, of Newport Beach; Kunal Mehta, 45, of Irvine; Ethan Yarally, 18, of Richmond Hill, New York; Cody Demirtas, 19, of Stuart, Florida; Aakash Anand, 22, of New Zealand; Evan Tangeman, 21, of Newport Beach; Joel Cortes, 21, of Laguna Niguel; John Tucker Desmond, 19, of Huntington Beach; and two individuals identified by alias. Charges are allegations, and every one of those defendants is entitled to the presumption of innocence.
The ages are the story. Most of this group was between 18 and 22. Lam reportedly left school in the eighth grade. Recruitment ran through gaming platforms. The barrier to entry for stealing a quarter of a billion dollars was a headset and a script.
Where The Case Stands Now
Lam pleaded guilty to federal racketeering conspiracy on 9 September 2026. The maximum sentence for that count is 20 years. A status hearing is scheduled for 8 December 2026. He is the eleventh of eighteen charged defendants to enter a guilty plea.
Assets seized reportedly include more than 30 vehicles and a watch valued at $2 million. Whether the victim is made whole is a separate question from whether the defendants are sentenced, and the two rarely track each other. Proceeds converted into depreciating luxury goods and spent on nightclubs do not come back at full value.
What This Changes If You Hold Crypto
Nothing in this case argues for better software. Every item below is a process change, and most of them cost nothing.
- Treat every inbound contact as hostile. Google does not call you. Your exchange does not call you about suspicious activity. If someone contacts you, the contact itself is the red flag, regardless of what the caller ID says.
- Hang up and call back on a number you look up yourself. Not the number they give you, not the number in the email, not a search ad. This one step defeats the entire attack chain described above.
- Never reset or disable two factor authentication while someone is on the line. There is no legitimate support process that requires it. Treat that request as proof of fraud and end the call.
- Keep keys and seed phrases out of cloud storage. Not in Drive, not in a notes app, not in email, not in a password manager entry labelled “wallet.” If a document holds your recovery phrase, your cloud login is your wallet.
- Assume your holdings are already known. Hacked databases, dark web lists, breach dumps and public court filings mean the target list exists whether you helped or not. Operate as though someone has it.
- Add friction to large withdrawals. Whitelisted addresses with a mandatory delay, a separate signing device, a second approver. Friction is what buys you the hours in which a scam collapses.
- Separate the noisy wallet from the quiet one. A hot wallet you actually use, and cold storage nobody can connect to you socially. The 4,100 bitcoin in this case sat where the attack could reach them.
- Do not announce liquidity events. Distributions, raises, exits and sales. If your inbox knows, assume a list somewhere knows.
The Mistakes That Made It Possible
- Believing self custody is a security product. Self custody moves the attack surface from an institution to you. It does not shrink it. In this case the surface was a phone.
- Trusting inbound urgency. The opening move was a warning about unauthorised access. Manufactured urgency exists to prevent the one thing that would have ended it: hanging up and verifying.
- Treating two people as corroboration. A Google caller and a Gemini caller confirming each other is one attacker with two phones, not two sources.
- Keeping recovery material where convenience lives. Cloud storage is designed for access. Recovery phrases require the opposite property.
- Assuming laundering is the hard part. The defendants had a real laundering stack and were still arrested inside 31 days, because spending is louder than moving.
- Reading this as a crypto story. The identical script empties a brokerage account, a business bank account or a payroll system. Crypto made it irreversible, it did not make it possible.
Frequently Asked Questions
How did Malone Lam steal $230 million in Bitcoin?
Through social engineering, not hacking. On 18 August 2024, callers posing as Google support and then as a Gemini exchange representative convinced a Washington, D.C. victim to reset his two factor authentication and reveal Google Drive access and security codes. Over 4,100 bitcoin, worth more than $230 million at the time, were transferred out. No blockchain, exchange or wallet software was breached.
Who was the victim of the Malone Lam crypto theft?
An individual in Washington, D.C. who was a creditor of the collapsed crypto lender Genesis. The bitcoin taken was connected to a distribution received through the Genesis bankruptcy process, which is part of why investigators describe the targeting as deliberate rather than opportunistic.
Has Malone Lam been convicted?
He pleaded guilty. On 9 September 2026 Lam, now 22, entered a guilty plea to federal racketeering conspiracy, which carries a maximum sentence of 20 years. A status hearing is scheduled for 8 December 2026. He is the eleventh of eighteen charged defendants to plead guilty in the case.
How were they caught so quickly?
Thirty one days passed between the theft and the arrests on 18 September 2024. On chain investigators, including the researcher known as ZachXBT, publicly traced the movement of funds. The defendants then converted proceeds into more than 30 luxury vehicles, a $2 million watch, rental mansions and nightclub spending reported at $569,000 in a single Los Angeles visit. Mixers and peel chains obscure transactions. They do not obscure a car registration.
Could this attack work on me?
The attack requires no technical sophistication on the victim’s side to succeed, which means account size is the only reason it has not been attempted. The single most effective defence is a rule rather than a tool: never act on an inbound contact, always hang up and call back on a number you look up independently, and never change security settings while anyone is on the line.
Is this the largest crypto theft from an individual?
It is among the largest ever charged against a single victim. Larger totals exist, but they generally involve exchanges, bridges or protocols rather than one person’s holdings. The distinguishing feature here is the ratio: a quarter of a billion dollars taken from one individual using a telephone.
The Bottom Line
A 20 year old who left school in the eighth grade took more from one person in one afternoon than most venture funds deploy in a year, and the entire technical component was a phone call and a screen share. Everything the industry argues about, custody models, chain security, protocol design, was irrelevant to the outcome.
Two things are worth carrying out of this. The first is that the targeting came from a public process. A bankruptcy distribution told the attackers who to call and roughly when. Any event that publicly signals new liquidity does the same job.
The second is that irreversibility changes the arithmetic of a mistake. A wire can sometimes be recalled and a card charge can be disputed. A confirmed bitcoin transaction is final. When the undo button does not exist, the control has to sit before the action, which means process, delay and verification rather than software.
If you want the structural way to hold this exposure rather than the self custody way, I keep a running breakdown of crypto ETFs, their fees, staking treatment and what does not exist yet, including the Bitcoin products specifically. Custody by a regulated institution carries its own risks, and counterparty failure is exactly what produced the Genesis creditor in this story. There is no option without a tradeoff. There is only choosing which one you are equipped to manage.
Related reading: the September 2026 rotation and a crypto forecast with no price in it.
Sources
- U.S. Department of Justice, U.S. Attorney’s Office for the District of Columbia, indictment announcement
- NBC Miami, guilty plea, September 2026
- Decrypt, arrests and the Google support impersonation
- BleepingComputer, twelve additional suspects charged
Malone Lam has pleaded guilty. Every other individual named here is charged, not convicted, and is entitled to the presumption of innocence. Nothing here is legal or investment advice. I am not a lawyer and not a financial advisor.
