Malone Lam is set to stand before a federal judge in Washington, D.C. on September 9, 2026, and change his plea to guilty in what prosecutors call the largest known single-victim Bitcoin theft in U.S. history. The case traces back to an August 2024 phone call in which Lam and his co-conspirators, posing as Google and Gemini support staff, talked a D.C. resident out of more than 4,100 Bitcoin, worth over $230 million at the time and closer to $240 million in recent reporting. Two years later, the theft has grown into an 18-defendant racketeering prosecution, the first Bitcoin case the Department of Justice has built under formal RICO conspiracy charges.

The plea deal carries sentencing guidelines that recommend at least 14 years in prison for Lam, according to court filings reviewed by Fox News. If he enters the plea as scheduled, Lam becomes the 11th defendant in the sprawling case to admit guilt, following ten co-conspirators who have already pleaded guilty to charges tied to the theft and the laundering operation that followed it. The case has become a reference point for how organized, human-layer social engineering now rivals technical exploits as the biggest threat to large Bitcoin holders.

What Happened at the September 2026 Plea Hearing

Lam, a Singaporean national born in July 2004, was scheduled for a plea agreement hearing in the U.S. District Court for the District of Columbia this week. Federal prosecutors describe him as the ringleader of a network of young men, mostly in their late teens and early twenties, who ran a coordinated scheme to identify wealthy cryptocurrency holders, trick them into surrendering account access, and drain their wallets within hours. Court records reviewed by NBC News confirm the theft occurred in August 2024, and wire reporting picked up by KSAT details the arrests that followed on September 18, 2024, once investigators traced the stolen Bitcoin through exchange accounts and mixing services.

Under the plea agreement terms reported this week, Lam faces a sentencing range that starts at 14 years, a figure that reflects both the scale of the theft and his role as the alleged organizer of the wider network. That range sits above the roughly six-year sentences handed to several co-conspirators who took plea deals earlier as money-laundering specialists rather than as the scheme’s architects, based on court filings cited by Fortune.

How 4,100 Bitcoin Vanished in a Single Afternoon

The theft did not rely on a smart contract bug, a stolen private key, or a compromised exchange server. It relied on a phone call. Prosecutors say Lam, Jeandiel Serrano, and other conspirators contacted the D.C. victim and identified themselves as security staff from Google and from Gemini, the cryptocurrency exchange. They warned him his accounts had been breached by an outside party and walked him through a series of “verification” steps designed to look like standard account recovery.

The Google and Gemini Impersonation Script

According to the original indictment, the group manipulated login alerts to make it appear that suspicious activity was already underway on the victim’s accounts, then used that manufactured urgency to extract his Google Drive access and his account security codes. Once inside, they reset recovery settings and multi-factor authentication, cutting the victim out of his own accounts within a short window. From there, more than 4,100 Bitcoin moved out of his holdings and into wallets controlled by the group.

Laundering Through Mixers and Peel Chains

Once the coins were in hand, the group split them into smaller batches and pushed them through so-called peel chains, a laundering technique that strips off portions of a balance across many transactions to break the trail an investigator would otherwise follow on-chain. They routed funds through multiple centralized exchanges and mixing services, using VPNs to mask their location. The approach worked well enough to briefly hide the scale of the theft, but on-chain investigator ZachXBT and federal agents eventually reconstructed the flow of funds well enough to identify the exchange accounts holding tens of millions of dollars in stolen crypto.

Who Is Malone Lam?

Lam is described in a biographical case summary as an eighth-grade dropout from Singapore who split his time between Miami and Los Angeles in the months after the theft. He was 20 years old when the original indictment was unsealed in September 2024 and is now 22 as the case heads toward a plea. Serrano, his alleged closest collaborator in executing the D.C. theft, is a Los Angeles resident who was around 21 at the time of the scheme. Court documents also connect the pair to a wider circle that includes Veer Chetal, identified by the alias “Wiz,” who pleaded guilty in November 2024 and had roughly $500,000 in cash recovered from a duffel bag along with $37 million in seized crypto assets.

Investigators say Serrano made a costly operational mistake: he failed to mask his IP address while opening an account at an exchange that briefly held close to $30 million of the stolen funds, a lead that helped agents connect the group to the theft far faster than the laundering scheme was designed to allow.

The Spending Spree That Blew Their Cover

Within roughly a month of the theft, the group had converted a large share of the stolen Bitcoin into a visible, traceable lifestyle. Court records and reporting from Fox News and Fortune describe purchases of more than 30 vehicles, including custom Porsches, Lamborghinis, and Ferraris, alongside a $2 million watch bought by Lam and a roughly $500,000 watch recovered from Serrano. The group rented mansions in Los Angeles and Miami, including one property in Encino, California, at $47,500 a month, and spent close to $4 million at nightclubs over a single month. Lam alone reportedly spent more than $569,000 during one night out at a Los Angeles club.

That spending pattern is a recurring failure mode in large crypto thefts. Money that moves through mixers can be hard to trace on-chain, but cash converted into cars, jewelry, and short-term rentals leaves a conventional paper and video trail that federal agents know how to follow. The FBI has noted a nearly 50% rise in crypto investment fraud complaints in 2025, a trend investigators link partly to the visibility that comes when young, first-time criminal networks convert stolen crypto into luxury goods almost immediately, based on reporting from Fortune.

From Wire Fraud to a RICO Case: 18 Defendants and Counting

The original September 2024 indictment charged only Lam and Serrano with conspiracy to commit wire fraud and conspiracy to launder monetary instruments, each carrying a maximum 20-year sentence. By May 2025, the Justice Department had expanded the case into a full Racketeer Influenced and Corrupt Organizations Act conspiracy, adding 12 more defendants and tying the network to roughly $263 million in cryptocurrency stolen across multiple schemes and victims, not just the single D.C. theft, according to reporting from The Record. That expansion made this the first Bitcoin theft case the DOJ has prosecuted under RICO, a statute more commonly associated with organized crime and drug trafficking networks than crypto fraud.

The current count stands at 18 total defendants. Ten had pleaded guilty as of the most recent court filings, with Lam’s expected plea marking the eleventh. Prosecutor William Hart, according to Fortune’s review of court transcripts, described the defendants’ spending as a lifestyle built entirely on a foundation of fraud, a framing that has shaped how the DOJ has argued for lengthy sentences even for defendants who present as young, first-time offenders.

MetricFigure
Bitcoin stolen from D.C. victim (Aug. 2024)4,100+ BTC
Value at time of theft (Aug. 2024)Over $230 million
Value cited in Sept. 2026 coverageOver $240 million
Total network theft alleged under RICO~$263 million
Total defendants charged18
Guilty pleas entered before Lam’s hearing10
Lam’s minimum sentencing guideline14 years
Vehicles purchased by the group30+
Single-night nightclub spend (Lam)$569,000
Monthly nightclub spending (group)~$4 million
Monthly Encino, CA rental$47,500
Cash recovered from co-defendant Veer Chetal~$500,000

Timeline: From Theft to Plea Deal

  • August 18, 2024: Lam, Serrano, and conspirators allegedly pose as Google and Gemini support to trick the D.C. victim, draining 4,100+ Bitcoin.
  • September 18, 2024: Lam and Serrano are arrested after investigators trace laundered funds through exchange accounts.
  • Late September 2024: The original two-defendant federal indictment is unsealed, charging wire fraud and money-laundering conspiracy.
  • November 2024: Co-defendant Veer Chetal pleads guilty. Agents recover roughly $500,000 in cash and $37 million in crypto tied to him.
  • May 2025: DOJ expands the case into an 18-defendant RICO conspiracy covering roughly $263 million in total thefts.
  • Through 2025 and early 2026: Ten defendants plead guilty. One co-conspirator’s sentencing is set for April 24, 2026, before Judge Colleen Kollar-Kotelly.
  • September 9, 2026: Lam is scheduled for a plea agreement hearing in D.C. federal court, with sentencing guidelines starting at 14 years.

Why the DOJ’s Crypto Enforcement Capacity Matters Here

The timing of this case sits awkwardly against a broader retreat in federal crypto enforcement. The Justice Department disbanded its dedicated cryptocurrency crimes prosecution unit in 2025, a move that lined up with the current administration’s hands-off approach to digital-asset regulation. Building an 18-defendant RICO case, with its web of laundering specialists, seized assets, and cooperating witnesses, is exactly the kind of long-running, resource-heavy prosecution that a specialized unit is designed to support. Fortune’s reporting frames the Lam case as a test of whether the DOJ can still deliver that kind of prosecution without the team built specifically to do it.

That tension matters beyond this one case. Crypto-focused fraud rings have grown more organized since 2024, and prosecutors increasingly need RICO-style tools to charge coordinated networks rather than isolated pairs of hackers. Whether the Lam prosecution closes cleanly, with all 18 defendants sentenced, will shape how aggressively federal prosecutors pursue similar networks going forward.

How This Heist Compares to Crypto’s Biggest Thefts

Data compiled by Comparitech’s tracker of the biggest cryptocurrency heists shows the Lam case stands out less for its dollar total, which trails several exchange-level breaches, and more for its method. Every other entry near the top of the list involves a compromised hot wallet, a manipulated multisig signing interface, or a smart contract flaw. The Lam case involved none of that. It targeted one person, using a phone call and a fabricated security emergency, and it worked in a matter of hours.

IncidentDateAmount StolenAttack Method
BybitFebruary 2025~$1.46–1.5 billionManipulated cold-wallet signing interface (Lazarus Group)
Ronin NetworkMarch 2022~$620–625 millionCompromised validator keys
CoincheckJanuary 2018~$530–547 millionHot wallet vulnerability (NEM theft)
Mt. Gox2011–2014~$470 million (at time)Exchange-wide hot wallet compromise
Malone Lam / D.C. victimAugust 2024Over $230–240 millionSocial engineering, account takeover (single victim)

Ranked purely by dollar value, the Lam theft does not crack the top tier of crypto hacks. Ranked by victim count, it is a category of one: a single individual lost more in one afternoon than most exchanges lose in a full-scale breach. That distinction is why security researchers increasingly treat this case as a template for how attackers now go after individuals with large, identifiable Bitcoin holdings rather than exchanges with layered defenses.

The Rise of “OG” Bitcoin Holder Targeting

Security researchers describe the Lam network’s approach as characteristic of a wider pattern targeting early Bitcoin holders, sometimes called “OG” holders, who accumulated large balances years before today’s security norms existed. These holders are often identifiable through leaked KYC data, breached customer databases, and public wealth signals, then approached with tailored social-engineering scripts that impersonate Google, a specific exchange, or even hardware wallet support lines.

What makes this group of victims attractive is not just balance size. Many OG holders set up their accounts under older security practices, sometimes with recovery options tied to legacy email addresses or phone numbers that are easier to socially engineer than a modern hardware-backed multi-factor setup. Attackers exploit that gap directly, banking on the fact that a technically unsophisticated but wealthy holder is more likely to comply with a convincing account-compromise call than to question it.

Market and Industry Impact

The direct market impact of a single-victim theft, even one this large, is smaller than a major exchange hack because it does not touch exchange solvency or trigger withdrawal freezes. Bitcoin traded near $80,000 in the days around this week’s plea hearing, and the case has not moved broader crypto prices. The impact instead shows up in exchange security posture and in how platforms like Gemini handle account recovery requests tied to large balances.

Exchanges have already tightened manual review requirements for high-value account recovery in the wake of cases like this one, adding extra verification steps and delays specifically for accounts flagged as high balance. Insurance and custody providers serving large individual holders have also cited social-engineering losses, including this case, as justification for requiring multi-party approval on withdrawals above set thresholds. The case has become a reference point in enterprise crypto custody sales conversations, cited alongside exchange-level breaches as evidence that technical security alone does not close the gap.

What Crypto Holders Should Take From This Case

The single clearest lesson from the Lam case is that no exchange or support team will ever call, text, or email asking for security codes, seed phrases, or Google Drive access to verify an account. Any contact that manufactures urgency around a supposed breach and then asks for credentials or recovery codes should be treated as the attack itself, not a response to one.

Large holders can reduce exposure with a few concrete steps: moving recovery options off legacy email and phone numbers, enabling hardware-based multi-factor authentication rather than SMS codes, splitting large balances across cold storage and multisig setups rather than a single hot account, and treating any unsolicited account-flagged contact as a red flag rather than a prompt to act quickly. None of these steps require sophisticated tooling. They require treating social engineering as seriously as a smart contract audit.

Defendant Status: Who Has Pleaded, Who Hasn’t

DefendantAlleged RoleStatus (as of Sept. 2026)
Malone LamAlleged ringleaderPlea hearing scheduled Sept. 9, 2026, guideline minimum 14 years
Jeandiel SerranoClose collaborator, execution of D.C. theftCharged, case ongoing
Veer Chetal (“Wiz”)Laundering, cash handlingPleaded guilty Nov. 2024, ~$37M in crypto seized
Tucker DesmondNetwork participantSentenced to probation
Additional co-defendants (14 total)Laundering specialists, network participants10 guilty pleas entered; remaining cases active

Predictions: Where This Case Goes Next

  1. Lam’s plea will likely be accepted at or shortly after the September 9 hearing, with formal sentencing scheduled for early 2027 given the pace set by earlier co-defendant sentencings.
  2. Expect his final sentence to land close to, but not dramatically above, the 14-year guideline minimum, consistent with the roughly six-year terms given to lower-tier laundering specialists in the same case.
  3. The remaining unresolved defendants in the 18-person RICO case will mostly resolve through plea deals rather than trials, mirroring the pattern of the first ten pleas.
  4. Exchanges will keep tightening manual review on high-value account recovery requests through 2027, treating this case as a cited justification for added friction on large withdrawals.
  5. Expect at least one more DOJ or FBI advisory in late 2026 specifically warning early Bitcoin holders about impersonation scripts modeled on the Google and Gemini approach used here, given the FBI’s already-documented rise in crypto investment fraud complaints.

Historical Context: Social Engineering vs. Technical Exploits

Crypto’s biggest losses have historically come from technical failures: a signing interface that displayed the wrong transaction, a validator key that leaked, a hot wallet with too little cold-storage separation. The Bybit, Ronin, Coincheck, and Mt. Gox incidents all fit that pattern, and industry security spending has followed accordingly, pouring resources into multisig design, cold-storage architecture, and smart contract audits.

The Lam case sits outside that pattern entirely. It is closer in method to a business email compromise scam than to a DeFi exploit, and it succeeded against a target who, by definition, had enough Bitcoin to be worth years of prosecution effort to recover. That gap between where security spending goes and where large individual losses actually originate is likely to widen scrutiny on custody providers and exchanges to build account-recovery friction specifically aimed at social engineering, not just technical intrusion.

Frequently Asked Questions

Who is Malone Lam?

Malone Lam is a Singaporean national, born in July 2004, identified by federal prosecutors as the alleged ringleader of a network accused of stealing over $230 million in Bitcoin from a Washington, D.C. victim in August 2024 through a social-engineering scheme.

How much Bitcoin was stolen in the Malone Lam case?

Prosecutors say the group stole more than 4,100 Bitcoin from a single D.C. victim, worth over $230 million at the time of the August 2024 theft and cited at over $240 million in current reporting. The broader RICO case alleges roughly $263 million in total thefts across multiple schemes and victims.

How did Malone Lam and his network steal the Bitcoin?

The group allegedly impersonated Google and Gemini support staff, convinced the victim his accounts were compromised, and used that manufactured urgency to obtain his Google Drive access and account security codes, which they used to reset recovery settings and drain his Bitcoin holdings.

What sentence does Malone Lam face?

Under the reported plea agreement, sentencing guidelines recommend a minimum of 14 years in prison for Lam, reflecting his alleged role as the organizer of the wider theft and laundering network.

How many people have been charged in the case?

Eighteen defendants have been charged in the expanded RICO conspiracy case. Ten had pleaded guilty before Lam’s scheduled September 9, 2026 hearing, with his plea expected to be the eleventh.

Why is this called the first Bitcoin RICO case?

The Department of Justice expanded the original wire fraud and money-laundering charges into a full Racketeer Influenced and Corrupt Organizations Act conspiracy in May 2025, marking the first time federal prosecutors have used RICO statutes, more commonly applied to organized crime, against a Bitcoin theft network of this scale.

Is this the largest cryptocurrency theft ever?

Not by total dollar value. Exchange-level breaches like the 2025 Bybit hack (~$1.46–1.5 billion) and the 2022 Ronin Network breach (~$620–625 million) are larger overall. The Lam case is instead described as the largest known theft from a single individual victim in U.S. history.

How can Bitcoin holders protect themselves from similar scams?

Security researchers recommend moving account recovery off legacy email and phone numbers, using hardware-based multi-factor authentication instead of SMS codes, and treating any unsolicited contact claiming to be exchange or Google support as a likely attack rather than a legitimate security check, since no legitimate support team asks for security codes or Drive access to verify an account.