Malone Lam, a 22-year-old Singaporean national and recent resident of Miami, pleaded guilty on September 8 in a federal court in Washington to participating as a leader in an international criminal conspiracy that used social engineering to steal and launder cryptocurrency. The U.S. Department of Justice attributes thefts of more than $245 million to the network. The Associated Press reports that one of the largest incidents involved more than 4,100 bitcoin stolen from a single victim in the Washington area.
The story is significant because it overturns a widespread belief about crypto security. Bitcoin was not “hacked”. The blockchain did not stop working, and the cryptography was not broken. The attackers targeted the most vulnerable part of the entire system: people, their credentials, and the processes through which they recover or protect their accounts.
A network born online and organized like an enterprise
According to court documents cited by the DOJ, the conspiracy was active from at least October 2023 through May 2025, linking individuals across California, Connecticut, New York, Florida, and abroad. Members also connected through gaming platforms and used impersonation, social engineering, and in some cases physical intrusions to obtain information needed to drain wallets.
Lam, known online by multiple aliases, allegedly identified targets and coordinated different roles. This level of specialization made the group resemble a traditional criminal organization: some gathered intelligence, some engaged the victim, some moved the funds, and others converted or spent them.
The heist of over 4,100 bitcoin
AP reconstructed one of the most prominent attacks, in which the criminals allegedly posed as representatives of Google and the Gemini exchange. The goal was to convince the victim to share enough information and codes to gain access to the cryptocurrency. Once control was seized, the funds could be transferred within minutes.
The irreversible nature of crypto transactions makes this type of fraud particularly dangerous. A bank can freeze or dispute a transfer under certain circumstances; a validly signed on-chain transaction cannot simply be reversed by a central authority.
The true weak spot is identity recovery
Sophisticated users can use hardware wallets and multisig systems, but they often remain reliant on email, phone numbers, exchanges, and cloud storage. An attacker does not necessarily need to directly steal the private key if they can reconstruct the path that allows the victim to access their assets.
Every backup account, recovery procedure, and connected device becomes part of the security model. This is why high-net-worth holdings should not depend on a single phone or an easily compromised recovery process.
The stolen wealth became visible
The DOJ describes ostentatious spending: exotic cars, watches worth hundreds of thousands of dollars, rental mansions, private jets, personal security, and nights out at clubs with bills reaching up to half a million dollars. This lifestyle is not just colorful trivia; it illustrates the difficulty of converting large amounts of stolen crypto into real-world spending without leaving a trail.
Blockchains are pseudonymous, not anonymous. Transactions are publicly visible, and investigators can combine them with exchange data, IP addresses, purchases, and witness testimony to reconstruct the flows.
Crypto creates opportunities and new criminal incentives
Holding digital assets directly provides control, but it shifts responsibilities onto the user that are handled by intermediaries in the traditional banking system. This autonomy is one of crypto’s core values and, at the same time, a major source of risk.
A criminal who persuades a victim to sign a transaction or surrender a credential can move hundreds of millions without having to clear traditional banking checks. As the value held by individuals grows, so does the incentive to mount tailored attacks.
Exchanges remain crucial hubs
Even when a theft occurs from private wallets, exchanges can become entry or exit points for money laundering. KYC, on-chain analysis, and cooperation with authorities make it possible to freeze certain funds once they hit regulated platforms.
Criminals therefore seek out mixers, chain hopping, and less-regulated services, but each step increases complexity and the margin for error. The scale of the Lam case demonstrates that laundering is often the hardest phase following the theft.
Security must be proportionate to wealth
Someone holding hundreds of millions in assets cannot rely on the same security procedures as a social media account. What is needed is device separation, multi-signatures, operational limits, out-of-band verification, and protocols that make it impossible for a single phone call to authorize a catastrophic loss.
Companies serving high-net-worth clients must do the same. Support teams are targets because they can become shortcuts around the strongest encryption.
The case is not yet closed
Lam is one of several defendants involved in the network, and the proceedings will continue. The DOJ has scheduled a status hearing for December. The guilty plea pertains to participation in the RICO conspiracy; sentencing and the positions of the other defendants must be evaluated separately.
Yet the technical takeaway is already clear. In the crypto world, securing the algorithm is not enough if the human process controlling the keys remains vulnerable to manipulation. Social engineering continues to work because it exploits trust, urgency, and authority—elements no blockchain can eliminate.



