Key Highlights
- Malone Lam is scheduled to appear in federal court in Washington, D.C., for a plea agreement hearing in connection with the alleged theft of more than $240 million in Bitcoin.
- Prosecutors allege Lam and his associates impersonated representatives of Google and the Gemini crypto exchange to gain access to a victim’s accounts and security information.
- Eighteen defendants have been charged in the case, with 10 already pleading guilty. Lam’s plea would make him the 11th defendant to do so.
A 22-year-old Singaporean man is scheduled to enter a plea agreement this week in connection with the alleged theft of more than $240 million in Bitcoin, one of the largest cryptocurrency theft cases prosecuted in the United States.
According to a report by Associated Press on September 7, Malone Lam is set to appear Tuesday in federal court in Washington, D.C., for a plea agreement hearing. Prosecutors have identified him as a suspected ringleader in a social-engineering scheme that targeted a single longtime cryptocurrency investor in August 2024.
Details of the alleged scheme
According to court documents, members of a group of young men in their late teens and early 20s contacted the victim while posing as representatives of Google and the Gemini cryptocurrency exchange. They warned the investor that his accounts had been compromised and persuaded him to grant access to his Google Drive and supply security codes.
Prosecutors state that this access allowed the group to transfer more than 4,100 Bitcoin, then valued at over $240 million. The stolen cryptocurrency was moved through multiple exchange platforms. Money-laundering specialists were allegedly used to convert portions of the funds into cash.
Eighteen defendants have been charged in the case. Ten have already pleaded guilty. If Lam enters a guilty plea, he would become the 11th. At an earlier court appearance, a prosecutor estimated that federal sentencing guidelines could call for a prison term of at least 14 years upon conviction.
Alleged spending of proceeds
Prosecutors allege that Lam and his associates spent portions of the proceeds on luxury items and experiences. The group is said to have spent approximately $4 million at Los Angeles nightclubs over roughly one month. Lam alone allegedly spent more than $569,000 during a single night out.
Additional alleged expenditures included the purchase of a watch valued at nearly $2 million and more than 30 vehicles, among them custom Porsches, Lamborghinis, and Ferraris. The group also rented multimillion-dollar homes, used private jets, and hired private security.
During Lam’s initial court appearance in Miami, U.S. Magistrate Judge Alicia Valle remarked on the described spending, comparing it to “Ferris Bueller gone bad,” a reference to the protagonist of the 1986 film “Ferris Bueller’s Day Off.”
Arrests and investigation
Lam was arrested on Sept. 18, 2024, at a Miami mansion. On the same day, FBI agents arrested co-defendant Jeandiel Serrano at Los Angeles International Airport. Serrano was wearing a watch valued at roughly $500,000 at the time of his arrest, according to authorities.
Investigators traced activity linked to Serrano after he allegedly failed to conceal his IP address while creating an account on a cryptocurrency exchange that held nearly $30 million in stolen funds. The address led to an Encino, California, residence rented for $47,500 per month.
Recent large Bitcoin thefts
The case occurs amid other significant Bitcoin thefts reported in recent years, such as the Coldcard incident. Galaxy Research stated it had high confidence that 1,779.28 Bitcoin had been stolen from approximately 8,600 addresses linked to a firmware vulnerability in certain Coldcard devices.
The vulnerability, introduced in March 2021, caused some devices to generate recovery seeds using weak, predictable randomness rather than their hardware random number generator.
Attackers precomputed those keys and transferred the funds. Galaxy Research reported the confirmed losses exceeded $114.7 million. A suspected fourth wave of activity could raise the figure to approximately 2,055 Bitcoin, though that wave was not included in the confirmed total.
Updating the firmware does not restore security to a seed already generated under the weak conditions. Holders of single-signature seeds created on affected devices without sufficient additional entropy or a strong passphrase have been advised to transfer funds to new seeds generated on corrected firmware.
The two matters involve distinct methods, one centered on social engineering and the other on a hardware seed-generation flaw, and have been investigated and reported separately.
Also Read: DBS and Citi Settle Weekend Singapore–New York USD Payment on SWIFT Ledger
