Skip to content
Crypto Guides

Malone Lam's $245M Racketeering Enterprise: How the Social-Engineering Scam Worked

Luis Schilli
Luis Schilli September 15, 2026 10 min read
Malone Lam's $245M Racketeering Enterprise: How the Social-Engineering Scam Worked

Two phone calls were all it took. A Washington, D.C. investor lost more than 4,100 Bitcoin, worth roughly $230 million to $240 million, after two callers posed as Google and Gemini support. No hacking, no phishing link, just a convincing voice on the line. The man prosecutors say ran the operation, Malone Lam, pleaded guilty on September 8, 2026, in a case the Department of Justice has tied to $245 million in stolen and laundered funds overall.

Key Takeaways

  • The scam used two phone calls, not a phishing link: a co-conspirator posed as Google support warning of suspicious login attempts, then a second posed as Gemini support warning of malware, together convincing the victim to hand over Google Drive access.
  • The flagship theft topped 4,100 Bitcoin: worth roughly $230 million to $240 million at the time, part of a broader $245 million racketeering enterprise the Department of Justice says Lam organized.
  • Malone Lam pleaded guilty on September 8, 2026: to one count of racketeering conspiracy, widely described as the first time federal prosecutors have used racketeering law against a Bitcoin theft.
  • No sentencing date has been set: Lam faces up to 20 years, and a status hearing is scheduled for December 8, 2026, in a case that has produced 18 defendants and 11 guilty pleas so far.
  • CoinTracking already keeps the records a theft victim needs: a timestamped transaction history documenting exactly what you held, and when, if you ever need to prove a loss like this one.

The Case: Malone Lam and the $245 Million Racketeering Enterprise

Malone Lam is a 22-year-old Singaporean national who was living in Miami at the time of his arrest. Within the conspiracy, he went by several aliases, including "Anne Hathaway," "$$$," and "King Greavy." Prosecutors named him as the ringleader and organizer of the wider enterprise, which reporting on the case links to 18 charged defendants in total.

On September 8, 2026, Lam pleaded guilty before U.S. District Judge Colleen Kollar-Kotelly in the U.S. District Court for the District of Columbia. He admitted to one count of participating in a racketeering conspiracy, tied to the August 2024 theft and the broader scheme it was part of. Multiple sources describe this as the first time federal prosecutors have applied racketeering law, the kind of statute more commonly used against organized crime syndicates, to a Bitcoin-related theft.

The investigation reaches well beyond Lam himself. His guilty plea was the 11th entered in the case so far, out of 18 people charged. As of this article's publish date, no sentencing date has been scheduled. Lam faces a maximum of 20 years in prison, and a status hearing is set for December 8, 2026. He was arrested in Miami weeks after the theft, following a highly visible spending spree that drew investigators' attention, according to coverage of the case.

Timeline of the Malone Lam case: the August 18, 2024 theft, the September 8, 2026 guilty plea, and the December 8, 2026 status hearing

The $245 million figure comes from the Department of Justice's own press release. It's an enterprise-wide total: the combined value of everything stolen and laundered across the whole operation Lam is accused of organizing. That's a different number from the single Washington, D.C. theft in this article. That theft came to roughly 4,100 Bitcoin, worth an estimated $230 million to $240 million at the time. Coverage of the case has cited $230 million, $240 million, and $245 million somewhat interchangeably, depending on whether the outlet means the single incident or the enterprise as a whole. It's worth keeping the two straight: one number describes what happened to one victim, the other describes the scale of everything prosecutors say Lam's organization touched.

The broader enterprise wasn't limited to phone calls, either. Reporting on the wider case also links it to a handful of home break-ins targeting other victims. The flagship technique, and the one actually worth understanding in detail, is the phone-based impersonation used against the Washington, D.C. investor, because it's a scam almost anyone holding crypto could plausibly face.

Know exactly what's in your wallet, and when

If you ever need to reconstruct what you held before an incident like this, CoinTracking already has the timestamped record, no digging through old screenshots or emails required.

How the Scam Actually Worked: A Two-Call Vishing Attack

This wasn't phishing in the sense most people picture, a fake link buried in an email or text message. It wasn't SIM swapping either, where an attacker hijacks a victim's phone number to intercept text-message codes. What happened to the Washington, D.C. victim is better described by a different pair of terms: vishing, short for voice phishing, combined with pretexting, the practice of inventing a false scenario to manipulate someone into acting against their own interest.

The First Call: Fake Google Support

On August 18, 2024, the victim received a call from a co-conspirator identified in reporting on the case as Veer Chetal, who claimed to be calling from Google's support team. Chetal warned of suspicious attempts to access the victim's Google account, the kind of warning that sounds routine, even helpful, on its face. That first call did the groundwork: it planted the idea that the account was already under attack and that fast action was needed to secure it.

The Second Call: Fake Gemini Support

A second co-conspirator, identified as Jeandiel Serrano, followed up posing as support staff from Gemini. Serrano's call warned of a malware attack targeting the victim's crypto wallet. Coming right after the fake Google warning, the second call reinforced the urgency the first one had already created and pointed the victim toward a specific, seemingly protective action: granting access to his account.

What the Access Actually Let Them Take

Between the two calls, the victim was manipulated into granting access to his Google Drive and revealing the security codes stored there. That single decision is what turned two phone calls into a theft worth $230 million to $240 million. Many crypto holders use cloud storage like Google Drive as an informal backup. They store recovery phrases, two-factor authentication codes, or notes about where funds are held there. That's exactly the kind of information a crypto wallet's recovery process or a dedicated password manager is built to protect. A general-purpose cloud drive is not. Once the conspirators had that access, they used it to move more than 4,100 Bitcoin out of the victim's control.

How to Protect Yourself From Vishing and Pretexting Scams

The Malone Lam case is one of the largest examples of this kind of scam on record, but the mechanics behind it are common, and the defenses are straightforward once you know what to watch for.

  • Never grant remote or cloud-drive access to someone who called you: Google and Gemini do not call customers out of the blue to warn about suspicious activity, and neither does any other reputable exchange or platform. If a caller asks you to share access to an account, a drive, or a device, that request is the scam, not the fix for it.
  • Verify support contacts independently: hang up, then reach out through the official app, website, or phone number you find yourself, not a number or link the caller provides. A legitimate support interaction can wait the extra few minutes it takes to confirm who you're actually talking to.
  • Keep recovery phrases and 2FA backups out of general cloud storage: Google Drive, iCloud, and similar services aren't built as secure vaults for wallet recovery information. Recovery phrases and seed backups should stay offline entirely, on paper or a metal backup plate, never in a cloud account or even a password manager. Passwords and account logins are different: those are safe to keep in a password manager with strong encryption.
  • Treat urgency as a warning sign, not a reason to move fast: both calls in the Lam case worked by creating a sense that something bad was already happening. Scammers rely on urgency to short-circuit the careful thinking that would otherwise catch the scam.
Document the loss properly

CoinTracking imports your transaction history from over 400 exchanges, wallets, and blockchains, so you already have the timestamped records a theft claim depends on.

If This Happens to You: Documenting the Loss for Your Taxes

A scam like this raises the same question any other crypto theft does under current US tax law: is the loss deductible? Our coverage of the ColdCard hardware wallet exploit walks through the underlying rules in detail, including the IRS's disaster-only casualty-loss restriction and the separate theft-loss path available for crypto held as an investment. The same framework applies to a vishing-driven theft like this one, and it depends primarily on why you held the crypto in the first place, personal use or investment, which is a question for a tax professional working from your specific facts.

Regardless of how the deduction question resolves, documenting what happened protects you either way. If you ever find yourself on the losing end of a scam like this, a few records are worth gathering right away, before they get harder to find:

  • Call logs and caller-ID records: your phone carrier can usually provide a record of when the calls came in, even if the caller-ID itself was spoofed.
  • Google Drive access logs: Google's own account activity tools show when and from where your Drive was accessed, which helps establish a timeline.
  • Exchange withdrawal confirmations: timestamped records of exactly what left your account and where it went.
  • A police report: filed with your local police department, which most recovery efforts and loss claims will eventually ask for.
  • An FBI IC3 complaint: filed at ic3.gov, the FBI's Internet Crime Complaint Center and the federal government's primary channel for reporting a scam like this one.

The mechanics of pulling this together look a lot like building a Source of Funds report. Instead of proving where your money came from, you're proving what you had, at what point in time, and what happened to it next. That includes the acquisition dates and cost basis of the coins that were taken, calculated the same way as any other taxable event, typically using FIFO or another accounting method.

A CoinTracking import covers part of this automatically. Every trade, deposit, and transfer connected to your account gets its own timestamp on import. Cost basis is calculated from your full transaction history, once everything is imported and correctly categorized. That means your withdrawal records already exist, instead of something you have to reconstruct from memory months later. If any of your other holdings ended up affected too, reporting those losses correctly still depends on that same clean transaction history.

Conclusion

Malone Lam's case shows how far a well-run social-engineering scam can go without a single stolen password or a cracked private key: two convincing phone calls were enough to move more than 4,100 Bitcoin out of one investor's control. The defenses that would have stopped it are simple: verify who's actually calling through official channels, and keep recovery information out of general cloud storage. They're worth internalizing before you're the one who picks up the phone.

Keep your records ready for whatever comes next

CoinTracking has tracked crypto portfolios and calculated taxes for over 2.2 million users since 2012, across more than 400 exchanges, wallets, and blockchains. Import your history once, and you're ready no matter what happens to an exchange, a wallet, or your own inbox.

Disclaimer

This article is for general informational purposes only and does not constitute financial, tax, or legal advice. Details of the Malone Lam case reflect publicly available reporting as of September 15, 2026, and could change as the broader investigation, including sentencing, proceeds. Tax treatment of stolen or hacked cryptocurrency depends on your individual circumstances and on current law, which can change. Readers should consult a qualified tax professional before making decisions based on the information presented here. The author and publisher are not responsible for any losses or damages incurred as a result of using the information in this article.

Luis Schilli, Head of Marketing
Author

Luis Schilli

Head of Marketing

Luis is Head of Marketing at CoinTracking, where he leads content, communications, and educational initiatives. He helps traders and investors navigate cryptocurrency taxation with practical, real-world guidance.

FAQs about Malone Lam's $245M Racketeering Enterprise

It was neither a phishing link nor a SIM swap. It was vishing, or voice phishing, combined with pretexting: two co-conspirators called the victim, one posing as Google support and one as Gemini support, and used that false context to talk him into handing over access.

The Department of Justice's $245 million figure covers the full racketeering enterprise, not a single theft. The Washington, D.C. incident described in this article came to roughly 4,100 Bitcoin, worth an estimated $230 million to $240 million at the time.

Lam pleaded guilty to one count of participating in a racketeering conspiracy, entered on September 8, 2026, before a federal judge in Washington, D.C. No sentencing date has been set, and Lam faces up to 20 years in prison.

It depends on why you held the crypto. Personal-use losses generally require a federally or state-declared disaster to qualify, while crypto held as an investment may qualify for a separate theft-loss deduction. Our ColdCard exploit coverage walks through the rules in full.

CoinTracking timestamps every deposit, trade, and transfer connected to your account as it's imported. Once your full history is imported and correctly categorized, that record already exists, ready to use if you're ever targeted by a scam like this one.

Start Tracking Your Crypto Taxes Today

Experience why 2.2 million users trust CoinTracking — sign up today for a seven-day free trial!