Invest1 publisher3 min readPublished
A fake Google and Gemini call delivered 94% of the thefts named in Malone Lam's plea
Prosecutors valued the take at 4,100 bitcoin, more than $245 million, drained after one Washington holder granted Google Drive access and read out security codes; every other victim named in the case totals about $14.8 million.
The Investor · Invest desk

What happened
- Malone Lam, 22, a Singapore citizen who had been living in Miami, pleaded guilty to one count of RICO conspiracy for leading a ring that stole and laundered more than $245 million in cryptocurrency.
- The largest theft came on 18 August 2024, when people posing as Google and Gemini representatives got a Washington, D.C. holder to grant Google Drive access and hand over security codes, draining over 4,100 Bitcoin.
- Members spent as much as $500,000 in a single night at a nightclub and bought $3.8 million of cars, and Lam has agreed to hand over the Ferraris, Rolls-Royces, Lamborghinis and Mercedes-Benzes as victim compensation.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- constraint Hong Kong's securities regulator has said that signers approving fraudulent transactions undermine custody whether it runs on HSMs, MPC or multisignature, so the hardware line of a custody budget cannot buy its way out of the authorization step.
- decision Loss that concentrates in a handful of large holders makes verification effort spread evenly across a client book the wrong allocation, and forces a choice about which signers get call-back procedure first.
- exposure The enterprise held breaking and entering in reserve for calls that failed, which moves exposure toward premises, staff and physical devices as the phone channel gets harder.
- contradiction Chainalysis puts 2025 scam receipts at $14 billion and possibly above $17 billion while the FBI's complaint data records more than $11 billion of losses, so any statement about impersonation's share of the total depends on which ledger is being counted.
Four thousand one hundred bitcoin booked at more than $245 million values the coin near $59,800 [18], which is the price on the day the wallet emptied, 18 August 2024 [3], rather than a mark on anything since. The other victims named in the case add up to roughly $14.8 million, about $800,000 from a holder identified as M.C. in June 2024 and about $14 million from S.P. [5][24], so that single Washington, D.C. call carried 94% of the $259.8 million of thefts on the record [19].
What the caller needed was access to Google Drive and a set of security codes, obtained by claiming to be Google and Gemini [3], and Assistant U.S. Attorney Christopher Howland described the group in court as a "social engineering enterprise", as reported by Courthouse News [4]. The Justice Department says it grew out of relationships formed on online gaming platforms, with the work split into database hacking, target identification, fraudulent calls and laundering, plus breaking and entering when the remote approach failed [7].
Hong Kong's securities regulator has warned that weak approval controls and signers authorizing fraudulent transactions can undermine a custody system whether it runs on HSMs, MPC or multisignature [12], while a 2026 institutional survey found 66% of investors naming security and key-signing protocols as a key factor in choosing a custodian [13]. Those two findings sit one layer apart: buyers are grading the cryptography, and the regulator is pointing at the person who signs. That gap is where the custody-as-verification-problem reading earns its keep, or rather, the more careful version of it does, because the failure the regulator describes is procedural: a signer authorizing a transaction that should never have been approved, regardless of what protects the key material.
The New Mexico break-in and the two scam-tracking ledgers complicate that reading in different ways. The break-in that went after a hardware wallet came away with nothing [6], but the enterprise kept that capability precisely for calls that did not work [7], so a tighter phone script relocates the loss rather than deleting it. And the aggregates are two different ledgers: Chainalysis has scams receiving at least $14 billion on-chain in 2025, possibly above $17 billion as more addresses are identified [14], against the FBI's 181,565 cryptocurrency-related complaints and more than $11 billion in losses [16], which puts this one theft at about 2.2% of the FBI figure [20]. The 1,400% year-on-year growth in impersonation scams arrives without a stated base [14], and TRM Labs rating scams the only "Mature" category in its 2026 AI-in-Crime Adoption Index [15] is a judgment about method, not a loss share.
Lam was arrested in Miami on 18 September 2024, 31 days after the largest theft [9][22], and an accomplice, Evan Tangeman, was sentenced in April for laundering proceeds from the operation [10]. The cars Lam has agreed to surrender cover about 1.6% of that one theft [21]. Attribution took a month. Forfeiture recovers only a small fraction of losses this size. The money that changes the outcome is spent before someone authorizes the transaction, not recovered afterward.
What to watch
- Lam's status hearing on 8 December, and whether the sentence lands near the 20-year maximum on the single RICO count [c11].
- Whether Chainalysis revises 2025 scam receipts above the $17 billion upper estimate as more addresses are attributed [c14].
- Whether institutional due diligence starts asking about caller verification instead of the key-signing protocols 66% of investors currently grade custodians on [c13].