NewsCryptoSingaporean Man to Plead Guilty in $240M Bitcoin Theft Involving Gemini Impersonation

Singaporean Man to Plead Guilty in $240M Bitcoin Theft Involving Gemini Impersonation

Author: CryptoBriefing·

Key Takeaways

  • The scheme involved impersonating Google and Gemini support staff to convince a wealthy D.C. investor that his accounts were compromised and obtain his security credentials.
  • The August 2024 theft totaled more than 4,100 Bitcoin, valued at over $240 million, and the broader operation was linked to thefts exceeding $263 million through March 2025.
  • This is the first Bitcoin-related prosecution brought under the RICO statute, signaling that prosecutors treat coordinated crypto theft rings like organized crime.
  • Eighteen people have been indicted, ten have already pleaded guilty, and Lam faces a minimum sentencing guideline of 14 years in prison.
  • The group also committed home burglaries to steal hardware wallets, and converted stolen Bitcoin into luxury assets including sports cars, private jets, and a nightclub bill exceeding $569,000.
Singaporean Man to Plead Guilty in $240M Bitcoin Theft Involving Gemini Impersonation

A classic con tactic adapted for the cryptocurrency era—impersonating a trusted institution over the phone, inducing panic, and making off with a victim's savings—has culminated in one of the largest Bitcoin theft cases ever prosecuted in the United States. The stolen assets amounted to more than 4,100 Bitcoin, worth over $240 million at the time of the theft.

Malone Lam, a 22-year-old Singaporean national, is scheduled to appear in a U.S. federal court on September 9, 2026, to enter a guilty plea in connection with the case.

How the Scheme Worked

Lam and his associates allegedly posed as representatives of both Google and the Gemini crypto exchange while contacting a wealthy investor based in Washington, D.C.

The objective was simple, though the execution was elaborate: persuade the target that his accounts had been compromised, then convince him to hand over security codes and access credentials. Once the group gained access, they transferred his Bitcoin holdings entirely out of his control. The approach mirrors a well-documented pattern of tech-support and impersonation fraud that the FBI's Internet Crime Complaint Center has repeatedly flagged as one of the costliest categories of cybercrime reported by victims in the United States.

The theft took place in August 2024, although the broader criminal operation had reportedly been running since approximately October 2023. By the time authorities dismantled it, the group had been linked to thefts totaling more than $263 million across multiple incidents extending through March 2025.

The FBI arrested Lam in September 2024 at a mansion in Miami—a detail that underscored how the stolen funds were being spent. According to prosecutors, the group converted Bitcoin into cash and spent it rapidly, purchasing dozens of sports cars and private jets, and running up a single Los Angeles nightclub bill reportedly exceeding $569,000. The rapid liquidation also illustrates a persistent challenge for investigators: while Bitcoin transactions are recorded on a public blockchain, criminals who convert proceeds to cash and luxury assets can still complicate asset recovery, which is often a lengthy process for victims.

A Landmark Prosecution

The case carries legal significance beyond its dollar value. It marks the first time a Bitcoin-related prosecution has been brought under the Racketeer Influenced and Corrupt Organizations Act (RICO), a statute historically associated with organized crime syndicates rather than cryptocurrency theft rings. Applying RICO to a crypto theft ring signals that prosecutors are willing to treat coordinated digital-asset schemes with the same legal framework long used against mafia families—an approach that carries heavier potential penalties and broader reach across an entire criminal enterprise.

Eighteen people have been indicted in connection with the scheme. Ten have already pleaded guilty ahead of Lam's scheduled hearing, indicating that prosecutors have built a durable case from the inside out. Lam himself faces a minimum sentencing guideline of 14 years in prison if the plea proceeds as expected.

The operation also had a physical dimension that investigators found notable. The group reportedly carried out home burglaries specifically to steal hardware wallets—the small USB-like devices used to store cryptocurrency private keys offline.

Implications for Crypto Security

Cryptocurrency exchanges invest heavily in technical infrastructure, multi-factor authentication, and blockchain-level security. None of that protection matters, however, if an attacker can simply call a customer and impersonate the exchange's support team. In this scheme, Gemini's brand was used as a prop, though the exchange itself was not compromised at the infrastructure level.

For individuals holding significant crypto assets, the case underscores several uncomfortable realities. Legitimate exchanges and platforms do not initiate unsolicited calls asking for security codes. Any unexpected contact claiming to be from a financial institution or exchange, requesting credentials or urgent account action, should be treated as a red flag, no matter how official it sounds. Separately, the group's reported targeting of hardware wallets through burglaries points to physical custody of private keys as its own security consideration, distinct from online account protection.

With ten guilty pleas already secured and the lead defendant scheduled to follow, federal prosecutors are framing the case as organized crime rather than opportunistic fraud. How courts sentence Lam and his co-defendants is likely to be watched as a reference point for how seriously the U.S. justice system treats large-scale cryptocurrency fraud going forward.