The $245 Million Phone Call: How Crypto Fraud Became a Business
One of the largest cryptocurrency thefts from a single victim did not require breaking Bitcoin's cryptography. Stolen data, a credible story and the victim's cooperation were enough to take over $245 million in virtual c...
Watchlist
Published in the last two hours. Multiple named entities are involved.
One of the largest cryptocurrency thefts from a single victim did not require breaking Bitcoin's cryptography. Stolen data, a credible story and the victim's cooperation were enough to take over $245 million in virtual currency from a single Washington, D.C. resident in August 2024.
On September 8, 2026, Malone Lam, a 22-year-old Singaporean national, pleaded guilty to a racketeering conspiracy charge in the US.
Prosecutors say the enterprise he helped run operated from October 2023 to at least May 2025, hacking and buying databases of cryptocurrency holders, then analysing the data to identify high-value targets. In some cases, members broke into victims' homes to seize hardware wallets.
Malone Lam, 22, a citizen of Singapore and recent resident of Miami, pleaded guilty today in connection with his role as ringleader of an international cybercrime conspiracy that used social engineering to steal and launder cryptocurrency valued at more than $245 million,… pic.twitter.com/R8Nnz9a7n6
— U.S. Attorney DC (@USAO_DC) September 8, 2026Fraud-as-Business Model
Lam's enterprise worked as an organised business with a clear hierarchy and distinct roles. Participants specialised in different domains, and each executed a specific part of the operation.
Database hackers breached websites and servers, or bought stolen records on the dark web, to build lists of potential victims. Target identifiers then combed the lists for the wealthiest prospects.
In a group chat cited in the indictment, Lam offered co-defendant Conor Flansburg roughly 40 of those organised, stolen databases. Flansburg agreed to send Lam and a fellow organiser a 20% cut of any theft over $10 million, replying, "we hackin, all day every day."
A separate team of launderers converted the proceeds into cash, wire transfers and goods. None of these roles required breaking Bitcoin's cryptography, only data about who held the assets, how to reach them and how to make the approach believable.
That division of labour is not unique to Lam's network. A 2026 Global Initiative Against Transnational Organized Crime study of Ukrainian scam call centres described a similar structure at national scale: callers, closers, IT teams, HR, trainers, finance staff and administrators, each handling one link in the chain.
The point is not the geography, but the operating model: social engineering has become a staffed, segmented business. A wallet does not need to be breached directly if attackers can identify the owner, assemble a convincing profile and induce the transfer.
In 2025, Coinbase said criminals had bribed overseas support agents to copy customer names, addresses, identification documents, transaction histories and balance snapshots.
The company said no passwords or private keys were exposed, and that it would reimburse customers tricked into transferring funds. Coinbase said the stolen data was intended to make later impersonation attempts more convincing.
Lam's enterprise, the Ukrainian call centres and the Coinbase breach have one thing in common: in none of them did a private key get compromised.
The common thread is that the attack began outside the cryptographic layer. The weakest point was not the chain, but the information surrounding its users.
Customer Data Enters the Custody Perimeter
Private-key protection still matters, but it covers only one part of the attack chain. A hardware wallet cannot protect an owner whose identity, contact details and approximate holdings have already been assembled into a target profile. Cryptography cannot establish whether a transaction was authorised freely, under deception or under physical threat.
Customer records are now part of the asset-security problem. A balance snapshot, address, phone number or support note can help attackers choose a target and make an impersonation attempt credible.
Exchanges and custodians therefore need to treat access to customer data more like access to operational keys: tightly logged, narrowly permissioned and harder to use after an unsolicited support contact.
Higher-risk transfers can require cooling-off periods, extra verification, or sign-off split across more than one person; self-custody setups face the same question if a single identifiable individual can move all the assets at once.
Lam's enterprise ran on a supply chain of database hackers, target identifiers, callers and launderers built around a straightforward split of the proceeds.
A federal court in Washington, D.C. is scheduled to hold a status hearing in the case on December 8, 2026, when a sentencing date is expected to be set. That hearing will be the next point at which the machinery behind the $245 million theft returns to public view.
This article was written by Tanya Chepkova at www.financemagnates.com.Why this matters
Coinbase is showing up inside the Security Incidents theme, so this story is worth tracking for follow-through rather than treating it as a one-off headline.
Original source
Read on Finance MagnatesRelated market context
Zamanat Targets GCC’s $250 Billion SME Financing Gap With Up to $100 Million Tokenized Private Credit Fund
Dubai, UAE, September 10th, 2026, Chainwire Zamanat Fund CEIC Limited is the company’s first live proof point for regulated fund t...
Coinbase Links CLARITY Act Passage to Institutional Capital
Coinbase CEO Brian Armstrong said U.S. crypto regulatory clarity is likely to arrive, whether or not the Senate advances the CLARI...
MetaMask Splits From Consensys as 100M-Download Wallet Targets Open Money
Key Takeaways: Consensys Software Inc. to split into distinct consumer and institutional brands called MetaMask. MetaMask will pri...
Paolo Ardoino says 650 million people decentralized US debt, but Tether still controls the T-bills
Paolo Ardoino offered a striking answer to a familiar U.S. debt problem: replace concentrated foreign buyers with hundreds of mill...
Hackers Hijack Trezor, Bitbox Emails to Target Crypto Users
Trezor, Bitbox, and Cointracking warned customers Thursday that phishing emails were sent through compromised mailing infrastructu...
Zoomex Launches ZWTC 2026 Multi-Asset Trading Championship With a Record Prize Pool of Up to 5 Million USDT
Returning for its third year, Zoomex’s flagship global trading competition expands across crypto perpetuals, stock contracts, AI-p...