Singaporean national Malone Lam has pleaded guilty in US federal court to participating in a racketeering conspiracy prosecutors say was used to steal and launder more than $245 million in cryptocurrency. Prosecutors allege the scheme relied on social engineering tactics and home break-ins, and that Lam helped run an international operation that targeted victims through online connections.
In a statement released Tuesday, the US Department of Justice said Lam organized the enterprise, identified prospective victims, and coordinated other conspirators. According to court documents referenced by the DOJ, the operation was formed through connections on online gaming platforms and was active from no later than October 2023 through at least May 2025. The plea was entered before US District Judge Colleen Kollar-Kotelly, and the court scheduled a status hearing for Dec. 8. The government did not announce a sentencing date.
Key takeaways
- Lam pleaded guilty to one count of a RICO conspiracy, shifting the case from a single theft allegation to an alleged broader criminal enterprise.
- US prosecutors describe a workflow combining social engineering with account takeover, then laundering proceeds through multiple crypto services.
- The DOJ says the operation linked victims via online gaming platform connections and operated for roughly a two-year window.
- The guilty plea comes nearly two years after Lam was charged over the theft of more than 4,100 Bitcoin from a Washington, DC resident.
How the alleged heist began with a 4,100-Bitcoin theft
Prosecutors initially accused Lam and Jeandiel Serrano of fraudulently obtaining more than 4,100 Bitcoin from a single victim on Aug. 18, 2024. At the time, that cache was valued at more than $230. Earlier coverage of the case noted that blockchain investigator ZachXBT identified the victim as a Genesis creditor and described an attack pattern that involved impersonation and account compromise.
According to that reporting referenced in the case background, the attackers allegedly posed as Google support staff to gain access to the victimโs accounts. Prosecutors say the operation then moved to impersonate Gemini support, urging the victim to reset two-factor authentication and to use screen-sharing software. Investigators allege the screen-sharing step exposed private keys, enabling the theft.
Following the initial allegations, Lam and Serrano were arrested on Sept. 18, 2024. The DOJ then unsealed their indictment the next day, alleging that the defendants laundered stolen proceeds through crypto mixers, exchanges, pass-through wallets, and virtual private networks.
From an alleged theft to a wider RICO conspiracy
Lamโs guilty plea is significant because it is tied to the Racketeer Influenced and Corrupt Organizations (RICO) frameworkโan approach prosecutors use when they argue defendants participated in a continuing criminal enterprise. In the DOJโs description, Lam was not merely a participant in a single hack, but a coordinator who helped form and operate the network.
Earlier in the case, prosecutors expanded the scope. On May 15, 2025, the DOJ announced a superseding indictment that added 12 more defendants and broadened the allegations into an RICO conspiracy involving more than $263 million in cryptocurrency thefts. That update also included allegations of an additional $14 million theft in July 2024 and an alleged home break-in targeting a hardware wallet.
For investors and builders, the RICO structure matters because it signals prosecutorsโ intent to treat these acts as part of a repeatable enterprise rather than an isolated fraud. It also affects how the court may evaluate the relationships between defendants and the operational methodsโespecially when investigators allege multiple tactics aimed at the same end goal: draining funds and then obscuring their origin.
Operational tactics prosecutors say were coordinated
The DOJโs Tuesday statement describes an enterprise that allegedly recruited and identified victims using connections formed on online gaming platforms. Prosecutors say Lam organized the operation, selected targets, and worked with other conspirators to carry out the theft and laundering process.
In addition to the alleged cyber component, prosecutors say the enterprise included physical intrusion. The expanded indictment referenced an alleged home break-in targeting a hardware walletโan allegation that, if proven, would demonstrate that the scheme was not limited to remote account compromise.
The government also alleged that Lam continued directing associates even during pretrial detention. Prosecutors claimed he arranged delivery of luxury items to his girlfriend. More broadly, the DOJ asserted that members of the group spent stolen funds on high-end purchases, including private jets, rental properties, watches, and at least 28 exotic cars. Prosecutors further alleged that nightclub expenses reached $500,000 per evening.
While these claims are part of the prosecutionโs theory and not findings by the court, they help explain why prosecutors pursued a RICO case: they depict an alleged pattern of criminal activity paired with conspicuous consumption and operational coordination.
What comes next for the case
Lamโs guilty plea sets a procedural milestone, but it does not end questions that market participants may be watching. The court scheduled a status hearing for Dec. 8, yet the DOJ has not announced a sentencing date. That leaves the timing and trajectory of remaining proceedingsโparticularly the cases involving additional defendantsโunclear.
Going forward, readers should pay attention to how the government and defense present the scope of the enterprise at sentencing, especially whether the prosecution will emphasize specific tactics such as impersonation workflows, the role of laundering infrastructure, and the alleged use of physical break-ins. Those details often determine how courts view responsibility in RICO matters and can influence outcomes for co-defendants in the expanded indictment.






