Minecraft Friends to RICO Defendants: Malone Lam Pleads Guilty to $245 Million Bitcoin Scheme
Malone Lam, a 22-year-old Singaporean national, pleaded guilty on September 8 in a Washington D.C. federal court to one count of racketeering conspiracy for his role as ringleader of a criminal enterprise that stole $245.9 million from a single Washington D.C. investor in its largest operation, part of a broader scheme totaling more than $263 million across all victims and defendants.
The plea, entered before Judge Colleen Kollar-Kotelly, makes Lam the eleventh of eighteen charged defendants to admit guilt in a case that prosecutors describe as the first major application of the federal Racketeer Influenced and Corrupt Organizations Act to a Bitcoin theft scheme. He faces a maximum sentence of 20 years, with sentencing guidelines pointing toward at least 14 years. A status and forfeiture hearing is scheduled for December 8, 2026.
How the Scheme Worked
The enterprise operated from October 2023 through at least May 2025 and functioned with the structural discipline of an organized crime syndicate. According to blockchain forensics firm TRM Labs, members were divided into five functional roles: database hackers who obtained stolen credentials from dark web marketplaces; analysts who identified high-net-worth crypto holders within that data; social engineers who impersonated Google and Gemini customer support staff over the phone to extract seed phrases and one-time passwords; money launderers who converted stolen crypto into cash; and residential burglars who conducted physical home invasions to steal hardware wallets. In one documented instance from July 2024, Lam monitored a home invasion in New Mexico in real time using access he had obtained to the victim's compromised iCloud account.
The network's largest single operation, carried out in August 2024, drained more than 4,100 Bitcoin worth approximately $245.9 million from a Washington D.C. investor identified in court documents only as "R.W." Conspirators accessed the victim's Google Drive to extract security credentials before emptying multiple wallets. Additional thefts included roughly $14 million from a second victim and $800,000 from a third, bringing the total across all defendants to more than $263 million.
The laundering pipeline documented by TRM Labs involved sequential wallet transfers, known as "peel chains," to obscure the funds' origins, cross-chain swaps from Bitcoin to Ethereum via decentralized finance platforms, and final cash-out through what court documents describe as "Asia-based exchanges," a reference that points to jurisdictions with weaker anti-money-laundering enforcement. Court records also document the use of crypto mixers and pass-through wallets as additional layers of obfuscation.
Where the Money Went
Court records and media reporting document spending on a scale that drew comparisons to fiction. Lam and his associates spent up to $569,000 in a single night at a Los Angeles nightclub, purchased more than 30 luxury vehicles including a $3.8 million Pagani Huayra, and rented mansions in Miami and the Hamptons. Hermès bags and Rolex watches were distributed to models and influencers. One co-defendant received a Lamborghini Urus and a Rolls-Royce Ghost from Lam and later hid $500,000 in cash inside his parents' washing machine. Private jets and a single luxury watch valued at $2 million were among the additional expenditures documented in court records.
Judge Kollar-Kotelly reportedly described the case as "Ferris Bueller gone bad." U.S. Attorney Jeanine Ferris Pirro was less amused: "If you build a cybercrime empire, we will find you, dismantle your operation and hold you accountable," she said following the plea.
As of late 2024, approximately $70 million had been recovered or frozen. More than $100 million remained unaccounted for, with a significant portion transferred to locations beyond court jurisdiction. Forfeiture agreements cover a fleet of Ferraris, Rolls-Royces, Lamborghinis, and Mercedes-Benzes intended for victim restitution.
The Network's Origins and the RICO Precedent
The enterprise grew out of online gaming. Lam, who operated under aliases including "Anne Hathaway," "$$$," and "King Greavy," met co-conspirator Jeandiel Serrano on Minecraft while living in Singapore and persuaded him to relocate to Texas in October 2023 to begin operations. Serrano has been charged and is awaiting a separate proceeding. Most recruits were young men under 20 years old, drawn from networks across California, Connecticut, New York, Florida, and internationally.
The RICO statute, designed in 1970 to prosecute mafia structures, has not previously been applied to a Bitcoin theft network. Its use here allows prosecutors to hold all enterprise members jointly accountable for the full pattern of criminal activity rather than only their individual acts, and it carries heavier sentencing exposure. Analysts at Crypto Briefing and Fortune note this represents a meaningful doctrinal shift in how U.S. law treats organized crypto crime.
Regional Implications
The case carries direct consequences for users and regulators outside the United States. Singapore, Lam's country of origin, has already accelerated its institutional response, in part because this is the first case in which a Singaporean citizen has been identified as the ringleader of a U.S. RICO cryptocurrency prosecution of this scale. The Singapore Police Force launched a dedicated Cyber Command unit in July 2026 and ran a joint operation with Coinbase, Gemini, Chainalysis, and TRM Labs earlier in the year to flag scam-linked accounts. The Monetary Authority of Singapore tightened licensing requirements for cross-border digital token platforms in June 2025.
The cash-out route through Asia-based exchanges raises compliance questions for exchanges across Nigeria, Ghana, India, Pakistan, and Southeast Asia that may have processed laundered funds. India's exposure is underscored by a 409 percent increase in cryptojacking incidents recorded in the country, a figure that has drawn increased attention from international enforcement bodies. Exchanges in all of these regions should expect heightened scrutiny from international anti-money-laundering bodies and U.S. regulators.
The social engineering tactics at the core of the scheme mirror trends accelerating globally. According to reporting by AMLBot and BitcoinKE, 65 percent of all crypto security incidents globally in 2025 were driven by social engineering. In South Africa, impersonation scams rose 1,400 percent year-on-year, and aggregate crypto fraud losses across the continent reached roughly $12.7 billion in 2025. The enforcement gap is most acute in key adoption markets including Nigeria, Kenya, South Africa, and Ghana, where law enforcement agencies generally lack the forensic blockchain capacity and cross-border legal frameworks that made this prosecution possible. The Lam case makes that gap harder to ignore.
The Enforcement Paradox
The guilty plea arrives against a contradictory policy backdrop. The Trump administration wound down the Justice Department's dedicated crypto enforcement unit even as FBI crypto fraud complaints rose nearly 50 percent in 2025 and global crypto fraud reached an estimated $17 billion. That rollback has drawn scrutiny in part because crypto businesses donated approximately $1.2 billion to Trump's 2024 campaign, raising conflict-of-interest questions about the administration's posture toward crypto enforcement, according to reporting by Fortune. Cybersecurity researcher Allison Nixon, who tracks the "Com" underground network from which this enterprise emerged, described the situation plainly: "If we don't seriously ramp up resources to take these people down and do it faster, then it's going to spread more and more."
Lam's sentencing date has not yet been set. Two co-defendants remain at large, reportedly in Dubai.