The $230 Million Theft That Started With a Phone Call

    Subscribe to our newsletter

    By submitting this form, you agree to the Allure Security privacy policy.

    Share Article

    Malone Lam pictured over federal court documents with Bitcoin symbols representing the $230 million cryptocurrency theft case

    Malone Lam stole 4,100 Bitcoin by impersonating Google. No systems were breached. No malware was deployed. The victim handed over a one-time password because the caller sounded like someone he should trust.

    On September 9, 2026, Malone Lam pleaded guilty in a Washington, D.C. federal court for his role in one of the largest cryptocurrency thefts in US history. The 22-year-old Singaporean and 17 co-defendants stole more than 4,100 Bitcoin, worth approximately $230 million at the time, from a single victim. Ten co-defendants had already pleaded guilty before Lam, with sentences ranging from 70 to 78 months.

    No system was breached. No malware was deployed. The entire theft was executed through social engineering: Lam and his associates impersonated representatives of Google and the Gemini cryptocurrency exchange, convinced the victim his accounts were compromised, and talked him into handing over a one-time password. An eighth-grade dropout stole $230 million by borrowing the credibility of two brands the victim trusted.

    The case is worth understanding not because of its scale but because of how little technical sophistication it required, and what that reveals about where the real vulnerability lives.

    How two weeks of fake alerts built a real belief

    The theft happened on August 18, 2024, but the operation started roughly two weeks earlier. Lam’s group began sending the victim messages formatted to look like Google security notifications. Login attempt from Russia. Login attempt from an unrecognized device. The messages arrived persistently, almost daily, each one individually easy to dismiss.

    Brett Johnson, a former cybercriminal who built the ShadowCrew dark web marketplace and spent twenty years committing fraud before reforming, described this exact technique in a recent Allure Security webinar. “What happens when you persistently get that same message almost daily for a week and a half to two weeks?” he said. “It has a psychological imprint on you. You may be still telling yourself that’s a scam, but at the same time you’re like, man, is it?”

    When the phone call finally came, it arrived in a context the victim had been primed to expect. The caller knew his personal information. The caller ID matched. The request, verify your identity with a one-time password, was indistinguishable from what a legitimate security response would look like. The victim complied, and the Bitcoin was gone within hours.

    Johnson, who used similar multi-channel techniques during his criminal career, explained why the approach defeats training: “I’m trying to get you to react emotionally. I’m trying to get you to set reason and logic to the side and just give me a knee-jerk reaction.” The victim was not careless. He was a sophisticated investor managing hundreds of millions in digital assets. The attacker was an eighth-grade dropout. The asymmetry ran entirely in the direction of social engineering skill.

    What the attacker exploited was not a system

    The Lam case is instructive because of what it did not involve. There was no phishing page to detect. No malware to sandbox. No exploit chain to patch. The attack consisted entirely of borrowing the authority of two brands, Google and Gemini, and deploying that authority through communication channels the victim expected those brands to use.

    Johnson drew a comparison that security professionals rarely hear from someone who practiced both sides: “Think of social engineering as sales. You listen clearly and actively, find out what the objections are, and then you overcome those objections.” The reconnaissance that powered the Lam operation, the victim’s personal details, banking information, communication patterns, is available for purchase on dark web marketplaces for as little as twenty-five dollars per lookup. “There’s so much information out there about you that you don’t appreciate,” Johnson said. “And we are very good about collating all of that, putting it together, and using it in a narrative that will absolutely succeed in victimizing you.”

    The spending that followed the theft confirmed its scale. Before their arrests a month later, Lam and his associates purchased fleets of sports cars, flew on private jets, rented mansions in Miami and the Hamptons, and in one evening Lam spent over $569,000 at a Los Angeles nightclub. He was arrested on September 18, 2024, at a Miami mansion. His co-defendant, Jeandiel Serrano, was arrested the same day at LAX wearing a watch valued at approximately $500,000.

    The brand was the weapon

    Google and Gemini were not victims of this theft in the financial sense. They lost no money and suffered no breach. But their brands were the operational infrastructure of the attack. Every alert, every phone call, every trust signal the victim relied on to decide whether to comply carried the authority of platforms he believed were protecting him.

    This is the pattern that connects the Lam case to the broader impersonation landscape. The same dynamic plays out when attackers impersonate banks to induce wire transfers, when callback phishing campaigns use PayPal’s name to get victims to call a fraudulent support line, and when device code phishing exploits Microsoft’s authentication flow. The brand’s trust is the attack surface. The brand’s legitimate communication patterns provide the template. And the brand bears the reputational cost when customers discover that the notification they trusted was not real.

    Johnson made a related observation about banks specifically: “Banks used to say, ‘oh, we will never text you, we will never call you with anything suspicious.’ But you know what banks were doing? They were calling you. They were sending you text messages. So you had no idea which was legitimate and which wasn’t.”

    For organizations monitoring their external brand exposure, the Lam case is a reminder that the impersonation infrastructure, the spoofed caller IDs, fake security alerts, and fraudulent support channels, exists before the attack is launched. Johnson, speaking from twenty years on the other side, confirmed as much: “If it hasn’t been used against you yet, it will be. It’s not that you’re not going to be hit. You’re going to be.”

    The Bottom Line

    Malone Lam stole $230 million without writing a line of code, breaching a system, or deploying malware. He impersonated Google and Gemini, conditioned the victim with two weeks of fake alerts, and made a phone call that sounded exactly like the security response the victim expected. The platforms whose brands made the theft possible were never compromised. They were borrowed. And the victim, a sophisticated investor managing hundreds of millions in assets, did exactly what anyone would do when contacted by a service they trust about a threat they believed was real.

    Key Takeaways

    Who is Malone Lam and what did he do?

    Malone Lam is a 22-year-old Singaporean who pleaded guilty in September 2026 for stealing more than 4,100 Bitcoin, worth approximately $230 million, from a single victim. Lam and 17 co-defendants impersonated Google and Gemini exchange representatives, used two weeks of fake security alerts to condition the victim, then called and convinced him to hand over a one-time password. No systems were breached. It is one of the largest single-victim cryptocurrency thefts in US history.

    How did the $230 million cryptocurrency theft happen?

    The attackers sent persistent fake Google security alerts over roughly two weeks, conditioning the victim to expect a follow-up. When they called impersonating Google, the caller knew the victim’s personal information and the caller ID appeared legitimate. The victim read back a one-time password, which gave the attackers access to his cryptocurrency wallets. The entire operation relied on social engineering and brand impersonation rather than any technical exploit.

    What is a Google security alert scam?

     Fake Google security alerts are phishing messages designed to look like legitimate notifications about suspicious login attempts or account compromises. In the Malone Lam case, these alerts were sent persistently over two weeks to create a psychological pattern that made the eventual phone call feel like a legitimate follow-up. The alerts exploited Google’s real notification format, making them difficult to distinguish from genuine communications.

    How do social engineering attacks bypass security training?

    Former cybercriminal Brett Johnson explains that social engineering is designed to trigger emotional reactions, bypassing the rational analysis that training teaches. The attacker’s goal is to create urgency that overrides verification. In the Lam case, the victim was a sophisticated investor managing hundreds of millions in assets, yet complied because the attacker constructed a scenario indistinguishable from a legitimate security response. Intelligence and awareness do not prevent compliance when the emotional trigger is strong enough.

    How is cryptocurrency social engineering a brand impersonation problem?

    Google and Gemini were impersonated in the Lam theft, not compromised. The platforms’ own security notification patterns provided the template the attackers replicated. The brand’s credibility was the mechanism that made the victim comply. Organizations whose brands carry authentication authority, from tech platforms to banks to payment services, face the same exposure: their trust becomes the weapon in attacks they never initiated and cannot directly control.

    See the threats targeting your brand right now

    Get a customized assessment showing active impersonation, phishing infrastructure, and exposed credentials specific to your organization. No commitment required.