• About
  • Privacy Poilicy
  • Disclaimer
  • Contact
CoinInsight
  • Home
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Ripple
  • Future of Crypto
  • Crypto Mining
No Result
View All Result
  • Home
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Ripple
  • Future of Crypto
  • Crypto Mining
No Result
View All Result
CoinInsight
No Result
View All Result
Home Future of Crypto

How Crypto Fraud Became a Business

Coininsight by Coininsight
September 12, 2026
in Future of Crypto
0
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

Related articles

ESMA Warns Crypto’s Expanding Financial Links Could Magnify Europe’s Next Market Shock

September 11, 2026

MEXC Stock Futures Trading Volume Rises 130% in August as Trading Activity Broadens Across U.S. and Korean emory and Semiconductor Sectors

September 11, 2026


One of the largest cryptocurrency thefts from a single victim did not require breaking Bitcoin’s cryptography. Stolen data, a credible story and the victim’s cooperation were enough to take over $245 million in virtual currency from a single Washington, D.C. resident in August 2024.

On September 8, 2026, Malone Lam, a 22-year-old Singaporean national, pleaded guilty to a racketeering conspiracy charge in the US.

Prosecutors say the enterprise he helped run operated from October 2023 to at least May 2025, hacking and buying databases of cryptocurrency holders, then analysing the data to identify high-value targets. In some cases, members broke into victims’ homes to seize hardware wallets.

Malone Lam, 22, a citizen of Singapore and recent resident of Miami, pleaded guilty today in connection with his role as ringleader of an international cybercrime conspiracy that used social engineering to steal and launder cryptocurrency valued at more than $245 million,… pic.twitter.com/R8Nnz9a7n6

— U.S. Attorney DC (@USAO_DC) September 8, 2026

Fraud-as-Business Model

Lam’s enterprise worked as an organised business with a clear hierarchy and distinct roles. Participants specialised in different domains, and each executed a specific part of the operation.

Database hackers breached websites and servers, or bought stolen records on the dark web, to build lists of potential victims. Target identifiers then combed the lists for the wealthiest prospects.

In a group chat cited in the indictment, Lam offered co-defendant Conor Flansburg roughly 40 of those organised, stolen databases. Flansburg agreed to send Lam and a fellow organiser a 20% cut of any theft over $10 million, replying, “we hackin, all day every day.”

A separate team of launderers converted the proceeds into cash, wire transfers and goods. None of these roles required breaking Bitcoin’s cryptography, only data about who held the assets, how to reach them and how to make the approach believable.

That division of labour is not unique to Lam’s network. A 2026 Global Initiative Against Transnational Organized Crime study of Ukrainian scam call centres described a similar structure at national scale: callers, closers, IT teams, HR, trainers, finance staff and administrators, each handling one link in the chain.

Chart from Global Initiative Against Transnational Organized Crime report.

The point is not the geography, but the operating model: social engineering has become a staffed, segmented business. A wallet does not need to be breached directly if attackers can identify the owner, assemble a convincing profile and induce the transfer.

In 2025, Coinbase said criminals had bribed overseas support agents to copy customer names, addresses, identification documents, transaction histories and balance snapshots.

The company said no passwords or private keys were exposed, and that it would reimburse customers tricked into transferring funds. Coinbase said the stolen data was intended to make later impersonation attempts more convincing.

Lam’s enterprise, the Ukrainian call centres and the Coinbase breach have one thing in common: in none of them did a private key get compromised.

The common thread is that the attack began outside the cryptographic layer. The weakest point was not the chain, but the information surrounding its users.

Customer Data Enters the Custody Perimeter

Private-key protection still matters, but it covers only one part of the attack chain. A hardware wallet cannot protect an owner whose identity, contact details and approximate holdings have already been assembled into a target profile. Cryptography cannot establish whether a transaction was authorised freely, under deception or under physical threat.

Customer records are now part of the asset-security problem. A balance snapshot, address, phone number or support note can help attackers choose a target and make an impersonation attempt credible.


Exchanges
and custodians therefore need to treat access to customer data more like access to operational keys: tightly logged, narrowly permissioned and harder to use after an unsolicited support contact.

Higher-risk transfers can require cooling-off periods, extra verification, or sign-off split across more than one person; self-custody setups face the same question if a single identifiable individual can move all the assets at once.

Lam’s enterprise ran on a supply chain of database hackers, target identifiers, callers and launderers built around a straightforward split of the proceeds.

A federal court in Washington, D.C. is scheduled to hold a status hearing in the case on December 8, 2026, when a sentencing date is expected to be set. That hearing will be the next point at which the machinery behind the $245 million theft returns to public view.

One of the largest cryptocurrency thefts from a single victim did not require breaking Bitcoin’s cryptography. Stolen data, a credible story and the victim’s cooperation were enough to take over $245 million in virtual currency from a single Washington, D.C. resident in August 2024.

On September 8, 2026, Malone Lam, a 22-year-old Singaporean national, pleaded guilty to a racketeering conspiracy charge in the US.

Prosecutors say the enterprise he helped run operated from October 2023 to at least May 2025, hacking and buying databases of cryptocurrency holders, then analysing the data to identify high-value targets. In some cases, members broke into victims’ homes to seize hardware wallets.

Malone Lam, 22, a citizen of Singapore and recent resident of Miami, pleaded guilty today in connection with his role as ringleader of an international cybercrime conspiracy that used social engineering to steal and launder cryptocurrency valued at more than $245 million,… pic.twitter.com/R8Nnz9a7n6

— U.S. Attorney DC (@USAO_DC) September 8, 2026

Fraud-as-Business Model

Lam’s enterprise worked as an organised business with a clear hierarchy and distinct roles. Participants specialised in different domains, and each executed a specific part of the operation.

Database hackers breached websites and servers, or bought stolen records on the dark web, to build lists of potential victims. Target identifiers then combed the lists for the wealthiest prospects.

In a group chat cited in the indictment, Lam offered co-defendant Conor Flansburg roughly 40 of those organised, stolen databases. Flansburg agreed to send Lam and a fellow organiser a 20% cut of any theft over $10 million, replying, “we hackin, all day every day.”

A separate team of launderers converted the proceeds into cash, wire transfers and goods. None of these roles required breaking Bitcoin’s cryptography, only data about who held the assets, how to reach them and how to make the approach believable.

That division of labour is not unique to Lam’s network. A 2026 Global Initiative Against Transnational Organized Crime study of Ukrainian scam call centres described a similar structure at national scale: callers, closers, IT teams, HR, trainers, finance staff and administrators, each handling one link in the chain.

Chart from Global Initiative Against Transnational Organized Crime report.

The point is not the geography, but the operating model: social engineering has become a staffed, segmented business. A wallet does not need to be breached directly if attackers can identify the owner, assemble a convincing profile and induce the transfer.

In 2025, Coinbase said criminals had bribed overseas support agents to copy customer names, addresses, identification documents, transaction histories and balance snapshots.

The company said no passwords or private keys were exposed, and that it would reimburse customers tricked into transferring funds. Coinbase said the stolen data was intended to make later impersonation attempts more convincing.

Lam’s enterprise, the Ukrainian call centres and the Coinbase breach have one thing in common: in none of them did a private key get compromised.

The common thread is that the attack began outside the cryptographic layer. The weakest point was not the chain, but the information surrounding its users.

Customer Data Enters the Custody Perimeter

Private-key protection still matters, but it covers only one part of the attack chain. A hardware wallet cannot protect an owner whose identity, contact details and approximate holdings have already been assembled into a target profile. Cryptography cannot establish whether a transaction was authorised freely, under deception or under physical threat.

Customer records are now part of the asset-security problem. A balance snapshot, address, phone number or support note can help attackers choose a target and make an impersonation attempt credible.


Exchanges
and custodians therefore need to treat access to customer data more like access to operational keys: tightly logged, narrowly permissioned and harder to use after an unsolicited support contact.

Higher-risk transfers can require cooling-off periods, extra verification, or sign-off split across more than one person; self-custody setups face the same question if a single identifiable individual can move all the assets at once.

Lam’s enterprise ran on a supply chain of database hackers, target identifiers, callers and launderers built around a straightforward split of the proceeds.

A federal court in Washington, D.C. is scheduled to hold a status hearing in the case on December 8, 2026, when a sentencing date is expected to be set. That hearing will be the next point at which the machinery behind the $245 million theft returns to public view.



Share76Tweet47

Related Posts

ESMA Warns Crypto’s Expanding Financial Links Could Magnify Europe’s Next Market Shock

by Coininsight
September 11, 2026
0

Key Takeaways:Nearly €2 trillion of market value has been stripped from crypto losses since their October highs per ESMA.The convergence...

MEXC Stock Futures Trading Volume Rises 130% in August as Trading Activity Broadens Across U.S. and Korean emory and Semiconductor Sectors

by Coininsight
September 11, 2026
0

Mutsamudu, Comoros, September 11, 2026 — MEXC, a pioneer in 0-fee digital asset trading, released its August TradFi trading data....

ESMA Flags Crypto Spillover, Prediction Market Risks

by Coininsight
September 10, 2026
0

Europe’s securities regulator has warned that growing links between crypto and traditional finance could increase the risk of shocks spreading...

Zamanat Targets the GCC’s $250 Billion SME Financing Gap With a Tokenized Private Credit Fund of Up to $100 Million

by Coininsight
September 10, 2026
0

Disclaimer: The below article is sponsored, and the views in it do not represent those of ZyCrypto. Readers should conduct...

Iran’s $10B Crypto Surge Helps Bypass Trade Restrictions

by Coininsight
September 9, 2026
0

As the US sanctions continue to strain its economy, Iran is now relying on crypto to keep its cross-border trade...

Load More
  • Trending
  • Comments
  • Latest
What’s Actually Going On With Ripple’s Blockchain?

What’s Actually Going On With Ripple’s Blockchain?

January 12, 2026
MetaMask Launches An NFT Reward Program – Right here’s Extra Data..

MetaMask Launches An NFT Reward Program – Right here’s Extra Data..

July 24, 2025
Finest Bitaxe Gamma 601 Overclock Settings & Tuning Information

Finest Bitaxe Gamma 601 Overclock Settings & Tuning Information

November 26, 2025
Easy methods to Host a Storj Node – Setup, Earnings & Experiences

Easy methods to Host a Storj Node – Setup, Earnings & Experiences

March 11, 2025
Kuwait bans Bitcoin mining over power issues and authorized violations

Kuwait bans Bitcoin mining over power issues and authorized violations

2
The Ethereum Basis’s Imaginative and prescient | Ethereum Basis Weblog

The Ethereum Basis’s Imaginative and prescient | Ethereum Basis Weblog

2
Unchained Launches Multi-Million Greenback Bitcoin Legacy Mission

Unchained Launches Multi-Million Greenback Bitcoin Legacy Mission

1
Earnings Preview: Microsoft anticipated to report larger Q3 income, revenue

Earnings Preview: Microsoft anticipated to report larger Q3 income, revenue

1

Coinbase, Moov Bring Stablecoin Payments to 1,000+ Banks

September 12, 2026

How Crypto Fraud Became a Business

September 12, 2026

Why’s the stock market riding high when the economy isn’t – and can it last?

September 12, 2026

Success Story: Jhester Metchado’s Learning Journey with 101 Blockchains

September 12, 2026

CoinInight

Welcome to CoinInsight.co.uk – your trusted source for all things cryptocurrency! We are passionate about educating and informing our audience on the rapidly evolving world of digital assets, blockchain technology, and the future of finance.

Categories

  • Bitcoin
  • Blockchain
  • Crypto Mining
  • Ethereum
  • Future of Crypto
  • Market
  • Regulation
  • Ripple

Recent News

Coinbase, Moov Bring Stablecoin Payments to 1,000+ Banks

September 12, 2026

How Crypto Fraud Became a Business

September 12, 2026
  • About
  • Privacy Poilicy
  • Disclaimer
  • Contact

© 2025- https://coininsight.co.uk/ - All Rights Reserved

No Result
View All Result
  • Home
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Ripple
  • Future of Crypto
  • Crypto Mining

© 2025- https://coininsight.co.uk/ - All Rights Reserved

Social Media Auto Publish Powered By : XYZScripts.com
Verified by MonsterInsights