What Malone Lam admitted
Lam pleaded guilty in federal court in the District of Columbia to one count of participating in a RICO conspiracy. The Justice Department describes him as an organizer who identified potential victims and coordinated roles within the group. US District Judge Colleen Kollar-Kotelly scheduled a status hearing for December 8, 2026, but has not set a sentencing date.
The Associated Press reports that the admitted charge carries a statutory maximum of 20 years in prison. That is a ceiling, not a forecast of the sentence. A plea agreement, federal guidelines, asset recovery and other factors may affect the outcome when the judge addresses sentencing.
How one phone call opened a path to 4,100 BTC
The largest theft occurred on August 18, 2024. According to prosecutors and the AP account, co-conspirators called a Bitcoin holder while posing in sequence as representatives of Google and the Gemini crypto exchange. They persuaded the victim to provide access to a cloud account and disclose security codes, allowing the group to transfer more than 4,100 BTC.
This was not a breach of the Bitcoin blockchain or a cryptographic attack that guessed a private key. The attackers moved the trust boundary to the person, email account, cloud storage and recovery procedures. The network correctly processed authorized transactions but could not determine that the authorization had been obtained through deception.
Why the court records use different loss figures
The original indictment valued the 4,100 BTC at more than $230 million when they were transferred. The latest Justice Department release describes the enterprise tied to Lam as exceeding $245 million. A 2025 superseding indictment alleged more than $263 million across multiple thefts and victims.
Those figures should not be added together. They reflect different charging scopes, valuation dates and sets of assets. The 4,100 BTC amount describes the largest single incident, while the enterprise-wide dollar figures include other thefts and changed as the case expanded. The published record does not establish a final restitution total.
What happened to the stolen funds
The Justice Department says participants spent cryptocurrency on private jets, rental homes, security guards, luxury watches and handbags, and a fleet of cars worth as much as $3.8 million each. Its case summary lists nightclub services costing up to $500,000 per evening. AP separately describes a bill of about $569,000 at one Los Angeles club and a $2 million watch.
Lam's plea establishes his responsibility for the agreed RICO-conspiracy count, but it does not turn every allegation in the indictment into a separate judicial finding against every defendant. Eighteen people have been charged in the case. AP says Lam became the eleventh to plead guilty; allegations against defendants whose cases are unresolved remain allegations.
Why ordinary two-factor authentication may not be enough
A one-time code protects an account only while the user enters it into the genuine interface and does not disclose it. An attacker who convincingly impersonates support may try to obtain the password, verification code and screen access during one conversation. CISA therefore recommends phishing-resistant multi-factor authentication, especially physical security keys based on FIDO standards.
Gemini explicitly says it does not call customers, offer phone support, or ask anyone to send cryptocurrency, disclose a verification code or reveal a secret recovery phrase. Any unexpected call claiming an account is under attack should be ended. The alert should then be checked independently through a saved official address or app, never through a link or phone number supplied in the incoming message.
How to separate Bitcoin custody from account recovery
A hardware wallet cannot protect a backup if its seed phrase is stored in cloud storage, a photograph or a note accessible through the primary email account. For substantial balances, keep the signing device separate from the everyday computer, keep recovery secrets offline, and verify the destination and amount on a trusted display before approval. A request to share a screen or install remote-access software should stop the transaction.
If an account takeover is suspected, end the conversation first and secure email and cloud storage from a clean device: change the password, terminate unfamiliar sessions and review recovery methods. Contact the exchange only through its official channel, then assess the wallet. A deliberate pause is safer than moving funds under pressure from someone manufacturing urgency.