The biggest crypto theft in US history went through a Google Drive
Malone Lam pleaded guilty on September 8 to a racketeering conspiracy that took more than 4,100 bitcoin from one man in Washington. Nobody broke any cryptography.

Malone Lam, 22, pleaded guilty on Tuesday September 8 to one count of federal racketeering conspiracy over an international scheme that stole and laundered more than $245 million of cryptocurrency. He faces up to 20 years. Judge Colleen Kollar-Kotelly set a status hearing for December 8.
The method deserves more attention than the number. In August 2024 two of Lam's alleged co-conspirators posed as representatives of Google and the Gemini exchange, talked a Washington man into giving them access to his Google Drive, got the security codes out of him, and moved over 4,100 bitcoin.
A quarter of a billion dollars, taken by telephone.
But no cryptography failed here. No exchange was hacked, no bridge exploited, no signature forged. The victim's keys did exactly what keys do. What failed was a person on a call, which is the failure mode that has never once been fixed by a better wallet, and the reason the industry's security spending keeps missing the biggest single incident in its own history.
Work the arithmetic and the theft prices bitcoin at about $59,750 a coin at the time (4,100 coins, $245 million), which tells you how much this story has been marked to market since.
What came next reads like a script nobody would greenlight. Prosecutors say Lam laundered the proceeds into a fleet of sports cars (one valued at $3.8 million), rented mansions in Miami, Los Angeles and the Hamptons, luxury handbags and watches, and nightclub evenings running close to $500,000. One night in a Los Angeles club came to $569,000. That is roughly nine and a half stolen bitcoin, spent between dinner and closing.
He was arrested on September 18, 2025, at his rental home in Miami, exotic cars in the driveway. The indictment says an off-duty law enforcement officer had tipped him off that agents were coming. From jail, on a recorded call, he told associates: "We always talked about what it would be like if I were to go down, but never thought it would be this crazy." So where is the money? Neither account we read gives a recovery figure, and that silence is the part of this story we would push on. Eighteen defendants have been charged and eleven have now pleaded guilty. Evan Tangeman, also 22, was sentenced in April to over five years. And a case this well documented, with this many cooperating defendants and this much conspicuous spending, is probably close to the best conditions American law enforcement will ever get for clawing back stolen crypto.
Our read is that the recovery will still likely be poor, and that we will find out at sentencing rather than before. We would expect the forfeiture figure to land under half the $245 million, and we would be glad to be wrong. If prosecutors announce recovery above that, it changes what a large theft is worth attempting, and every threat model in this industry should be rewritten around it.
One detail keeps catching us. Lam is described as an eighth-grade dropout who came to the US from Singapore, running a network of young men doing crypto scams from 2023. The prosecutors' own framing is a cybercrime empire. The tooling was a phone, a script and somebody else's Google account.
What would you have done on that call?
