Mark RadarMARK RADAR
About
EN
Sign in
Event File CRYPTO Social Engineering

Crypto Ringleader Malone Lam Pleads Guilty in $245 Million RICO Case

2 reports · First detected 2026-09-09 · Last active 2026-09-09

U.S. prosecutors said Malone Lam built an international cybercrime network through contacts made on online gaming platforms, with the enterprise operating from at least October 2023 to May 2025. Its members used social engineering and, at times, home break-ins to obtain credentials and drain cryptocurrency wallets. The case underscores how attackers can exploit a holder’s identity and trust without breaching the underlying blockchain.

Lam, a 22-year-old Singapore citizen and former Miami resident, pleaded guilty on Sept. 8, 2026, in U.S. District Court in Washington to one count of participating in a RICO conspiracy. Prosecutors valued the cryptocurrency stolen and laundered at more than $245 million. Lam spent as much as $500,000 on nightclub services in a single evening and faces up to 20 years in prison; Judge Colleen Kollar-Kotelly set a status hearing for Dec. 8.

All Coverage

2 original reports

The Backstory

The history behind this event
California Man Sentenced to 78 Months in $250 Million Crypto Theft Conspiracyfirst seen 2026-05-07 · 1 reports · similarity 0.81

The case stemmed from a social-engineering crime ring operating across several US states and overseas. From late 2023 to early 2025, its members divided tasks including database hacking, fraudulent phone calls and money laundering to steal more than $250 million in cryptocurrency. When hardware wallets could not be breached remotely, members resorted to physical break-ins, underscoring how digital-asset security also involves risks to personal safety and homes.

The US Attorney's Office for the District of Columbia said 20-year-old Marlon Ferro was sentenced in federal court on May 6, 2026, to 78 months in prison, followed by three years of supervised release, and ordered to pay $2.5 million in restitution. In February 2024, he stole a hardware wallet in Texas containing about 100 Bitcoin, then worth more than $5 million. He pleaded guilty to RICO conspiracy on October 17, 2025.

Crypto Users Targeted in Social Engineering Attack Using Obsidian Community Pluginsfirst seen 2026-04-15 · 1 reports · similarity 0.69 · same topic: Social Engineering

Cryptocurrency transactions are typically difficult to reverse once recorded on-chain, making industry professionals with access to wallet credentials high-risk targets for social engineering. Chainalysis estimates that compromises of personal crypto wallets caused $713 million in losses in 2025. The incident also shows how legitimate productivity tools such as Obsidian and their community plugins can be turned into entry points for corporate breaches.

Elastic Security Labs disclosed the REF6598 campaign on April 14, 2026. Scammers posed as a venture capital firm, initially contacting finance and crypto professionals on LinkedIn before moving conversations to Telegram and persuading victims to open an attacker-controlled Obsidian cloud vault and sync its plugins. The campaign targeted both Windows and macOS systems and deployed the PHANTOMPULSE remote access trojan. Elastic said it intercepted the attack at an early stage.

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)