Skip to main content
AVOID.NET
Malone Lam Crypto Syndicatereviewed 2026-09-07 · 27 claims checked

Fact-check findings

What an automated fact-checker found when it re-read Malone Lam Crypto Syndicate against the sources the page cites. Only the most recent review is shown.

Read this first

These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.

“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.

Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.

disputed

1 claim

The reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.

  1. #23[disputed][awaiting moderator]in section: Guilty Pleas and Sentencing
    If convicted, Lam faces a potential minimum 20-year sentence.
    reviewerIf convicted, Lam faces a potential minimum 20-year sentenceRICO conspiracy has no mandatory minimum; 20 years is the statutory maximum per count. The page's phrasing inverts maximum and minimum, and is also inconsistent with September 2026 reporting citing a guideline estimate of roughly 14 years.
    Proposed correction (not yet applied)
    If convicted, Lam faces a potential maximum 20-year sentence per count.

unverifiable

1 claim

No source the reviewer could reach confirms or contradicts the claim.

  1. #27[unverifiable][awaiting moderator]in section: Threat to Cryptocurrency Holders and Security Implications
    The use of iCloud account access to surveil victims' physical locations prior to home invasions adds a physical-world dimension to the threat.
    reviewerThreat model narrative: victims selected via leaked databases/OSINT, attack methodology, iCloud surveillance, remote-access riskPlausible and consistent with the rest of the page's narrative, but could not be independently confirmed against a primary source in the time available.

stale

6 claims

The claim was accurate when written but events since have overtaken it.

  1. #2[stale][awaiting moderator]in section: Overview and Criminal Enterprise Structure
    The enterprise grew from a network of individuals connected through online gaming platforms including Minecraft and Discord, eventually encompassing at least 14 members based across California, Connecticut, New York, Florida, and internationally.
    reviewerEnterprise grew from gaming networks to 'at least 14 members' across listed statesThe '14 members' figure reflects the May 2025 superseding indictment (Lam + Serrano + 12). It excludes Veer Chetal, who was charged separately and secretly in November 2024, and other defendants added since. Current reporting (Sept 2026) puts the total charged at 18.
    Proposed correction (not yet applied)
    The enterprise grew from a network of individuals connected through online gaming platforms including Minecraft and Discord, eventually encompassing at least 18 members based across California, Connecticut, New York, Florida, and internationally.
  2. #3[stale][awaiting moderator]in the summary
    the enterprise comprised at least 14 members recruited through online gaming platforms and operated specialized roles including database hackers, social engineering callers, money launderers, and physical burglars
    reviewerEnterprise comprised at least 14 members (summary restatement)Same underlying undercount as in sections[0]; the role breakdown itself (database hackers, callers, launderers, burglars) is accurately confirmed by DOJ press materials.
    Proposed correction (not yet applied)
    the enterprise comprised at least 18 members recruited through online gaming platforms and operated specialized roles including database hackers, social engineering callers, money launderers, and physical burglars
  3. #18[stale][awaiting moderator]in section: Charges, Indictments, and RICO Application
    As of June 2026, nine defendants have pleaded guilty. Lam pleaded not guilty on May 19, 2025, and as of January 2026, plea negotiations were still ongoing, with a status conference scheduled for January 12, 2026.
    reviewerLam pleaded not guilty May 19, 2025; plea negotiations still ongoing as of January 2026 with Jan 12 2026 status conference; nine defendants pleaded guilty as of June 2026The May 19, 2025 not-guilty plea and January 12, 2026 status conference date are both independently confirmed and accurate as historical facts, but the 'nine defendants ... as of June 2026' framing is now superseded: contemporaneous reporting shows ten had pleaded guilty by September 2026 and Lam himself was about to plead guilty.
    Proposed correction (not yet applied)
    As of September 2026, ten co-defendants had pleaded guilty and Lam had a plea agreement hearing scheduled, at which he was expected to become the eleventh defendant to plead guilty; Serrano's case remained unresolved. Lam pleaded not guilty on May 19, 2025, and plea negotiations continued through late 2025 and into 2026, with status conferences including one on January 12, 2026.
  4. #20[stale][awaiting moderator]in the summary
    As of June 2026, nine co-defendants have pleaded guilty and been sentenced to 70–78 months, while Lam and co-lead Jeandiel Serrano remain in pre-trial proceedings.
    reviewerAs of June 2026, nine co-defendants pleaded guilty and were sentenced to 70-78 monthsBeyond being time-stale, the '70-78 months' range implies all nine were sentenced within it, but the page's own sections[3]/[5] content shows only Tangeman (70mo) and Ferro (78mo) had confirmed sentences; Mehta and others had pleaded guilty but not yet been sentenced per the most recent reporting found.
    Proposed correction (not yet applied)
    As of September 2026, ten co-defendants had pleaded guilty; sentences issued to date range from 70 to 78 months, though not all nine plea-takers named in this article had been sentenced by that point. Lam had a plea hearing scheduled and Serrano remained in pre-trial proceedings.
  5. #21[stale][awaiting moderator]in section: Guilty Pleas and Sentencing
    As of June 2026, nine co-defendants have pleaded guilty to RICO conspiracy and related charges. Sentences issued to date range from 70 to 78 months in federal prison.
    reviewerNine co-defendants pleaded guilty as of June 2026, sentences 70-78 months (section restatement)Same underlying staleness as the summary and sections[4] finding; grouped under lam-plea-status-stale.
    Proposed correction (not yet applied)
    As of September 2026, ten co-defendants had pleaded guilty to RICO conspiracy and related charges. Confirmed sentences issued to date (Tangeman, Ferro) range from 70 to 78 months in federal prison; several other guilty-plea defendants had not yet been sentenced.
  6. #22[stale][awaiting moderator]in section: Guilty Pleas and Sentencing
    Malone Lam and Jeandiel Serrano remain in pre-trial proceedings as of June 2026.
    reviewerMalone Lam and Jeandiel Serrano remain in pre-trial proceedings as of June 2026Same lam-plea-status-stale defect.
    Proposed correction (not yet applied)
    Jeandiel Serrano remained in pre-trial proceedings as of September 2026; Malone Lam had a plea agreement hearing scheduled for early September 2026, at which he was expected to plead guilty.

partially supported

2 claims

The cited evidence supports part of the claim but not all of it.

  1. #16[partially supported][awaiting moderator]in the timeline
    Malone Lam and initial co-conspirators begin the Social Engineering Enterprise while residing together in Texas, recruiting members through online gaming networks.
    reviewerEnterprise began no later than October 2023 while Lam and initial co-conspirators resided together in TexasThe Texas founding detail is accurate per court records reported elsewhere, but the specific source cited (TRM Labs) does not contain this detail; the citation does not support the claim it is attached to.
  2. #25[partially supported][awaiting moderator]in section: On-Chain Investigation and Asset Recovery
    The perpetrators made several operational security errors that facilitated identification: a slip-up on a Windows start page, an address used to purchase luxury clothing that was inadvertently shared, and Instagram posts by Lam's girlfriend that revealed his nightly location.
    reviewerOpSec errors: Windows start page slip-up, clothing-purchase address, girlfriend's Instagram location postsTwo of three listed opsec errors are independently confirmed; the 'Windows start page' detail could not be verified in any source consulted.

confirmed

17 claims

The cited evidence supports the claim as written.

  1. #1[confirmed][no action needed]in section: Overview and Criminal Enterprise Structure
    The Social Engineering Enterprise (SEE) was an alleged criminal organization founded approximately October 2023 by Malone Lam Yu Xuan, a Singaporean national born July 19, 2004, who resided in Miami and Los Angeles.
    reviewerMalone Lam's full legal name, birthdate, and nationalityName, DOB and nationality are consistently corroborated across sources. Residence list omits Texas, where the enterprise reportedly began; see separate finding on enterprise founding location/count.
  2. #4[confirmed][no action needed]in section: Overview and Criminal Enterprise Structure
    The DOJ charged the organization under the Racketeer Influenced and Corrupt Organizations Act (RICO), treating the network as a cohesive organized crime enterprise — a historically rare application of the statute to cryptocurrency theft.
    reviewerDOJ charged the organization under RICO, an aggressive/rare application to crypto theftMultiple outlets independently describe this as the first (or among the first) Bitcoin-related RICO prosecutions.
  3. #5[confirmed][no action needed]in section: The $230 Million Bitcoin Theft (August 2024)
    The enterprise's largest alleged theft occurred on August 18–19, 2024, when Lam and co-conspirator Jeandiel Serrano allegedly stole over 4,100 Bitcoin — valued at approximately $230–243 million at the time — from a single victim in Washington, D.C., who was a creditor of the defunct Genesis crypto trading firm.
    reviewerAugust 18-19, 2024 theft of over 4,100 BTC (~$230-243M) from a Genesis creditor in D.C.Well corroborated across DOJ and independent reporting.
  4. #6[confirmed][no action needed]in section: The $230 Million Bitcoin Theft (August 2024)
    The attack employed a multi-stage social engineering scheme. Attackers first called the victim using a spoofed telephone number impersonating Google Support, claiming the victim's account had been compromised. They then called again impersonating Gemini cryptocurrency exchange support, instructing the victim to reset two-factor authentication settings and install remote-access software (AnyDesk).
    reviewerAttack method: spoofed Google support call, then Gemini support call, 2FA reset, AnyDesk remote access, private key theftConfirmed via DOJ indictment narrative and independent reporting.
  5. #7[confirmed][no action needed]in section: The $230 Million Bitcoin Theft (August 2024)
    The stolen funds were split across multiple wallets and routed through more than 15 exchanges using peel chains, pass-through wallets, cryptocurrency mixers, and VPNs to obscure the money trail.
    reviewerFunds routed through more than 15 exchanges using peel chains, pass-through wallets, mixers, VPNsConfirmed.
  6. #8[confirmed][no action needed]in section: The $230 Million Bitcoin Theft (August 2024)
    On-chain investigator ZachXBT, collaborating with CFInvestigators, zeroshadow, and Binance Security, identified the primary suspects through blockchain tracing and activity correlation, ultimately helping law enforcement freeze more than $9 million in stolen assets and return approximately $500,000 to the victim.
    reviewerZachXBT, with CFInvestigators, zeroshadow, Binance Security, identified suspects; froze $9M, returned ~$500KWell corroborated.
  7. #9[confirmed][no action needed]in section: The $230 Million Bitcoin Theft (August 2024)
    ZachXBT published a thread identifying the perpetrators by their online aliases — 'Greavys' (Lam), 'Wiz' (Veer Chetal), and 'Box' (Serrano) — based in part on operational security errors including an exposed address used to purchase luxury clothing. Lam was further identified because his girlfriend shared location photographs on Instagram each night.
    reviewerZachXBT identified perpetrators via aliases; OpSec errors included exposed clothing-purchase address and girlfriend's nightly Instagram location postsBoth the clothing-address and girlfriend Instagram OpSec details are independently corroborated.
  8. #10[confirmed][no action needed]in section: Home Invasions and Physical Theft Operations
    Marlon Ferro (alias 'GothFerrari'), aged 19–20 of Santa Ana, California, served as the syndicate's 'physical-access operator.' In February 2024, Ferro allegedly broke into a home in Winnsboro, Texas, stealing approximately 100 Bitcoin worth over $5 million at the time.
    reviewerMarlon Ferro, 19-20, Santa Ana CA, broke into Winnsboro TX home in Feb 2024, stealing ~100 BTC (~$5M)Confirmed.
  9. #11[confirmed][no action needed]in section: Home Invasions and Physical Theft Operations
    Ferro was arrested on May 13, 2025, in possession of two firearms and false identification documents.
    reviewerJuly 2024 New Mexico home invasion via brick, iCloud tracking, $14M theft; Ferro arrested May 13, 2025 with firearms/false IDConfirmed.
  10. #12[confirmed][no action needed]in section: Home Invasions and Physical Theft Operations
    In a separate incident tied to the August 2024 Bitcoin theft, co-conspirator Veer Chetal's parents were allegedly carjacked in Connecticut one week after the heist, in what prosecutors allege was a botched kidnapping-for-ransom scheme executed by six Florida-based associates targeting proceeds from the theft.
    reviewerVeer Chetal's parents carjacked in Connecticut one week after the heist, botched kidnapping-for-ransom by six Florida-based associatesConfirmed; date and 'six men from Florida/Miami' detail both independently corroborated.
  11. #13[confirmed][no action needed]in section: Money Laundering and Proceeds
    Kunal Mehta (aliases 'Papa', 'The Accountant', 'Shrek') of Irvine, California, the eighth defendant to plead guilty (November 18, 2025), allegedly laundered at least $25 million and created shell companies to facilitate cryptocurrency-to-cash conversions, charging a 10% fee.
    reviewerKunal Mehta, 8th to plead guilty (Nov 18 2025), laundered $25M via shell companies, 10% fee, exotic vehiclesConfirmed. Note that as of the most recent reporting found, Mehta had pleaded guilty but had not yet been sentenced.
  12. #14[confirmed][no action needed]in section: Money Laundering and Proceeds
    Evan Tangeman, 22, of California, the ninth defendant to plead guilty (December 2025), laundered at least $3.5 million, secured luxury rental homes across California and Florida using false identities, and after the September 2024 arrests of Lam and Serrano, allegedly directed other members to destroy digital devices to obstruct the investigation. Law enforcement recovered a Rolls Royce Ghost (valued over $300,000) and Porsche GT3 RS from his properties.
    reviewerEvan Tangeman, 22, 9th to plead guilty (Dec 2025), laundered $3.5M, destroyed devices, Rolls Royce/Porsche seizedConfirmed.
  13. #15[confirmed][no action needed]in section: Money Laundering and Proceeds
    The group's spending patterns were alleged to be extravagant: members reportedly spent approximately $4 million at Los Angeles nightclubs over a three-week period, up to $500,000 in a single night, chartered private jets, purchased designer clothing (over $255,000 on record), luxury watches, jewelry, and rented mansions using fraudulent documents. Bulk cash was allegedly concealed for transport inside stuffed animals (Squishmallows toys). Proceeds were also allegedly distributed as Hermes bags as gifts.
    reviewerNightclub spending ~$4M over three weeks, up to $500K/night, designer clothing >$255K, Squishmallows cash smuggling, Hermes gift bagsWell corroborated across multiple independent outlets.
  14. #17[confirmed][no action needed]in section: Charges, Indictments, and RICO Application
    In May 2025, a superseding indictment charged 12 additional defendants — including Kunal Mehta, Hamza Doost, Joel Cortez, Evan Tangeman, Marlon Ferro, Conor Flansburg, Nicholas Dellecave, Mustafa Ibrahim, Danish Zulfiqar, and others — under RICO conspiracy, conspiracy to commit wire fraud, money laundering, and obstruction of justice. Two defendants remain at large, reportedly in Dubai.
    reviewer12 additional defendants charged in May 2025 superseding indictment; two remain at large in DubaiThis is an accurate account of the May 2025 superseding indictment specifically, distinct from the case's cumulative defendant total (see enterprise-member-count-stale finding).
  15. #19[confirmed][no action needed]in section: Charges, Indictments, and RICO Application
    The case is reported to be among the first Bitcoin-related RICO prosecutions in U.S. history, and represents what prosecutors have described as one of the most aggressive crypto theft charge sets ever filed.
    reviewerThe case is among the first Bitcoin-related RICO prosecutions and one of the most aggressive crypto theft charge setsConfirmed and appropriately hedged ('among the first' / 'described as').
  16. #24[confirmed][no action needed]in section: On-Chain Investigation and Asset Recovery
    The initial identification of Lam and Serrano was significantly aided by independent blockchain investigator ZachXBT, who published a detailed analysis thread shortly after the August 2024 theft. Working with collaborators CFInvestigators, zeroshadow, and Binance Security, ZachXBT traced the stolen funds through more than 15 exchanges and constructed an activity/identity correlation diagram linking the suspects' online aliases to their real identities.
    reviewerZachXBT thread, collaborators, 15+ exchanges, aliases before arrestConfirmed.
  17. #26[confirmed][no action needed]in section: On-Chain Investigation and Asset Recovery
    The stolen Bitcoin — over 4,100 BTC — was valued at approximately $230–243 million at the time of theft; as of late 2025, that quantity of Bitcoin is estimated to be worth approximately $384 million.
    reviewerStolen 4,100+ BTC valued at $230-243M at time of theft, ~$384M as of late 2025The $384M mark-to-market estimate is independently corroborated by contemporaneous reporting, though the page does not cite a source for this specific figure.
How this fits together. The reviewer reads the published page and its cited sources and records one finding per claim. A human moderator decides whether each proposed correction is applied; those decisions, and the score changes they cause, appear in the audit log. Earlier review runs are not shown here; only the latest reflects the page as it stands.