SubscribeBTCSCAMWallet Test
Front page / Community Win
Community Win

How on-chain investigators traced a $243M Bitcoin heist within days

A fake Google and Gemini support call drained more than 4,100 BTC from one Genesis creditor. Public tracing by ZachXBT and collaborators helped turn it into a federal RICO case.

JR
Jules Renner
Community Manager · JUL 20, 2026 · 4 min read
Painting: Renaissance archive · Source: U.S. Department of Justice (USAO-DC)

On August 18, 2024, a Washington, DC resident who was a creditor of the bankrupt lender Genesis lost more than 4,100 Bitcoin in a single afternoon — a haul worth roughly $230 million to $243 million at the time. According to the DOJ, it stands as the largest known single-victim cryptocurrency theft. No servers were breached and no code was exploited. The victim was talked out of the money over the phone.

The crew posed as support staff. Callers spoofing Google and the Gemini exchange convinced the victim to reset two-factor authentication and move funds to wallets the attackers controlled, according to the DOJ. It is the oldest trick in the fraud playbook — a trusted-brand impersonation — executed against a very large target.

The trail was public within days

What made this case different is what happened next. Independent on-chain investigators, including ZachXBT and the firm zeroShadow, began mapping the stolen coins almost immediately, following them across peel chains, mixers and multiple exchanges. Their work was documented in public, in near real time. Early on, more than $9 million was frozen and about $500,000 was returned to the victim.

That public evidence trail did not sit idle. In September 2024, the U.S. Attorney's Office for the District of Columbia arrested and charged Malone Lam — a Singaporean national born in 2004 who went by "Greavys" — and Jeandiel Serrano, known as "Box." A third principal, Veer Chetal, or "Wiz," also faced charges and cooperated. The DOJ's initial filing valued the theft at about $230 million.

From two defendants to a RICO enterprise

The case kept growing. On May 16, 2025, the DOJ unsealed a superseding indictment that treated the group — which had expanded to roughly 14 members, many of them friends from online gaming — as a single racketeering enterprise that stole more than $263 million between 2023 and early 2025. Prosecutors charged 12 additional people with racketeering conspiracy, wire-fraud conspiracy, money laundering and obstruction.

The roles read like an organized-crime chart: database hackers, "callers," launderers and in-person burglars. The DOJ tied violent home invasions to the ring, including a July 2024 New Mexico break-in connected to defendant Marlon Ferro, in which crews sought to seize victims' hardware wallets. Investigators said proceeds bought roughly 33 luxury and exotic cars, along with jewelry and nightclub spending, and that bulk cash was mailed hidden inside stuffed toys.

By mid-2026 the prosecution had produced nine guilty pleas. Kunal Mehta, known as "Papa" and the eighth defendant to plead, admitted to RICO conspiracy on November 18, 2025 after laundering at least about $25 million, per the IRS's Criminal Investigation division; the DOJ separately announced a 70-month prison term for a California money launderer in the scheme. Lam, the alleged ringleader, had not entered a plea as of May 2026 and remained in custody, with a status hearing set for June 18, 2026.

How to shut this attack down

  • No real exchange, wallet provider or Google will phone you unprompted to "secure" your account or walk you through resetting two-factor authentication. Treat any inbound "support" call as hostile.
  • Hang up and reconnect through the company's official app or a URL you typed yourself — never a number or link the caller provides.
  • Never move funds, disable a security key or reset 2FA because someone on the phone tells you to; legitimate support never needs that.
  • Keep serious holdings in a hardware wallet, and never type or read your recovery phrase to anyone, ever.
  • Avoid broadcasting the size of your crypto holdings; this ring escalated to in-person burglaries aimed at hardware wallets.

The lesson from the wreckage is not just how badly a single phone call can go. It is that public, documented on-chain evidence works. Within days, open-source investigators had turned a quiet, catastrophic theft into a visible money trail — and that trail helped federal prosecutors build one of the largest crypto-crime cases on record.

— Sources: [DOJ / USAO-DC](https://www.justice.gov/usao-dc/pr/indictment-charges-two-230-million-cryptocurrency-scam) · [IRS Criminal Investigation](https://www.irs.gov/compliance/criminal-investigation/cryptocurrency-money-launderer-pleads-guilty-to-rico-conspiracy-in-scheme-that-stole-263-million-in-crypto) · [TRM Labs](https://www.trmlabs.com/resources/blog/doj-uses-organized-crime-statute-in-263-million-cryptocurrency-theft-money-laundering-and-home-invasion-conspiracy) · [CoinDesk](https://www.coindesk.com/business/2024/09/19/police-arrests-two-people-related-to-243m-crypto-heist-targeting-genesis-creditor)

The Rug Report
Every scam that mattered this week, each Sunday.

NOT FINANCIAL ADVICE · VERIFY EVERYTHING