OAK — OnChain Attack Knowledge

Worked example · 2024-08

Genesis Creditor — Multi-Stage Impersonation Social Engineering — 2024-08-19

Loss
~$243M in BTC, ETH, and other crypto assets from a single Genesis Global Capital creditor. Three figures circulate and each is correct for what it measures: $230M+ is the amount charged in the original 2024 indictment; ~$243M is the market-price valuation of the assets at the moment of theft; and $263M is the DOJ's figure as of the 2025-12-08 RICO announcement, stated as over 4,100 BTC and worth more than $368M by that date. The spread is BTC price movement, not a disputed quantity.
OAK Techniques observed
OAK-T4.007 (Native App Social Phishing / Engagement-Weighted Platforms) — primary; OAK-T7 (Laundering) — post-exploit.
Attribution
confirmed — originally three named threat actors: Malone Lam ("Greavys"; rendered "Malone Iam" in ZachXBT's original thread — a capital-I/lowercase-l transcription error. Full name Malone Lam Yu Xuan; the DOJ record and all subsequent reporting use Lam), Veer Chetal ("Wiz"), and Jeandiel Serrano ("Box"). Malone arrested in Miami (Sep 2024); Wiz and Box at large as of ZachXBT's investigation date. A fourth associate, Aakaash ("Light/Dark"), assisted with laundering. The case has since expanded far beyond those three. By the DOJ's announcement of 2025-12-08, the prosecution had been recast as a RICO racketeering conspiracy, twelve individuals stood charged, and nine had entered guilty pleas — including Veer Chetal. A Second Superseding Indictment added Nicholas Dellecave ("Nic", "Souja"; arrested Miami 2025-12-03), Mustafa Ibrahim ("Krust"; arrested in Dubai), and Danish Zulfiqar ("Danny", "Meech"; arrested in Dubai). Separately, Evan Tangeman (Newport Beach, CA) pleaded guilty to RICO conspiracy, admitting he laundered at least $3.5M for the enterprise, with sentencing set for 2026-04-24.
Key teaching point
This is the largest known social engineering theft against a single individual in crypto history. The attack demonstrates the multi-stage impersonation escalation pattern: the attackers chained spoofed calls (Google Support → Gemini Support), each stage extracting credentials or authorizations that enabled the next. The victim was a sophisticated institutional creditor, not a retail user. The laundering used 15+ exchanges with rapid cross-asset swapping (BTC→LTC→ETH→XMR) to break traceability.

Summary

On August 19, 2024, three threat actors executed a highly sophisticated social engineering attack against a single Genesis Global Capital creditor, stealing approximately $243M in cryptocurrency. The attackers:

  1. Called the victim spoofing Google Support, compromising personal accounts (email, cloud storage) to extract sensitive financial information
  2. Called again spoofing Gemini Support, using the compromised information to gain trust; per the DOJ record the victim was induced to reset two-factor authentication and transfer funds to a wallet the attackers controlled
  3. Drained the victim's crypto assets to attacker-controlled addresses
  4. Split the proceeds three ways, laundering through 15+ exchanges with rapid cross-asset swaps (BTC → LTC → ETH → XMR)

ZachXBT traced the full on-chain flow and identified the three principals through a combination of on-chain analysis, leaked screen-share recordings, and private database searches. The private video recording showing the threat actors' live reaction to receiving $238M became key evidence. Malone Lam was arrested by FBI in Miami in September 2024; the other two remain at large.

Timeline (UTC)

When Event OAK ref
Pre-Aug 2024 Attackers research target: a Genesis creditor with large crypto holdings (preparation)
2024-08-19 ~T+0h Call #1: Spoof Google Support number → compromise personal email/cloud accounts → extract financial account information T4.007 impersonation stage 1
2024-08-19 ~T+1h Call #2: Spoof Gemini Support → use compromised info to gain trust → obtain wallet credentials T4.007 impersonation stage 2
2024-08-19 ~T+2h $243M drained from victim wallets to attacker-controlled addresses. 4,064 BTC ($238M) transferred in single tx T4.007 drain
2024-08-19~Sep Laundering: funds split three ways, swapped BTC→LTC→ETH→XMR via 15+ exchanges, eXch, THORSwap T7 laundering
2024-09 Malone Lam (Greavys) arrested in Miami by FBI. Wiz (Veer Chetal) and Box (Jeandiel Serrano) remain at large (legal action)
2024-09-19 ZachXBT publishes full investigation with on-chain tracing of all three principals (public disclosure)
2024-11 Veer Chetal ("Wiz") secretly charged; later pleads guilty and forfeits ~30 designer watches, clothing, and $36M+ in ETH; loses bond after a further ~$2M crypto theft while awaiting sentencing (legal action)
2025-12-03 Nicholas Dellecave ("Nic", "Souja") arrested in Miami (legal action)
2025-12-08 DOJ announces a Second Superseding Indictment charging Dellecave, Mustafa Ibrahim ("Krust", arrested Dubai) and Danish Zulfiqar ("Danny", "Meech", arrested Dubai) with RICO conspiracy, bringing the total charged to twelve, of whom nine have pleaded guilty. Same announcement: Evan Tangeman pleads guilty to RICO conspiracy, admitting he laundered ≥$3.5M for the enterprise (sentencing 2026-04-24). DOJ states the theft totalled over 4,100 BTC, worth $263M in August 2024 and >$368M by the announcement date (legal action)

What defenders observed

  • Pre-attack (targeting phase): The attackers accessed personal information (name, email, phone, associated financial accounts) enabling convincing impersonation. The victim was a known creditor in the Genesis bankruptcy — this information asymmetry was the initial foothold.
  • During attack (impersonation chain): Two spoofed calls in sequence — Google then Gemini. Each stage used credentials/information from the previous stage to build trust. The pattern is: Stage N extracts data → Stage N+1 uses that data as proof of legitimacy.
  • Post-attack (on-chain): Funds moved from theft addresses to 15+ centralized exchanges within hours. The laundering used rapid cross-asset swaps (BTC→LTC→ETH) with Monero as the final hop. Each principal received a distinct share traceable on-chain.
  • Forensic (screen-share recording): A private video recording showed the threat actors' live reaction to receiving $238M — phone notifications, celebration, discussion of laundering. This recording was key forensic evidence for attribution.

What this example tells contributors writing future Technique pages

  • Multi-stage impersonation chaining is the T4.007++ pattern. The attackers used NOT a single impersonation but a chain: Google Support → Gemini Support. Each stage provides credentials that authenticate the next stage. Detection engineers should model these as a state machine: {stage_N_extracted_fields} ⊢ {stage_N+1_impersonation_target}.
  • High-net-worth targeting is a structural feature, not an edge case. The victim was a Genesis creditor — the attackers knew or inferred the target had large crypto holdings before the attack. T4 technique descriptions should explicitly cover "pre-attack target selection via public financial information" as part of the kill chain.
  • Laundering speed is a detection signal. The funds moved from theft to 15+ exchanges within hours. Normal institutional transfers do not exhibit this velocity + exchange fan-out pattern. The laundering tempo is itself a detection signal for social engineering thefts.
  • Screen-share/recording artifacts are a forensic goldmine. Threat actors recording their own reactions created the attribution evidence. Contributors writing T4 examples should note that social engineering attackers often record themselves (for clout, for associates), creating forensic artifacts beyond on-chain data.

Public references

  • ZachXBT — Investigation Thread (X/Twitter) — 14-part investigation with on-chain tracing of all three principals.
  • DOJ / U.S. Attorney D.C. — "Indictment Charges Two in $230 Million Cryptocurrency Scam" — the charging document. Malone Lam (20, Miami / Los Angeles; also used "Anne Hathaway" and "$$$") and Jeandiel Serrano (21, Los Angeles; "VersaceGod", @Skidstar) charged with conspiracy to steal and launder over $230M from a victim in Washington, D.C. The charged figure ($230M+) and the market-price valuation at theft (~$243M) differ; both are correct for what they measure.
  • Wikipedia — Malone Lam — biographical detail: Malone Lam Yu Xuan, born 2004-07-19, Singaporean, raised in Choa Chu Kang, attended Unity Secondary School, dropped out as a teenager. Co-founded the "Social Engineering Enterprise" with roommates in Texas; the network reached ~14 members across several states, working from hacked databases, dark-web data and phishing mail. Arrested by the FBI in Miami on 2024-09-18 after an off-duty police officer tipped him off; he threw his phone into Biscayne Bay en route. Proceeds spent on ~33 luxury cars, jewellery, travel and nightclubs.
  • DOJ / U.S. Attorney D.C. — "Guilty Plea and Superseding Indictment Announced in Social Engineering Scheme that Stole $263 Million in Cryptocurrency" (2025-12-08) — the case's recasting as a RICO racketeering conspiracy. Evan Tangeman (Newport Beach, CA) pleads guilty, admitting he laundered ≥$3.5M for the enterprise (sentencing 2026-04-24). The Second Superseding Indictment charges Nicholas Dellecave ("Nic", "Souja"; arrested Miami 2025-12-03), Mustafa Ibrahim ("Krust"; arrested Dubai) and Danish Zulfiqar ("Danny", "Meech"; arrested Dubai), bringing the total charged to twelve, with nine guilty pleas entered. Quantifies the theft as over 4,100 BTC, worth $263M in August 2024 and >$368M as of the announcement. Also references "residential burglars targeting hardware virtual currency wallets" as a component of the enterprise — the physical-coercion adjacency that connects this case to OAK-T5.009. (Mirrored by IRS Criminal Investigation at https://www.irs.gov/compliance/criminal-investigation/guilty-plea-and-superseding-indictment-announced-in-social-engineering-scheme-that-stole-263-million-in-cryptocurrency, which is fetchable where justice.gov returns 403.)
  • The Block — Chetal bond revocation — Veer Chetal ("Wiz") was a teenager at the time of the theft; secretly charged 2024-11; pleaded guilty; forfeited ~30 designer watches, clothing, and $36M+ in ETH. Lost bond after committing a further ~$2M crypto theft while awaiting sentencing.
  • Theft BTC transaction: 4b277ba298830ea538086114803b9487558bb093b5083e383e94db687fbe9090
  • Laundering addresses: documented in ZachXBT thread (15+ exchange deposit addresses, eXch, THORSwap).

Discussion

The Genesis Creditor case is structurally important to OAK because it demonstrates the upper bound of social engineering sophistication: multi-stage impersonation chains against institutional targets. The attack surface is not a smart contract — it's the human authentication layer between a custodian and their exchange/wallet provider. T4.007 (Native App Social Phishing) covers the impersonation vector, but the multi-stage chaining pattern is not yet explicitly modelled in OAK's T4 sub-technique hierarchy.

The attribution chain in this case is worth cataloguing: on-chain tracing + leaked screen recordings + private database phone number search → identification of all three principals. Contributors writing actor profiles (actors/) should use this case as the canonical example of how on-chain evidence combines with OSINT forensic artifacts to produce attribution even when the attackers use mixers and cross-chain swaps.

Techniques demonstrated (2)