Worked example · 2024-08
Genesis Creditor — Multi-Stage Impersonation Social Engineering — 2024-08-19
Summary
On August 19, 2024, three threat actors executed a highly sophisticated social engineering attack against a single Genesis Global Capital creditor, stealing approximately $243M in cryptocurrency. The attackers:
- Called the victim spoofing Google Support, compromising personal accounts (email, cloud storage) to extract sensitive financial information
- Called again spoofing Gemini Support, using the compromised information to gain trust; per the DOJ record the victim was induced to reset two-factor authentication and transfer funds to a wallet the attackers controlled
- Drained the victim's crypto assets to attacker-controlled addresses
- Split the proceeds three ways, laundering through 15+ exchanges with rapid cross-asset swaps (BTC → LTC → ETH → XMR)
ZachXBT traced the full on-chain flow and identified the three principals through a combination of on-chain analysis, leaked screen-share recordings, and private database searches. The private video recording showing the threat actors' live reaction to receiving $238M became key evidence. Malone Lam was arrested by FBI in Miami in September 2024; the other two remain at large.
Timeline (UTC)
| When | Event | OAK ref |
|---|---|---|
| Pre-Aug 2024 | Attackers research target: a Genesis creditor with large crypto holdings | (preparation) |
| 2024-08-19 ~T+0h | Call #1: Spoof Google Support number → compromise personal email/cloud accounts → extract financial account information | T4.007 impersonation stage 1 |
| 2024-08-19 ~T+1h | Call #2: Spoof Gemini Support → use compromised info to gain trust → obtain wallet credentials | T4.007 impersonation stage 2 |
| 2024-08-19 ~T+2h | $243M drained from victim wallets to attacker-controlled addresses. 4,064 BTC ($238M) transferred in single tx | T4.007 drain |
| 2024-08-19~Sep | Laundering: funds split three ways, swapped BTC→LTC→ETH→XMR via 15+ exchanges, eXch, THORSwap | T7 laundering |
| 2024-09 | Malone Lam (Greavys) arrested in Miami by FBI. Wiz (Veer Chetal) and Box (Jeandiel Serrano) remain at large | (legal action) |
| 2024-09-19 | ZachXBT publishes full investigation with on-chain tracing of all three principals | (public disclosure) |
| 2024-11 | Veer Chetal ("Wiz") secretly charged; later pleads guilty and forfeits ~30 designer watches, clothing, and $36M+ in ETH; loses bond after a further ~$2M crypto theft while awaiting sentencing | (legal action) |
| 2025-12-03 | Nicholas Dellecave ("Nic", "Souja") arrested in Miami | (legal action) |
| 2025-12-08 | DOJ announces a Second Superseding Indictment charging Dellecave, Mustafa Ibrahim ("Krust", arrested Dubai) and Danish Zulfiqar ("Danny", "Meech", arrested Dubai) with RICO conspiracy, bringing the total charged to twelve, of whom nine have pleaded guilty. Same announcement: Evan Tangeman pleads guilty to RICO conspiracy, admitting he laundered ≥$3.5M for the enterprise (sentencing 2026-04-24). DOJ states the theft totalled over 4,100 BTC, worth $263M in August 2024 and >$368M by the announcement date | (legal action) |
What defenders observed
- Pre-attack (targeting phase): The attackers accessed personal information (name, email, phone, associated financial accounts) enabling convincing impersonation. The victim was a known creditor in the Genesis bankruptcy — this information asymmetry was the initial foothold.
- During attack (impersonation chain): Two spoofed calls in sequence — Google then Gemini. Each stage used credentials/information from the previous stage to build trust. The pattern is: Stage N extracts data → Stage N+1 uses that data as proof of legitimacy.
- Post-attack (on-chain): Funds moved from theft addresses to 15+ centralized exchanges within hours. The laundering used rapid cross-asset swaps (BTC→LTC→ETH) with Monero as the final hop. Each principal received a distinct share traceable on-chain.
- Forensic (screen-share recording): A private video recording showed the threat actors' live reaction to receiving $238M — phone notifications, celebration, discussion of laundering. This recording was key forensic evidence for attribution.
What this example tells contributors writing future Technique pages
- Multi-stage impersonation chaining is the T4.007++ pattern. The attackers used NOT a single impersonation but a chain: Google Support → Gemini Support. Each stage provides credentials that authenticate the next stage. Detection engineers should model these as a state machine:
{stage_N_extracted_fields} ⊢ {stage_N+1_impersonation_target}. - High-net-worth targeting is a structural feature, not an edge case. The victim was a Genesis creditor — the attackers knew or inferred the target had large crypto holdings before the attack. T4 technique descriptions should explicitly cover "pre-attack target selection via public financial information" as part of the kill chain.
- Laundering speed is a detection signal. The funds moved from theft to 15+ exchanges within hours. Normal institutional transfers do not exhibit this velocity + exchange fan-out pattern. The laundering tempo is itself a detection signal for social engineering thefts.
- Screen-share/recording artifacts are a forensic goldmine. Threat actors recording their own reactions created the attribution evidence. Contributors writing T4 examples should note that social engineering attackers often record themselves (for clout, for associates), creating forensic artifacts beyond on-chain data.
Public references
- ZachXBT — Investigation Thread (X/Twitter) — 14-part investigation with on-chain tracing of all three principals.
- DOJ / U.S. Attorney D.C. — "Indictment Charges Two in $230 Million Cryptocurrency Scam" — the charging document. Malone Lam (20, Miami / Los Angeles; also used "Anne Hathaway" and "$$$") and Jeandiel Serrano (21, Los Angeles; "VersaceGod", @Skidstar) charged with conspiracy to steal and launder over $230M from a victim in Washington, D.C. The charged figure ($230M+) and the market-price valuation at theft (~$243M) differ; both are correct for what they measure.
- Wikipedia — Malone Lam — biographical detail: Malone Lam Yu Xuan, born 2004-07-19, Singaporean, raised in Choa Chu Kang, attended Unity Secondary School, dropped out as a teenager. Co-founded the "Social Engineering Enterprise" with roommates in Texas; the network reached ~14 members across several states, working from hacked databases, dark-web data and phishing mail. Arrested by the FBI in Miami on 2024-09-18 after an off-duty police officer tipped him off; he threw his phone into Biscayne Bay en route. Proceeds spent on ~33 luxury cars, jewellery, travel and nightclubs.
- DOJ / U.S. Attorney D.C. — "Guilty Plea and Superseding Indictment Announced in Social Engineering Scheme that Stole $263 Million in Cryptocurrency" (2025-12-08) — the case's recasting as a RICO racketeering conspiracy. Evan Tangeman (Newport Beach, CA) pleads guilty, admitting he laundered ≥$3.5M for the enterprise (sentencing 2026-04-24). The Second Superseding Indictment charges Nicholas Dellecave ("Nic", "Souja"; arrested Miami 2025-12-03), Mustafa Ibrahim ("Krust"; arrested Dubai) and Danish Zulfiqar ("Danny", "Meech"; arrested Dubai), bringing the total charged to twelve, with nine guilty pleas entered. Quantifies the theft as over 4,100 BTC, worth $263M in August 2024 and >$368M as of the announcement. Also references "residential burglars targeting hardware virtual currency wallets" as a component of the enterprise — the physical-coercion adjacency that connects this case to OAK-T5.009. (Mirrored by IRS Criminal Investigation at https://www.irs.gov/compliance/criminal-investigation/guilty-plea-and-superseding-indictment-announced-in-social-engineering-scheme-that-stole-263-million-in-cryptocurrency, which is fetchable where justice.gov returns 403.)
- The Block — Chetal bond revocation — Veer Chetal ("Wiz") was a teenager at the time of the theft; secretly charged 2024-11; pleaded guilty; forfeited ~30 designer watches, clothing, and $36M+ in ETH. Lost bond after committing a further ~$2M crypto theft while awaiting sentencing.
- Theft BTC transaction:
4b277ba298830ea538086114803b9487558bb093b5083e383e94db687fbe9090 - Laundering addresses: documented in ZachXBT thread (15+ exchange deposit addresses, eXch, THORSwap).
Discussion
The Genesis Creditor case is structurally important to OAK because it demonstrates the upper bound of social engineering sophistication: multi-stage impersonation chains against institutional targets. The attack surface is not a smart contract — it's the human authentication layer between a custodian and their exchange/wallet provider. T4.007 (Native App Social Phishing) covers the impersonation vector, but the multi-stage chaining pattern is not yet explicitly modelled in OAK's T4 sub-technique hierarchy.
The attribution chain in this case is worth cataloguing: on-chain tracing + leaked screen recordings + private database phone number search → identification of all three principals. Contributors writing actor profiles (actors/) should use this case as the canonical example of how on-chain evidence combines with OSINT forensic artifacts to produce attribution even when the attackers use mixers and cross-chain swaps.