Malone Lam Set to Plead Guilty in $263M Bitcoin RICO Case

Malone Lam, the Singaporean accused of organizing one of the largest single-victim cryptocurrency thefts prosecuted in the United States, is scheduled to enter a guilty plea in Washington federal court on September 8. Lam and other members of the group fraudulently obtained more than 4,100 BTC from a Washington, D.C. investor on August 18, 2024. Federal prosecutors later valued the Bitcoin at approximately $263 million at the time of the theft. The 22-year-old, known online through aliases including “King Greavys,”…

KuCoin Faces Community Alert Over $250K Atomic Stealer Laundering Claim

A community alert accused KuCoin of sending legal threats by email to a victim whose stolen funds were allegedly laundered through KuCoin accounts opened with purchased mule KYC. The case involves an alleged $250,000 Atomic stealer theft. The alert identified the theft address as 0x6368D06895b7becdcAC0806F438EfA653fE0a68D and listed five KuCoin deposit addresses that allegedly received the stolen funds after the drain. The named deposit addresses were 0x6043b2d79670a417fc523213155812846e893dc7, 0xa0fdb49aa589538d5622b92e9122727873558a13, 0x4a4b5c7db9aa8355a5e5abbfc1926cd6b2d9f610, 0xe7bb69f6c0ae0c1418bd86ec9697af9914d6875e and 0x35d65ec360347f7dc41a929cc7ce9f2485a4f833. The allegation is not that KuCoin itself stole the…

Polymarket Users Hit By Suspected $2.94M pUSD Phishing Drain

A suspected phishing attack targeting Polymarket users has drained an estimated $2.94 million from at least 11 victim wallets holding pUSD. The stolen assets were swapped into ETH and consolidated through the address 0xe65b1C586757c5510B60F998Eebb14C1eF71E1eD. The incident has not been confirmed as a Polymarket protocol exploit. The available onchain trail points to a user-side phishing or wallet-drainer campaign, where victims appear to have lost funds after interacting with malicious links, signatures or approvals tied to pUSD balances. Other theft addresses identified…

Polish Cyber Police Arrest Four In SIM-Swap Crypto Theft Case

Poland’s Central Bureau for Combating Cybercrime detained four suspected members of an organized criminal group accused of cyberattacks, cryptocurrency theft and money laundering. FBI and Homeland Security Investigations agents supported the operation, while the Regional Prosecutor’s Office in Krakow is supervising the case. The suspects allegedly targeted IT systems used by companies cooperating with telecommunications operators, along with employee email accounts. The group is accused of using specialized software and social engineering to gain unauthorized access to infrastructure that could…

Jailbroken Gemini Used In AI-Assisted Crypto Theft Campaign

A Russian-speaking threat actor tracked as “bandcampro” used a jailbroken Gemini setup to support a long-running AI-assisted “Patriot Bait” campaign involving Telegram influence activity, credential theft and crypto fraud. The campaign centered on the Telegram channel @americanpatriotus, which grew to roughly 17,000 subscribers while posing as an American military veteran persona. The channel mixed MAGA and QAnon-style messaging with crypto promotion, using political identity as the trust layer before pushing users toward fraud-linked assets, fake tools and wallet-compromise paths. The…

Kraken And Coinbase User Loses $6.7M After Apparent Physical Attack

A Kraken and Coinbase user lost about $6.7 million in crypto after an apparent physical attack led to withdrawals from both exchange accounts. The stolen assets included 1,554 ETH and 10.5 BTC from Kraken, along with 34.1 cbBTC from Coinbase. At current market prices, the ETH was worth about $3.3 million, the BTC was worth about $812,000, and the cbBTC was worth roughly $2.6 million. The theft address on Ethereum was 0xd3191Cba17504BDf7172ba9859aC854e3A79982A. The Bitcoin address tied to the case was…

ZachXBT Identifies 18-Year-Old In Alleged $19M Crypto Theft Trail

On-chain investigator ZachXBT has identified 18-year-old Dritan Kapllani Jr. as a U.S.-based threat actor allegedly tied to nearly $19 million in crypto thefts targeting digital-asset holders through social engineering. The ZachXBT thread centers on a March 14 theft of 185 BTC, worth about $13 million at the time, from a single victim. ZachXBT traced part of the stolen funds to an Exodus wallet allegedly controlled by Kapllani, which received about $5.3 million the next day. He also linked a second…

Malicious AI Routers Expose New Crypto Theft Risk For Developer Agents

Malicious AI API routers are emerging as a new crypto-theft risk as developers increasingly connect autonomous agents, coding assistants and blockchain tools through third-party model-routing infrastructure. A 428-router test found active abuse inside the routing layer that sits between users and major LLM providers. The study covered 28 paid routers sourced from Taobao, Xianyu and Shopify-hosted storefronts, plus 400 free routers collected from public communities. Nine routers injected malicious code, 17 touched researcher-controlled AWS canary credentials, and one free router…

Sillytuna Attackers Move $10M+ as Laundering Steps Hit Mixers and Exchange-Routed Liquidity

Arkham Intelligence tracking the Sillytuna attackers suggests the group has shifted from staging to active laundering, with more than $10 million in stolen assets moved across addresses and venues in short order. The update highlights three notable pathways. Roughly $1.08 million in Bitcoin was flagged as entering a mixing service. Mixing tools attempt to sever the visible link between inputs and outputs, making it harder to map the next hop even when the initial theft is well-attributed. For investigators, the…