₹2,050 Crore Crypto Case Shows Why Your Personal Data May Be More Valuable Than Your Password

The420.in Staff
5 Min Read

A cryptocurrency theft involving around ₹2,050 crore from a single Washington, D.C. victim has exposed a sophisticated cybercrime model in which personal data was allegedly used to identify wealthy crypto holders before they were targeted through social engineering.

Instead of directly breaking the security of Bitcoin or another cryptocurrency, members of the alleged network gathered information about potential victims, their contacts and digital assets, then used that intelligence to make fraudulent approaches more convincing.

How Were Wealthy Crypto Holders Targeted?

On September 8, 2026, 22-year-old Singaporean national Malone Lam pleaded guilty to a racketeering conspiracy charge in the United States.

Prosecutors said the international cybercrime network in which Lam played a leading role operated from October 2023 until at least May 2025.

The group allegedly hacked databases containing information about cryptocurrency holders or purchased stolen records and analysed the information to identify people believed to hold large amounts of digital assets.

Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise

How Did the Alleged Cybercrime Network Operate?

Investigators said different members of the group performed specialised roles.

Some allegedly hacked websites and servers to obtain cryptocurrency-related information, while others acquired stolen databases through underground markets.

Separate members analysed those records to identify high-value targets.

Once potential victims were selected, other participants allegedly contacted them and used social engineering to persuade them into transferring cryptocurrency.

Around 40 Databases Allegedly Offered for Target Profiling

According to prosecutors, Lam offered co-defendant Conor Flansburg access to around 40 organised databases containing stolen information.

The data could allegedly be used to create detailed profiles of potential victims and make impersonation attempts more credible.

The network also allegedly had a predetermined system for sharing proceeds from successful thefts, including major cryptocurrency thefts.

The structure indicates that stolen information itself had become a key resource in identifying and approaching high-value targets.

Why Was the ₹2,050 Crore Theft Different?

One of the most significant aspects of the case is that the attackers allegedly did not need to defeat Bitcoin’s underlying cryptographic security.

Instead, their advantage came from knowing who held valuable cryptocurrency, how to contact the person and what information could be used to gain the victim’s confidence.

In August 2024, a Washington, D.C. resident allegedly lost cryptocurrency valued at around ₹2,050 crore after members of the network used social engineering to obtain control of the assets.

The case demonstrates how information surrounding a crypto owner can become as important to criminals as access to the cryptocurrency itself.

Separate Team Allegedly Laundered the Stolen Crypto

The alleged operation did not end once cryptocurrency was stolen.

A separate group allegedly handled the proceeds, converting cryptocurrency into cash, bank transfers and goods.

This created another layer between the original theft and those benefiting from the proceeds.

The alleged structure resembled a specialised operation, with separate participants responsible for gathering data, identifying targets, contacting victims and laundering stolen assets.

Personal Data Becomes a New Crypto Security Risk

Other incidents involving stolen customer information from the cryptocurrency industry have highlighted a similar risk.

Even when passwords or private keys are not compromised, information such as a customer’s identity, contact details, transaction history and account balance can potentially help criminals make impersonation attempts much more believable.

For wealthy cryptocurrency holders, this means protecting a hardware wallet or private key may not be enough if criminals already possess detailed information about the person behind it.

Why This Matters for Crypto Investors

The warning for investors is simple: criminals may target the person rather than the cryptocurrency.

If fraudsters know how much crypto someone owns, their phone number, address, account activity or other personal details, they may use that information to pose as a trusted company or official and convince the victim to move funds voluntarily.

Unexpected calls or messages asking a crypto holder to transfer assets, secure a wallet or move funds because of an alleged security problem should therefore be independently verified before any transaction is made.

A federal court in Washington, D.C. is scheduled to hold the next status hearing in Lam’s case on December 8, 2026, when a sentencing date is expected to be set.

The case highlights an emerging challenge in cryptocurrency crime: sometimes the weakest link is not the blockchain or wallet technology, but the personal information surrounding the person who owns the assets.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected