Twelve new individuals charged by US authorities for their involvement in a crypto fraudthat is alleged to have stolen and laundered more than $230 million. The case, which falls under the federal RICO organized crime statute, reveals a complex digital fraudbased on social engineering, fake identities and abuse of remote access services.

Authorities had already arrested two young key suspects, Malone Lam and Jeandiel Serrano, in September 2024. Both were active online under aliases such as “Greavys,” “VersaceGod,” and “@SkidStar,” which they used on darknets and hacker communities.
According to the federal investigation, the group gained access to victims’ cryptocurrency accounts and transferred their funds to wallets under their control. In a single incident, in August 2023, the perpetrators managed to steal more than 4,100 Bitcoins – worth about $230 million at the time.
See also: Germany shuts down crypto exchange service eXch
A key figure in the case was an independent blockchain researcher known as ZachXBT, who provided valuable information to the FBI. He revealed that the scammers were posing as technical support for Google and Gemini. They set up a convincing phishing scenario, asking the victim to disable two-factor authentication (2FA) and share his screen via the remote access AnyDesk. In doing so, they gained access to his Bitcoin Core and emptied his digital vault.
The case highlights how vulnerable even the most experienced users remain to sophisticated social engineering tactics – and reminds us that security in cryptocurrencies is never a given.
Laundering millions with crypto mixers
The revelation of the high-profile cybercrime case linked to the theft of over $230 million in crypto continues to shock, as details about the path of the stolen funds. According to ZachXBT, approximately $243 million was quickly funneled through a labyrinthine system of exchanges, where the assets were converted into Bitcoin, Litecoin, Ethereum, and Monero to hide their original origins.
See also: Celsius founder Alex Mashinsky convicted of crypto fraud
The defendants, who now face charges not only of conspiracy and money laundering, but also of obstruction of justice and bank fraud, are alleged to have orchestrated a well-organized scheme:
- Marlon Ferro, 19 (Santa Ana, California)
- Hamza Doost, 21 (Hayward, California)
- Conor Flansburg, 21 (Newport Beach, California)
- Kunal Mehta, 45 (Irvine, California)
- Ethan Yarally, 18 (Richmond Hill, New York)
- Cody Demirtas, 19 (Stuart, Florida)
- Aakash Anand, 22 (New Zealand)
- Evan Tangeman, 21 (Newport Beach, California)
- Joel Cortes, 21 (Laguna Niguel, California)
- Unknown name aka “Chen” and “Squiggly” (unknown location)
- Unknown name aka “Danny” and “Meech” (unknown location)
- John Tucker Desmond, 19 (Huntington Beach, California)

Although most of the crypto assets were converted to Monero — one of the most popular cryptocurrencies for anonymous transactions — the perpetrators appear to have made some critical mistakes. Some fund movements revealed connections to the victims’ original wallets, leading authorities on their trail.
The fraudsters reportedly laundered the stolen crypto using crypto mixers and exchanges, pass-through wallets, “peel chains,” and virtual private networks (VPNs) to hide their identities and locations.
See also: Hackers use New York Post's X account for crypto fraud
Spending the money was equally provocative. The stolen assets were quickly channeled into purchases of luxury cars, expensive watches and accessories, as well as international travel and high-society parties.
The case highlights the dark side of the decentralized economy, highlighting the dangers lurking behind the anonymity offered by privacy coins and crypto mixing tools. Despite attempts at cover-up, blockchain’s transparency — when combined with technical expertise — remains a powerful weapon in the hands of researchers.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: www.bleepingcomputer.com
