GLOBAL FRAUD SCOREBOARD
THE GLOBAL FRAUD SCOREBOARD
Documented cases from court filings, regulatory actions, and public reporting. Ranked by scale — and we always state what is being measured. Fabricated account value is not the same as customer funds. Market collapse is not the same as direct theft.
PROFILES — 28 PEOPLE
Ramon Abbas
BEC fraud architect whose Instagram lifestyle became the prosecution's exhibit list. Dubai arrest June 2020, Operation Fox Hunt 2.
Malone Lam Yu Xuan
Largest known single-victim crypto heist in history. First Bitcoin RICO case. Social engineering, one phone call, $230M drained. 31 luxury cars in 30 days.
Kwon Do-hyung
$40B market value destroyed in Terra-LUNA collapse. Two depegs: May 2021 (hidden) and May 2022 (terminal). "You chose to lie. You chose poorly." — Judge Engelmayer
Bernard Lawrence Madoff
Largest Ponzi scheme in history. 48 years. $64.8B in fabricated statements. Warned to the SEC eight years before collapse. Duration was the disguise.
Samuel Benjamin Bankman-Fried
The trust of the smart. Misappropriated $8B in FTX customer funds. MIT, Jane Street, effective altruism, beanbag, cargo shorts — trusted by everyone who was most careful about trust.
Caroline Ellison
Ran the fund that received the stolen money. Cooperated before she was charged. Testified 3 days against . He leaked her diary to try to stop her. She testified anyway. 14 months served. Released January 2026.
Olalekan Jacob Ponle
Arrested alongside in Operation Fox Hunt 2, Dubai, June 2020. Extradited to the US.
Ghaleb Alaumary
Connected to North Korean / APT38 operations. Conspired with Abbas to launder funds from the Bank of Valletta (Malta) cyber heist, February 2019.
Abba Kyari
Alleged in US court documents as co-conspirator who received bribes from Abbas and used law enforcement authority to arrest individuals Abbas wanted targeted. Denied all charges. Case unresolved as of this writing. All claims are allegations.
Ross Ulbricht
Founded Silk Road in 2011. Arrested October 2013, SF public library. Sentenced to two life terms plus 40 years in 2015. Pardoned by President Trump on January 21, 2025 — a full and unconditional pardon, not a commutation.
Jordan Belfort
Pump-and-dump fraud via Stratton Oakmont. ~$200M in investor losses. Later became motivational speaker and fraud consultant. Subject of Martin Scorsese film (2013).
Frank William Abagnale Jr.
Claims disputed. 's widely reported autobiography has been substantially challenged by investigative biographer Alan Logan, who concluded most of the famous story was fabricated. Later worked as fraud consultant.
Alexander Mashinsky
Celsius Network froze withdrawals June 2022, filed bankruptcy July 2022. ~$4.7B in customer funds. Collapse partly driven by Terra-LUNA contagion. Pleaded guilty December 2024.
Ruja Ignatova
OneCoin was a fake cryptocurrency — no real blockchain. Co-founder disappeared in 2017. Estimated $4B+ raised from investors. On FBI's Most Wanted list. Warrant outstanding.
Elizabeth Anne Holmes
She built a company on a story. The Edison blood-testing device could not perform as claimed. Board of Kissinger, Shultz, Mattis. Stanford dropout. Black turtleneck. The Jobs comparison. Ninth Circuit affirmed conviction February 2025: "the promise was a mirage."
Ramesh “Sunny” Balwani
Tried separately from Holmes. His jury convicted him on all 12 counts including the patient-related fraud charges that Holmes was acquitted on. Managed laboratory operations and the customer-facing blood-testing business. Romantic relationship with Holmes during the fraud period.
Karl Sebastian Greenwood
Co-founded OneCoin with Ignatova. Personally misappropriated $300M+ on five-star resorts, villas, private jet, and a yacht. Arrested in Thailand 2018, 20 years sentenced 2023.
Konstantin Ignatov
Recruited by his sister from a forklift driving job in Germany. Ran the operation after she disappeared. Cooperated with prosecutors. “I have only myself to blame.”
Mark Scott
Laundered approximately $400M in OneCoin proceeds through a network of investment funds. The $400M is one piece of the money movement, not the total fraud scale.
Charles Ponzi
He named the crime. Not by inventing it — by running it so visibly that the newspapers found the words and the English language absorbed his name permanently. $2.50 in. $75 out. Every case in this series is a version of the structure he made famous.
Robert Allen Stanford
Legitimacy was the architecture. A real bank, a real knighthood, a real cricket stadium. $7.2B in CD fraud, 20,000 victims across 100 countries. SEC had examined and raised concerns before the collapse. He is still working on his case from Coleman II, scheduled release 2103.
James Davis
Stanford’s CFO and former Baylor University roommate. Pleaded guilty 2009 and cooperated with prosecutors, testifying about how the financial statements were fabricated and how investor money was redirected. The prosecution’s most significant inside witness.
Albert Gonzalez
The only person in this series who was inside the investigation while it was looking for him. He briefed Secret Service agents on how carding worked. He was the largest carder alive. Every briefing was an autobiography with the identifying details edited out.
Taek Jho Low
Alleged architect of 1MDB sovereign fund fraud. Has never been convicted. Maintains his innocence. Last seen Shanghai Disneyland, December 24, 2019.
Najib Abdul Razak
The 1MDB case’s documented conviction. Malaysia had never before convicted a sitting or former prime minister. 7 counts: documented fact, not allegation.
Riza Aziz
Co-founded Red Granite Pictures. Produced The Wolf of Wall Street. Red Granite settled a US DOJ forfeiture action for approximately $60M in 2017 without admitting wrongdoing. Charged separately in Malaysia.
Changpeng Zhao
Built the world’s largest crypto exchange without adequate AML controls. First person sentenced to prison for a single BSA violation. $4.3B company resolution. 4 months. Pardoned. The door was real. The controls were not.
James Zhong
Stole from the criminals. Held 51,680 BTC for 9 years without spending it. The blockchain found him anyway. He robbed the robbers. The state took the loot.
FRAUD CATEGORIES
FRAUD CATEGORIES
Seven documented fraud categories. Each has a distinct methodology, a distinct victim profile, and a distinct detection signature. Understanding the category is the first step to understanding the case.
METHODOLOGY
METHODOLOGY
TraceChain Fraud Intelligence publishes documented cases from court filings, regulatory actions, and verified public reporting. We do not publish accusations. We publish convictions, indictments, and sourced estimates -- and we tell you which is which.
EVIDENCE STANDARDS
WHAT WOULD PROVE US WRONG
Every figure we publish has a falsification condition. If a conviction is overturned, we update the record. If a loss estimate is revised by the source institution, we revise the entry. If you have court records that contradict a published figure, contact us. We review and correct within 48 hours.
WHAT THIS SITE IS NOT
TRACECHAIN FORENSICS
An AI-powered cryptocurrency and financial fraud investigation platform. The Fraud Intelligence publication is the public research arm -- documenting what the industry has confirmed so defenders understand what they are facing.
Russia is both a major source of cyber-enabled fraud aimed abroad and a heavy target of domestic phone and online scams. Russian-speaking groups have run banking-malware and card-theft operations such as Evil Corp's Dridex campaign, which US authorities say caused more than $100 million in losses (US Treasury/DOJ, 2019), and exchanges such as BTC-e and Garantex that US prosecutors say laundered criminal proceeds (DOJ, 2024–2025). At home, the Bank of Russia reported a record 27.5 billion rubles stolen through unauthorised bank transactions in 2024 and 29.3 billion rubles in 2025 (Bank of Russia, 2025–2026). Russia does not extradite its nationals, so most foreign cases end in indictments, sanctions or arrests abroad, and several convicted cybercriminals were returned to Russia in the 2024 and 2025 US–Russia prisoner exchanges (CBS News, 2025).
Ukraine hosts scam call centres that target victims across Europe with fake investment platforms and bank- or police-impersonation calls; the UN Office on Drugs and Crime estimated that up to 1,500 such call centres operated there as recently as 2024, many in and around Dnipro (bne IntelliNews citing UNODC, 2025). In October 2024, Czech, Latvian, Lithuanian and Ukrainian authorities, with Eurojust, hit a network running call centres in Dnipro, Ivano-Frankivsk and Kyiv, with estimated losses above EUR 10 million from more than 400 known victims (Eurojust, 2024). Ukraine's Cyber Police and Europol also arrested suspects in an investment scheme said to take more than EUR 200 million a year (Europol/Cyber Police, 2024). Several Ukrainian nationals have been convicted in the US for ransomware and banking-malware schemes.
Romanian criminal groups have been prominent in online auction fraud, card skimming and malware for over two decades, often operating abroad. The Bayrob group used fake eBay listings and malware to steal more than $4 million from US victims; two leaders were sentenced in the US in 2019 (DOJ, 2019). The Riviera Maya gang, allegedly led by Romanian national Florian Tudor, is accused of large-scale ATM skimming in Mexico (OCCRP, 2020). At home, the FNI investment-fund collapse of 2000 left a lasting mark, with businessman Sorin Ovidiu Vântu later jailed over it (Wikipedia summary of court rulings). Enforcement rests with DIICOT, the organised-crime and terrorism prosecutors' office, working closely with the FBI and Europol.
Public, independently verifiable data on fraud in Belarus is limited, and official statistics are not published in a form suitable for a sourced breakdown. The best-documented cases involve Belarusian nationals prosecuted abroad over crypto money laundering, such as Aliaksandr Klimenka, charged by US prosecutors in connection with the BTC-e exchange (DOJ, 2023). Western sanctions and the breakdown in law-enforcement cooperation since 2020 make cross-border fraud cases harder to pursue.
Moldova's defining fraud case is the 2014 'theft of the billion', in which about $1 billion vanished from three banks, equal to roughly an eighth of GDP at the time (Euronews, 2026). Ilan Shor was sentenced in absentia to 15 years in 2023 and remains a fugitive (AP, 2023), while former Democratic Party leader Vladimir Plahotniuc was extradited from Greece in September 2025 and sentenced to 19 years in April 2026; he says the case is political and is appealing (Euronews, 2026). Police also report a sharp rise in phone and online fraud, with online fraud damages growing from 73 million to over 211 million lei in one year (General Police Inspectorate, 2025).
Tbilisi became a base for investment-scam call centres that sell fake crypto and forex trading to victims in Europe and Canada. The 2025 'Scam Empire' investigation, based on 1.9TB of leaked data, found one Tbilisi operation had taken $35.3 million from more than 6,100 people between May 2022 and February 2025, and linked networks in Israel, Eastern Europe and Georgia to at least $275 million from 32,000 people (OCCRP, March 2025). Georgian prosecutors opened a criminal probe days after publication (OCCRP, 2025), and in December 2025 former State Security Service chief Grigol Liluashvili was detained on charges of taking bribes to protect call centres; he has not been tried (OCCRP, Dec 2025).
Kazakhstan faces high volumes of online fraud, especially fake online shops, phone scams and fraudulent investment schemes, including pyramid schemes promoted through messaging apps. A national Anti-Fraud Center run by the National Payment Corporation logged more than 90,000 fraud cases between its July 2024 launch and February 2026 (Astana Times, 2026). The country's largest fraud dispute is the BTA Bank case: the bank won English court claims worth over $6 billion against former chairman Mukhtar Ablyazov, who was also convicted in absentia in Kazakhstan and lives in France (RFE/RL, 2018; English High Court records). The Agency for Financial Monitoring leads investigations into pyramid schemes and money laundering.
Chinese-run criminal networks are central to the industrial scam compounds of Southeast Asia, especially in Myanmar, Cambodia and Laos, which run 'pig-butchering' investment and romance fraud against victims in China and worldwide. Beijing has cracked down hard: 2,876 Chinese suspects were repatriated from Myawaddy in early 2025, over 630 buildings at the KK Park compound were demolished, and all related suspects were reported returned by February 2026 (Ministry of Public Security, 2025–2026). In January 2026 a Wenzhou court executed 11 members of the Ming family syndicate from Myanmar's Kokang region after death sentences in September 2025 (CNN, 2026). Chinese investors are also frequent victims of domestic Ponzi schemes, such as the Lantian Gerui scheme whose proceeds turned up as 61,000 bitcoin in the UK (Metropolitan Police, 2025).
North Korea runs the world's largest state-directed crypto theft programme, using hacking groups tracked as and TraderTraitor and IT workers placed in foreign companies under false identities. Chainalysis estimates North Korea-linked hackers stole $2.02 billion in 2025, bringing their all-time total to about $6.75 billion (Chainalysis, Dec 2025). The FBI attributed the $1.5 billion Bybit theft of February 2025, the largest crypto heist on record, to North Korea (FBI, 2025), and with Japan's police attributed the $308 million DMM Bitcoin theft of 2024 (FBI/NPA, Dec 2024). Because North Korean operators are out of reach, enforcement relies on US indictments, sanctions, rewards and seizure of laundered funds.
Japan's fraud problem is dominated by 'special fraud' (tokushu sagi) phone scams against older people and by social-media investment and romance scams. The National Police Agency reported record combined losses of ¥324.11 billion (about $2.1 billion) in 2025, up from ¥199.1 billion in 2024 (NPA via Japan Times, Feb 2026). Special fraud losses almost doubled to ¥142.3 billion, with fake-police impersonation accounting for about 70% of them (NPA, 2026). Many calls are run from overseas; police cite fluid, anonymous groups ('tokuryu') that recruit through social media, and some cells operate from Southeast Asia. Japan was also the target of North Korea's $308 million DMM Bitcoin hack in 2024 (FBI/NPA, 2024).
Voice phishing is South Korea's most persistent fraud threat, much of it run by call centres in China and Southeast Asia that impersonate prosecutors, banks and lenders. The National Police Agency reported voice-phishing losses of over 1.1 trillion won in the first 11 months of 2025, up more than 56% (Korea Times, Jan 2026), while the Financial Supervisory Service, which counts only formal refund claims, recorded 433.8 billion won in 2025 (Seoul Economic Daily, March 2026). Korea has also produced some of the largest investment frauds in Asia, from the Optimus and Lime fund scandals to the $40 billion collapse of Terraform's TerraUSD and Luna.
Taiwan faces heavy losses to investment scams promoted through social-media ads and LINE groups, alongside phone and shopping fraud, while Taiwanese nationals have also been recruited into or run scam operations abroad. The National Police Agency's 165 Anti-Fraud Dashboard recorded NT$12.6 billion in losses in November 2024 alone (Taipei Times, Dec 2024); by November 2025 monthly losses had fallen to NT$5.99 billion, 57% below August 2024 (NPA via TWSE, 2025). Investment fraud accounts for the largest share of losses (TWSE citing NPA, 2025). In July 2024 Taiwan passed the Fraud Crime Hazard Prevention Act, requiring platforms, banks and telecoms to help block scams.
The Philippines has been both a base for scam hubs and a target of online fraud. Offshore gaming operators (POGOs) became linked to scam compounds and human trafficking, leading President Marcos to ban all POGOs in July 2024; PAGCOR said all 42 licences had been cancelled and 304 sites closed by 31 December 2024 (PAGCOR / PNA, 2025). Former Bamban mayor Alice Guo, linked to a raided scam hub, was convicted of qualified trafficking and sentenced to life in November 2025 (GMA News, 2025). Domestically, the Cybercrime Investigation and Coordinating Center received 10,004 online scam complaints in 2024, triple the previous year, with losses of nearly ₱198 million (CICC, 2025).
Australia publishes some of the world's most complete scam data through the National Anti-Scam Centre (NASC), which combines reports to Scamwatch, ReportCyber, banks (via AFCX), IDCARE and ASIC. Australians reported losing A$2.18 billion to scams in 2025, up 7.8% on 2024, across 481,523 reports (NASC, March 2026). Investment scams remain the costliest category at A$837.7 million, followed by payment redirection and romance scams (NASC, 2026). Much of the activity comes from offshore groups, including Southeast Asian scam compounds; the AFP has worked with foreign police to warn Australian targets. Major domestic fraud cases include the HIH Insurance collapse and the Plutus Payroll tax fraud.
New Zealanders are mainly targeted by offshore scammers through investment, romance and bank-impersonation scams. Scams and fraud became the most commonly reported incident category to the National Cyber Security Centre in late 2024, and reported direct financial losses to NCSC reached NZ$25.7 million for 2024 (NCSC, 2025). The country's largest home-grown frauds came from the finance-company and investment collapses after 2007, including Bridgecorp and Ross Asset Management, whose leaders were jailed. The Serious Fraud Office, Financial Markets Authority, Police and NCSC share enforcement.
Myanmar's lawless border zones, especially Myawaddy (Shwe Kokko, KK Park) in Karen State and the Kokang region of northern Shan State, host industrial scam compounds run largely by Chinese-led syndicates under the protection of local militias; the UN human rights office estimated in August 2023 that at least 120,000 people were being held there and forced to run online scams (OHCHR, 2023). The militias include the Karen National Army of Saw Chit Thu, which the US Treasury sanctioned in May 2025 for facilitating cyber scams (US Treasury, 2025). China has led enforcement: 16 members of the Kokang Ming family were sentenced to death in September 2025 and 11 were executed in January 2026, and Bai-family leaders were sentenced to death in November 2025 (CNN, 2025-2026). The junta raided KK Park in October 2025 and said it had demolished scam buildings, but reporting showed new construction nearby, suggesting the networks moved rather than shut down (AP, Dec 2025; Center for Information Resilience, 2025).
Cambodia became one of the world's largest bases for industrial-scale 'pig-butchering' investment and romance scams, run from casinos and compounds in Sihanoukville, Poipet, Bavet and O'Smach and staffed partly by trafficked workers; the UN estimated in 2023 that at least 100,000 people were held in Cambodian scam operations (OHCHR, 2023). In October 2025 US prosecutors indicted Prince Group founder Chen Zhi on wire-fraud and money-laundering conspiracy charges and sought forfeiture of 127,271 bitcoin (~$15bn), while Treasury sanctioned 146 related targets; Cambodia arrested Chen and sent him to China in January 2026 (US DOJ, 2025; CNN, 2026). The US Treasury has also sanctioned tycoon Ly Yong Phat (2024) and Senator Kok An (April 2026), saying Americans lost at least $10bn in 2024 to Southeast Asia-based scam operations (US Treasury, 2026). Cambodia launched a crackdown in July 2025, reporting nearly 30,000 suspects detained by August 2026, and passed its first dedicated anti-scam-centre law in April 2026, though job adverts suggest the industry persists (AP, 2026; Al Jazeera, 2026; ABC Australia, Sep 2026).
Laos' main fraud exposure is the Golden Triangle Special Economic Zone (GTSEZ) in Bokeo province, a casino enclave on a 99-year lease to Chinese businessman Zhao Wei, which hosts online scam centres staffed partly by trafficked workers (Crisis Group; Bloomberg, 2024). The US sanctioned Zhao Wei's network as a transnational criminal organisation in 2018 and the UK sanctioned him in 2023 over trafficking people into scam work (US Treasury, 2018; UK government, 2023). After a government ultimatum, Lao and Chinese police raided the zone in August 2024 and detained 771 people, but the Kings Romans casino kept operating and Zhao received a Lao state medal in December 2024 (RFA, 2024; The Diplomat, Dec 2024).
Thailand is both a major target of call-centre and investment scams, many run from compounds just across its borders in Myanmar and Cambodia, and a transit hub for trafficked scam workers (Kyoto Review, Mar 2026). Domestically, large investment frauds include the Forex-3D Ponzi scheme (about 2.5bn baht from ~9,800 investors) and the Stark Corporation accounting fraud (14.8bn baht, 4,704 victims) (Thai PBS, Dec 2024; Khaosod, Jun 2024). Thailand cut power to five Myanmar border scam zones in February 2025 and enacted an emergency decree in April 2025 making banks and telecom firms share liability for scam losses (CNN, Feb 2025; AGB, Apr 2025). The government said in June 2026 that a nine-month crackdown had arrested more than 29,000 suspects and seized or frozen over 24bn baht (Nation Thailand, Jun 2026).
Vietnam's biggest frauds have been corporate and banking scandals: property tycoon Truong My Lan was convicted in 2024 over the looting of Saigon Commercial Bank, and bond and stock-market frauds brought down the chairmen of Tan Hoang Minh and FLC (AP, 2024; VnExpress, 2024). Online fraud has grown fast, with estimated losses of VND18.9 trillion (~$744M) in 2024 (Viet Nam News, 2025), and police in 2025 broke up the 'Mr Pips' fake forex-trading network, which recruited staff in Cambodia (VietNamNet; Tuoi Tre, 2025). Vietnamese nationals also appear among workers trafficked to Cambodian and Myanmar scam compounds. Enforcement is led by the Ministry of Public Security; Vietnam abolished the death penalty for embezzlement in 2025, commuting Lan's sentence to life (CNN, Jun 2025).
Indonesia's largest fraud cases involve state insurers and cooperatives: the Jiwasraya case, in which businessmen Benny Tjokrosaputro and Heru Hidayat got life sentences for manipulating investments that cost the state Rp16.81 trillion, and the KSP Indosurya cooperative collapse (Jakarta Globe, 2020-2021; Kompas, 2023). Retail investors have also been hit by illegal binary-option platforms promoted by influencers such as Indra Kenz (Binomo) and Doni Salmanan (Quotex), both jailed (Media Indonesia; detik, 2022-2023). Scam reports have surged: the OJK-led Indonesia Anti-Scam Centre received 432,637 complaints with Rp9.1 trillion in reported losses between November 2024 and January 2026, led by online shopping fraud and impersonation calls (Infobanknews, 2026). The Satgas PASTI task force has shut thousands of illegal online lenders and investment offers.
Malaysia is linked to one of the largest financial scandals on record, 1MDB, in which US prosecutors say at least $4.5bn was stolen from the state fund; former prime minister Najib Razak was convicted in the main 1MDB trial in December 2025, while financier remains a fugitive (DOJ; CNN, Dec 2025). Online scam losses rose sharply to RM2.97bn in 2025 from RM1.57bn in 2024, with 66,204 cases, led by fake investment schemes (RM1.47bn) and phone impersonation scams (Royal Malaysia Police, Jun 2026). Malaysia is also a source and transit country for workers trafficked to regional scam compounds and a base for mule accounts. Enforcement is led by the police Commercial Crime Investigation Department, the National Scam Response Centre and the anti-corruption commission (MACC).
Singapore is a high-value target for scams and a regional financial hub that criminal networks use to launder money. Police recorded 37,308 scam cases and S$913.1M in losses in 2025, both down on 2024, but government-official impersonation scams more than doubled to 3,363 cases and S$242.9M (SPF, Feb 2026). In 2023 police seized about S$3bn in assets from a Fujian-linked network of ten foreign nationals, all later convicted of money laundering, and oil trader Hin Leong's founder Lim Oon Kuin was jailed in 2024 for cheating HSBC (Wikipedia; Malay Mail, 2024-2026). Enforcement relies on the police Anti-Scam Command, the 2025 Protection from Scams Act and close bank-police data sharing.
India faces fast-growing cyber fraud at home: the Home Ministry says Indians reported losses of Rs22,495 crore (~$2.6bn) to cyber fraud in 2025 from 2.8 million complaints, three-quarters of it to investment scams, with 'digital arrest' impersonation scams also rising (MHA via ThePrint, Feb 2026). Illegal call centres in India also run tech-support and government-impersonation scams against people in the US and elsewhere; the CBI's Operation Chakra has worked with the FBI against these networks, including a Noida ring accused of defrauding more than 600 Americans (Dec 2025). Large bank frauds remain a separate problem: Nirav Modi and Mehul Choksi are accused over the roughly Rs13,000-14,000 crore Punjab National Bank fraud and are fighting extradition from the UK and Belgium (AIR, 2025-2026). Enforcement runs through the Indian Cyber Crime Coordination Centre (I4C), the 1930 helpline, state cyber police, the CBI and the Enforcement Directorate.
Pakistan-based groups have supplied tools and labour to global online fraud: in May 2025 police arrested 21 people in Lahore and Multan linked to 'HeartSender', a phishing-kit and spam service tied to more than $50M in US losses, after the FBI and Dutch police seized its infrastructure (KrebsOnSecurity; Dawn, May 2025). Illegal call centres, some run with Chinese and other foreign nationals, have been raided repeatedly in Islamabad and Rawalpindi, including a 2026 raid in which 212 people were detained (Express Tribune, 2026). Enforcement is hampered by capacity: the FIA received over 73,000 cybercrime complaints in 2024 but registered only 1,604 cases (Business Recorder, citing FIA). Cyber-fraud policing moved in 2025 from the FIA to the new National Cyber Crime Investigation Agency, which itself faced a bribery scandal over protecting illegal call centres.
Bangladesh's major frauds have centred on banks and financial firms: former NBFI executive P K Halder is accused of siphoning roughly Tk10,000-11,000 crore from non-bank lenders and was sentenced in absentia in 2023, and the multi-level-marketing Destiny Group's leaders were convicted in money-laundering cases (Daily Star, 2022-2025). In 2016 hackers attributed by the US to North Korea's stole $101M from Bangladesh Bank's New York Fed account through fraudulent SWIFT orders; only part has been recovered (US DOJ, 2018; Wikipedia). The Anti-Corruption Commission (ACC), Bangladesh Financial Intelligence Unit and CID lead investigations, and many cases involve suspects abroad.
Sri Lanka's best-known fraud case is the 2015 Central Bank treasury bond scandal, in which a presidential commission found then-governor Arjuna Mahendran responsible for a loss of LKR11.1bn to public institutions through a bond auction that benefited Perpetual Treasuries, owned by his son-in-law; Mahendran stayed in Singapore and later rulings dismissed charges against him (Presidential Commission, 2017; Wikipedia). Sri Lankan bank accounts were also used as an exit route in the 2016 Bangladesh Bank heist, though the $20M sent to Sri Lanka was recovered. Public data breaking down scam losses by type is limited. The Central Bank bans pyramid schemes under the Banking Act and the CID investigates financial fraud.
Nepal's most prominent fraud problem is the embezzlement of savings in savings-and-credit cooperatives, which has drawn in senior politicians: Rastriya Swatantra Party chair Rabi Lamichhane was arrested in 2024-2025 over more than Rs109M allegedly moved from a Butwal cooperative to a media company he ran, and the case remains before the courts (Wikipedia, 2026). Weak oversight of cooperatives and money-laundering controls led the FATF to place Nepal under increased monitoring in February 2025. Investigations are led by the Nepal Police Central Investigation Bureau and Cyber Bureau and the Department of Money Laundering Investigation.
Nigeria-based networks are repeatedly named in US prosecutions for business email compromise (BEC) and associated money laundering, including the cases of Ramon '' Abbas (US DOJ, 2022) and Obinwanne Okeke (US DOJ, 2021). The country is also a target: banks and payment firms reported N52.26bn in fraud losses in 2024, falling to N25.85bn in 2025, with social engineering the leading technique (NIBSS, 2026). Foreign-run operations use Nigeria as a base too: in December 2024 the EFCC arrested 792 suspects, including 148 Chinese and 40 Filipino nationals, at a Lagos building allegedly running crypto-investment and romance scams aimed at victims abroad (EFCC, Dec 2024). The EFCC reported a record 4,111 convictions in 2024 (EFCC via Naija News, Mar 2025), and Nigeria took part in INTERPOL's Operation Red Card, where it made 130 arrests, 113 of them foreign nationals (INTERPOL, Mar 2025).
US prosecutors have charged Ghana-based defendants over romance scams and BEC. Three Ghanaian nationals were extradited to New York over an alleged criminal organisation that stole more than $100M (US DOJ SDNY), and in July 2026 the influencer Frederick Kumi ('Abu Trica') was extradited over an alleged $8M romance-fraud scheme against older Americans (US DOJ N.D. Ohio, 2026). At home, reported fraud cases at banks, specialised deposit-taking institutions (SDIs) and payment firms rose to 16,733 in 2024, with about GH¢99M at risk (Bank of Ghana, Apr 2025), and to 24,778 in 2025 (Bank of Ghana, 2026). The Cyber Security Authority says online fraud made up about 47% of the 3,876 cyber incidents its CERT-GH logged in January–July 2026 (CSA via MyJoyOnline, Sep 2026). The largest domestic investment case, the collapse of gold-trading firm Menzgold, is still on trial (GhanaWeb, 2025).
Côte d'Ivoire's police cybercrime platform (PLCC) handled 12,100 cases in 2024, up from 8,132 in 2023, with reported losses of about 6.96bn FCFA (PLCC/ANSSI via KOACI, May 2025). Internet fraud, known locally as 'broutage', caused the largest share of those losses (PLCC, 2025). Abidjan-based suspects have also targeted victims abroad. INTERPOL's Serengeti 2.0 operation broke up an inheritance scam that started in Germany and caused about $1.6M in losses (INTERPOL, Aug 2025), and a US indictment accuses an Ivorian national of phishing travel agencies out of about $14M (US DOJ E.D. Tex., Apr 2026). In Operation Red Card 2.0, Ivorian police arrested 58 people and seized 240 phones and more than 300 SIM cards in a crackdown on mobile-loan fraud (INTERPOL, Feb 2026).
Senegal's national police recorded 3,902 cybercrime complaints in 2024 and 3,794 cybercrime offences in 2025, with 257 people referred for prosecution in 2025 (Police nationale annual report, via Osiris, Mar 2026). During INTERPOL's Operation Serengeti (Sep–Oct 2024), Senegalese police and INTERPOL arrested eight people, five of them Chinese nationals, over an online Ponzi scheme worth about 3.7bn FCFA (Dakaractu, 2024). INTERPOL's 2024 Africa cyberthreat assessment names Senegalese finance, import-export and trading businesses among those exposed to BEC and romance scams (Pulse Senegal, 2026). Senegal also took part in INTERPOL Operation Red Card 2.0 (INTERPOL, Feb 2026).
The Better Business Bureau's 2017 study of online puppy scams traced many of them to Cameroon-based operators (BBB, Sep 2017). We did not find an official breakdown of fraud by type in this research pass. Cameroon is a party to the Budapest Convention on Cybercrime (Wikipedia, 2026), and online fraud is prosecuted under Law No. 2010/012 on cybersecurity and cybercrime. It took part in INTERPOL's Operation Red Card 2.0 (Dec 2025–Jan 2026), which targeted high-yield investment, mobile-money and fraudulent loan-app scams across 16 African countries (INTERPOL, Feb 2026).
Benin has taken part in INTERPOL's two Africa-wide operations against online fraud: Operation Red Card (Nov 2024–Feb 2025), which targeted cross-border scams, and Red Card 2.0 (Dec 2025–Jan 2026), which targeted investment, mobile-money and loan-app fraud (INTERPOL, 2025–2026). INTERPOL did not publish Benin-specific arrest figures for those operations. Benin is a party to the Budapest Convention on Cybercrime (Wikipedia, 2026). We did not find an official by-type fraud breakdown or a well-documented court case in this research pass.
South Africa has had some of the continent's largest corporate and investment frauds. They include the Steinhoff accounting fraud, where a PwC probe found over €6.5bn in fictitious or irregular income between 2009 and 2017 (Wikipedia/PwC), the looting of VBS Mutual Bank (about R1.89bn), and the Mirror Trading International crypto Ponzi scheme, where a US court ordered $1.7bn in restitution (Wikipedia, 2023). Retail fraud is rising fast. Banks reported 97,975 digital-banking fraud incidents in 2024, up 86%, with R1.888bn in gross losses, mostly through social engineering on banking apps (SABRIC, Aug 2025). Card-not-present fraud is the main card-fraud type (SABRIC, 2025). In INTERPOL's Operation Red Card, South African police made 40 arrests and seized more than 1,000 SIM cards (INTERPOL, Mar 2025).
Kenya's best-known historic fraud is the Goldenberg scandal (1990–1993): fictitious gold and diamond exports claimed inflated export compensation, costing the state the equivalent of more than 10% of GDP. The alleged architect, Kamlesh Pattni, was cleared by the High Court in 2013 (Wikipedia). More recent enforcement centres on online investment fraud. In INTERPOL's Operation Red Card 2.0, Kenyan police made 27 arrests linked to fraudulent investment schemes (INTERPOL, Feb 2026). Kenya is a party to the Budapest Convention on Cybercrime (Wikipedia, 2026). We did not find an official by-type fraud breakdown in this research pass.
We found little well-sourced, country-specific public data on fraud in Tanzania in this research pass. Tanzania was not among the countries listed in INTERPOL's 2025–2026 Red Card operations, and it is not a party to the Budapest Convention (Wikipedia, 2026). Online and mobile-money fraud is prosecuted under the Cybercrimes Act 2015. We did not find an official by-type breakdown or a well-documented court case.
Uganda took part in INTERPOL's Operation Red Card 2.0 (Dec 2025–Jan 2026), which targeted high-yield investment scams, mobile-money fraud and fraudulent loan apps in 16 African countries (INTERPOL, Feb 2026). INTERPOL did not publish Uganda-specific results. Uganda is not a party to the Budapest Convention (Wikipedia, 2026). Online fraud is prosecuted under the Computer Misuse Act 2011. We did not find an official by-type breakdown or a well-documented court case in this research pass.
The most widely reported recent fraud-related incident in Ethiopia was a system glitch at the state-owned Commercial Bank of Ethiopia on 15 March 2024. For several hours, customers could transfer or withdraw more money than they held, and the bank did not disclose the full loss (Wikipedia/AP, 2024). Ethiopia is not a party to the Budapest Convention (Wikipedia, 2026) and was not listed in INTERPOL's 2025–2026 Red Card operations. We did not find an official by-type breakdown or a well-documented fraud prosecution in this research pass.
Rwanda made 45 arrests, seized 292 devices and recovered $103,043 in INTERPOL's Operation Red Card (Nov 2024–Feb 2025), which targeted cross-border online scams (INTERPOL, Mar 2025). It also took part in Red Card 2.0 (Dec 2025–Jan 2026) (INTERPOL, Feb 2026). Rwanda is a party to the Budapest Convention on Cybercrime (Wikipedia, 2026). We did not find an official by-type breakdown or a well-documented court case in this research pass.
Zimbabwe took part in INTERPOL's Operation Red Card 2.0 (Dec 2025–Jan 2026), which targeted investment, mobile-money and loan-app fraud across 16 African countries (INTERPOL, Feb 2026). INTERPOL did not publish Zimbabwe-specific figures. Zimbabwe is not a party to the Budapest Convention (Wikipedia, 2026), and cyber-fraud falls under the Cyber and Data Protection Act 2021. We did not find an official by-type fraud breakdown or a well-documented fraud conviction in this research pass.
Angola's highest-profile fraud case concerns Isabel dos Santos, daughter of the former president. After the 2020 Luanda Leaks, Angola alleged she caused the state $1.14bn in losses through deals with Sonangol and Sodiam. INTERPOL circulated an arrest warrant in November 2022, a London court froze up to £580M of her assets in December 2023, and the UK sanctioned her in November 2024 (Wikipedia). In INTERPOL's Serengeti 2.0 operation, Angolan authorities shut 25 illegal crypto-mining centres run by 60 Chinese nationals and seized 45 illicit power stations and equipment worth more than $37M (INTERPOL, Aug 2025). Angola also took part in Red Card 2.0 (INTERPOL, Feb 2026). It is not a party to the Budapest Convention (Wikipedia, 2026).
Mozambique was the victim of the 'tuna bonds' or hidden-debt fraud. About $2bn of state-guaranteed loans to three state companies (Proindicus, Ematum and MAM), arranged by Credit Suisse and VTB between 2013 and 2016, were kept from parliament and the IMF, and at least $200M was diverted in bribes and kickbacks (Wikipedia, 'Tuna bonds'). Former finance minister Manuel Chang was convicted in New York in August 2024 and sentenced to 8.5 years in January 2025 (Wikipedia). Credit Suisse agreed in October 2021 to pay about $475M–$500M to US, UK and Swiss authorities and to forgive $200M of Mozambique's debt (Wikipedia). In 2024 London's High Court ordered shipbuilder Privinvest to pay Mozambique about $1.9bn in damages (Wikipedia).
Iran's best-documented fraud cases are huge insider bank and oil-revenue embezzlements, including the $2.6bn Bank Saderat forged-credit scandal, for which businessman Mahafarid Amir Khosravi was executed in 2014 (RFE/RL, 2014). Iranian-based cybercriminals have also run extortion schemes abroad: in 2018 US prosecutors charged two men in Iran over SamSam ransomware, which allegedly caused more than $30M in losses (US DOJ, 2018). Iran is on the FATF blacklist, and its crypto exchanges are now a focus of sanctions. In June 2026 OFAC sanctioned Nobitex and three other exchanges that together moved at least $40bn, citing sanctions evasion and payments linked to the IRGC and ransomware (Elliptic/Chainalysis, June 2026). Enforcement at home depends on the judiciary and the FATA cyber police, and has included death sentences for large-scale economic crimes.
Israel was the hub of the global binary-options and fake-forex boiler-room industry of the 2010s. Israeli-run call centres at home and in Bulgaria, Serbia, Cyprus and Ukraine took money from victims worldwide, and the Knesset banned binary options outright in October 2017 (Haaretz, 2017). US and European courts have since convicted the industry's leaders, including Yukom CEO Lee Elbaz (22 years, US, 2019) and Gal Barak (4 years, Vienna, 2020). In 2025 an OCCRP-led 'Scam Empire' investigation reported that call centres in Israel, Europe and Georgia took about $275M from would-be investors between 2021 and 2025 (OCCRP partners, 2025; allegations). Israeli nationals were also behind the CEO/'fake minister' impersonation fraud in France (Chikli, 2020).
The UAE, and Dubai in particular, is both a base and a refuge for international fraudsters and a laundering route for their proceeds. It was on the FATF grey list from March 2022 to February 2024 (FATF, 2024). Dubai Police's 2020 'Fox Hunt 2' operation arrested Nigerian BEC figures Ramon '' Abbas and Olalekan Ponle, both later convicted in the US. The UAE also extradited Sanjay Shah, Denmark's biggest tax fraudster, in 2023, although a Dubai court refused South Africa's request for the Gupta brothers. The UAE FIU estimated domestic fraud losses at AED 1.2bn (~$326M) for 2021–2023 and named vishing, phishing and smishing as the top types (UAE FIU, 2024). In April 2026 a Dubai Police–FBI operation shut nine scam centres and made 276 arrests, many of them trafficked workers (US DOJ, 2026).
Fraud reported in Saudi Arabia is mostly domestic. It includes phone and SMS fraud by callers posing as banks or government agencies, fake property deals, and large laundering rings using commercial fronts. In 2021 a court jailed 24 people, for up to 20 years each, for laundering SR17bn (~$4.5bn) through factories, clinics and companies (Arab News, 2021). In 2024 two expatriates got 15 years for a call-centre fraud that took SR22M in 177 operations (Saudi Gazette, 2024). In December 2025 an 11-member ring was jailed for a combined 155 years for fake property scams worth about SR40M (Gulf News, 2025). The Public Prosecution says reported fraud comes from misuse of victims' personal data, not system breaches (SPA, 2024). The 2017 Ritz-Carlton anti-corruption campaign recovered about $106bn in settlements but was widely criticised as extra-judicial.
Turkey has had some of the largest retail-investor collapses in the region. The Thodex crypto exchange shut in April 2021, locking about 400,000 users out of their funds; its founder got 11,196 years in 2023 and died in prison in 2025 (Decrypt, 2025; Turkish Minute, 2025). The Çiftlik Bank farm-game Ponzi led to 45,376-year sentences in February 2025 (The National, 2025). Turkish figures also appear in cross-border cases, including the Halkbank/Zarrab Iran sanctions-evasion scheme prosecuted in New York and the $133M Washakie biodiesel laundering case in Utah. The Interior Ministry and gendarmerie regularly raid illegal-betting and online-fraud networks moving billions of lira (Hürriyet Daily News, 2024). Turkey left the FATF grey list in June 2024.
Egypt keeps seeing Ponzi-style 'investment' schemes, from the 1980s Islamic investment companies to app-based crypto platforms. Ahmed al-Rayan's company drew more than 200,000 depositors before collapsing, and he was jailed in 1989 (Egyptian Streets, 2022). In 2023 police arrested 29 people, including 13 foreigners, behind the HoggPool cloud-mining app, which took about EGP 19M (Ministry of Interior / CBS, 2023). In 2025 police arrested 13 people over the FBC app, a referral Ponzi said to be led by foreign nationals, with loss estimates varying widely (Ahram Online, 2025). Grand corruption cases include the 2015–2016 'presidential palaces' embezzlement conviction of Hosni Mubarak and his sons.
Morocco-based groups are tied to two well-documented types of online fraud. The first is webcam sextortion aimed at foreigners, concentrated around the town of Oued Zem (Morocco World News, 2019). The second is corporate gift-card theft: Microsoft and the FBI say the Morocco-based group Storm-0539 ('Atlas Lion') has stolen up to $100,000 a day from some retailers (Microsoft, 2024). INTERPOL, Group-IB and Moroccan police arrested the phishing and carding-kit seller 'Dr Hex' in 2021 (Operation Lyrebird). Morocco also took part in the MENA-wide Operation Ramz, which led to 201 arrests across 13 countries (INTERPOL, 2026). Morocco left the FATF grey list in February 2023.
Iraq's largest documented frauds involve the theft of public money through the banking system. In the 2021–2022 'heist of the century', 247 cheques drained 3.7 trillion dinars (~$2.5bn) of tax deposits from the General Tax Authority's account at Rafidain Bank (The National, 2024). Businessman Nour Zuhair Jassim and senior officials were sentenced in absentia in November 2024. In 2023–2024 the US cut 14 and then 8 more Iraqi banks off from the central bank's dollar auction over money laundering and dollar smuggling to Iran. In 2024 FinCEN named Al-Huda Bank a primary money-laundering concern (FinCEN, 2024). FATF added Iraq to its grey list in June 2026.
The World Bank called Lebanon's pre-2019 financial model a 'Ponzi finance' scheme. The central bank attracted deposits with interest rates as high as 20%, and after the system collapsed in 2019 depositors lost around 80% of their savings' value, about $70bn (World Bank, 2022). Former central-bank governor Riad Salameh was charged in 2024 with embezzling at least $42M. He was released on a record bail in September 2025 and re-arrested in August 2026 in a new case (The National, 2025–2026), and he denies all allegations. Lebanon has also been a channel for drug-money laundering, notably through the Lebanese Canadian Bank network of Ayman Joumaa (US DOJ, 2011). FATF put Lebanon on its grey list in October 2024.
Jordan's biggest fraud cases involve tax and customs evasion and the embezzlement of state assets. In 2021 the State Security Court jailed tobacco magnate Awni Mutee and two others for 22 years each over a counterfeit-cigarette operation that cost the treasury about JD179M in unpaid taxes and duties (Jordan Times, 2021). In 2022 Walid al-Kurdi, a former Jordan Phosphate Mines chairman, was sentenced in absentia to 18 years and fined JD191M (Petra, 2022). Online, the Public Security Directorate's cybercrime unit warns about fake-prize and fake-trading-platform scams. During INTERPOL Operation Ramz, Jordanian police raided a fake trading platform staffed by 15 trafficked workers from Asia (INTERPOL, 2026). Jordan left the FATF grey list in October 2023.
Qatar's best-documented financial-crime cases are corruption and money-laundering cases involving senior officials. They are led by the January 2024 conviction of former finance minister Ali Sharif Al Emadi, who was jailed for 20 years for laundering more than $5.6bn and fined over QAR 61bn (Doha News, 2024). Qatari figures have also been named in foreign sports and political corruption probes. Swiss courts acquitted beIN/PSG chairman Nasser Al-Khelaifi three times in the FIFA TV-rights case. Belgian prosecutors' 2022 'Qatargate' investigation alleges that Qatar paid for influence at the European Parliament, which Qatar denies. At retail level, INTERPOL Operation Ramz found that Qatari devices had been compromised and used to spread malicious threats (INTERPOL, 2026).
Algeria's main fraud cases are the Khalifa Bank collapse of 2003, with losses estimated at up to $5bn, and a wave of post-2019 corruption trials of Bouteflika-era prime ministers, ministers and tycoons (Al Arabiya, 2022; Al Jazeera, 2019). The car-assembly scandal alone is said to have cost the treasury about $1bn. Algerian hacker Hamza Bendelladj was jailed for 15 years in the US in 2016 for his role in the SpyEye banking trojan. During INTERPOL Operation Ramz (2025–2026), Algerian authorities took down a phishing-as-a-service website (INTERPOL, 2026). Algeria was on the FATF grey list from October 2024 until June 2026.
The US is both the largest reported victim market and home to major domestic frauds. Consumers reported a record $15.9 billion in fraud losses to the FTC in 2025, up from $12.5 billion in 2024, with investment scams accounting for about $7.9 billion (FTC, 2026). The FBI's Internet Crime Complaint Center logged $20.9 billion in reported internet-crime losses for 2025 (FBI IC3 via AARP, 2026). Much of the investment and romance ('pig-butchering') fraud targeting Americans is run from scam compounds in Southeast Asia, while domestic cases range from Ponzi schemes to crypto-exchange collapses. Enforcement is led by the DOJ, FBI, SEC, FTC and CFTC, and federal courts have handed down some of the longest fraud sentences in the world.
Brazil has one of the world's highest volumes of recorded fraud: police registered about 2.2 million estelionato (fraud) cases in 2024, a 408% rise since 2018, including at least 281,200 electronic frauds (Fórum Brasileiro de Segurança Pública, Anuário 2025). Much of the growth is tied to Pix instant-payment scams, fake-bank-agent calls, WhatsApp impersonation and phishing. Brazil was also the centre of Operation Lava Jato, which exposed the Odebrecht bribery network across Latin America (US DOJ, 2016), and of large pyramid schemes such as TelexFree. Enforcement falls to the Federal Police, state civil police, the Central Bank (Pix security rules, the MED refund mechanism) and the CVM securities regulator.
Fraud in Mexico ranges from extortion calls and fake-kidnapping ('virtual kidnapping') scams to timeshare fraud aimed at US and Canadian owners, which the FBI and US Treasury have linked to the Jalisco New Generation Cartel (FBI, 2024; OFAC, 2024). Large-scale diversion of public funds has also led to prosecutions of former state governors, and federal auditors documented the 'Estafa Maestra' scheme that routed ministry money through universities and shell companies (ASF / Animal Político, 2017). Enforcement involves the Fiscalía General de la República, the Financial Intelligence Unit (UIF), the CONDUSEF consumer-finance agency and close cooperation with US prosecutors.
Colombia's fraud landscape includes pyramid schemes that drew in hundreds of thousands of savers in the 2000s (DMG, DRFE), 'carrusel' public-contract corruption in Bogotá, and extortion and phone scams run from prisons. Proceeds of drug trafficking are also laundered through trade-based schemes and front companies (FATF/GAFILAT, 2018). Enforcement falls to the Fiscalía General de la Nación, the Superintendencia Financiera and the UIAF financial-intelligence unit, with many cases extradited to the US.
Argentina's highest-profile fraud cases involve public works and the laundering of state money, above all the 'Vialidad' case in which former president Cristina Fernández de Kirchner was convicted of fraudulent administration of road contracts in Santa Cruz (federal court, Dec 2022; upheld by the Supreme Court, June 2025). High inflation has also fuelled crypto and 'high-yield' pyramid schemes such as Generación Zoe, as well as phishing and WhatsApp impersonation. Enforcement falls to the federal courts in Comodoro Py, the UIF financial-intelligence unit and the CNV securities regulator.
Peru was one of the countries hit hardest by the Odebrecht bribery network: the company admitted paying about $29 million in bribes there (US DOJ, 2016), and several former presidents have since been prosecuted. Alejandro Toledo was sentenced to 20 years and 6 months in October 2024 for taking Odebrecht bribes, and Ollanta Humala received 15 years for money laundering in April 2025 (Peruvian courts). Everyday fraud includes phone and SMS phishing, fake-loan apps and extortion. Enforcement relies on the special Lava Jato prosecution team, the SBS/UIF financial regulator and the anti-corruption courts.
Ecuador's major fraud and corruption cases concern bribes for public contracts, including the 'Sobornos 2012-2016' case in which former president Rafael Correa was convicted in absentia (National Court of Justice, 2020), and Odebrecht, which admitted paying about $33.5 million in bribes in the country (US DOJ, 2016). The dollarised economy and a surge in organised crime have also made Ecuador a laundering channel for drug proceeds (US State Dept INCSR). Enforcement falls to the Fiscalía General del Estado, the UAFE financial-intelligence unit and the Superintendencia de Bancos.
Paraguay's fraud and financial-crime risk centres on the Tri-Border Area (Ciudad del Este), long flagged for trade-based money laundering, cigarette smuggling and counterfeit goods (US State Dept INCSR). In 2022–2023 the US designated former president Horacio Cartes for 'significant corruption' and sanctioned him and his companies (US State Dept, July 2022; US Treasury OFAC, Jan 2023). The 2022 'A Ultranza Py' operation targeted a drug-trafficking and laundering network using front companies (Paraguayan Public Ministry, 2022). Enforcement relies on the Public Ministry, SEPRELAD (the financial-intelligence unit) and the Central Bank.
Venezuela's largest frauds involve the looting of state money through currency-exchange arbitrage and the national oil company PDVSA. US prosecutors describe schemes in which officials sold access to preferential exchange rates for bribes, and a network that laundered about $1.2 billion taken from PDVSA (US DOJ, 2018). In 2023–2024 Venezuelan authorities arrested former oil minister Tareck El Aissami over the 'PDVSA-Cripto' scandal involving diverted oil revenue. Much of the enforcement has come from US courts and OFAC sanctions rather than domestic prosecutors.
Jamaica is best known in fraud circles for advance-fee 'lottery scams' that phone older people in the US, claiming they have won a prize and must pay fees first; US authorities have prosecuted and extradited dozens of Jamaican participants (US DOJ, 2010s–2020s). Parliament passed the Law Reform (Fraudulent Transactions) (Special Provisions) Act in 2013 specifically to target these schemes. In 2023 the collapse of Stocks and Securities Ltd, after an employee allegedly diverted client funds including those of Usain Bolt, prompted regulatory reform (Financial Services Commission, 2023). Enforcement is led by the JCF's Major Organized Crime and Anti-Corruption Agency (MOCA) and the Financial Investigations Division.
Trinidad & Tobago's fraud profile is shaped by financial-sector failures and corruption cases, including the 2009 collapse of the CL Financial conglomerate that required one of the Caribbean's largest government bailouts. Former FIFA vice-president Jack Warner has been fighting US charges of wire fraud, racketeering and money laundering since 2015 (US DOJ, 2015). The country has been on and off the FATF 'grey list' and the EU list of high-risk jurisdictions over anti-money-laundering weaknesses. Enforcement falls to the Trinidad and Tobago Police Service Fraud Squad, the Financial Intelligence Unit (FIUTT) and the Office of the DPP.
Canadians reported a record $704 million in fraud losses to the Canadian Anti-Fraud Centre in 2025 from more than 112,000 reports, and investment fraud alone accounted for about half of that ($351 million) (CAFC, Feb 2026). The CAFC estimates only 5–10% of fraud is reported. Canada has also seen large domestic frauds, from the Norbourg fund scandal in Quebec to the collapse of crypto exchange QuadrigaCX (Ontario Securities Commission, 2020), and Canadian call centres have been used in 'grandparent' scams against US seniors (US DOJ, 2023). Enforcement involves the RCMP, provincial police, the CAFC and provincial securities regulators.
Fraud is the most common crime in England and Wales, and UK banks and card firms reported £1.28 billion stolen through payment fraud in 2025, up 4%, including a record £576.4 million lost to authorised push payment (APP) scams (UK Finance, June 2026). Investment scams were the single largest APP category at £221.5 million, while card-not-present fraud remained the biggest unauthorised category. London is also a global hub for laundering fraud proceeds through property and companies, shown by the 61,000-bitcoin seizure in the Qian Zhimin case (Metropolitan Police / CPS, 2025). Mandatory reimbursement of APP victims (up to £85,000) has applied since October 2024 under Payment Systems Regulator rules.
German police recorded 681,354 fraud offences committed inside the country in 2025 (down 8.4%), plus 549,385 fraud cases committed from abroad against German victims (up 7.0%), and the internet was used in 52.3% of fraud cases (BKA, PKS 2025). Germany was also the scene of two of Europe's largest white-collar scandals: the Wirecard collapse, in which €1.9 billion of reported cash did not exist (2020), and 'cum-ex' dividend-stripping trades that cost the treasury billions. Frauds against older people such as 'Enkeltrick' (grandchild) and fake-police calls are frequently run from call centres abroad. Enforcement involves the BKA, state police (LKA), BaFin and specialised prosecutors such as those in Cologne for cum-ex.
Payment fraud in France reached €1.241 billion in 2025 (up 3.8%), and credit transfers overtook cards as the main source of fraud by value (Banque de France, OSMP 2025 report, Sept 2026). 'Fraud by manipulation', such as fake bank-adviser calls, CEO fraud and IBAN substitution, reached €516 million, just over 40% of the total and double its share four years earlier. France is also the origin of the 'fake president' (CEO fraud) technique and of the EU carbon-credit VAT fraud of 2008–2009. Enforcement is led by the Parquet national financier, the OCRGDF police office and the Banque de France observatory.
Dutch payment fraud rose sharply in 2025: fraudulent transactions increased 30% to about 658,000 and losses 22% to €198 million, with credit transfers accounting for €148 million (De Nederlandsche Bank, June 2026). Bank-helpdesk fraud, in which criminals pose as bank staff, cost €25.8 million, and Dutch banks say about 70% of online fraud now begins on social media (Betaalvereniging Nederland, 2026). As a major financial and logistics hub, the Netherlands has also faced large anti-money-laundering cases against its biggest banks. Enforcement involves the Public Prosecution Service (OM), FIOD, the police and DNB.
Spain's best-known fraud cases involve political corruption and misuse of public or bank money, notably the Gürtel kickbacks network linked to the Partido Popular (National High Court, 2018) and the Bankia 'black cards' scandal (2017). Spain is also a base for organised fraud networks running phishing and 'smishing', fake-investment call centres and romance scams, which the Guardia Civil and Policía Nacional dismantle in regular operations, often with Europol. Enforcement is led by the Anti-Corruption Prosecutor's Office, the National High Court (Audiencia Nacional), the CNMV and SEPBLAC.
Italy's largest fraud cases include corporate accounting frauds such as Parmalat, whose 2003 collapse revealed a €14 billion hole in its accounts, and cross-border VAT carousel fraud: the EU Public Prosecutor's Office's 'Operation Admiral' (2024) exposed a VAT fraud network estimated at €2.2 billion run largely from Italy. Mafia groups are also involved in tax-credit and public-funds fraud, including EU recovery funds (EPPO annual reports). Enforcement is led by the Guardia di Finanza, the European Public Prosecutor's Office's Italian delegates, CONSOB and the UIF at the Bank of Italy.
Sweden has seen fast-growing fraud against older people, including phone scams in which callers pose as bank or police staff and ask victims to approve BankID logins, much of it linked to organised criminal networks (Swedish Police Authority). Welfare-benefit fraud by criminal groups has also been a political priority. In banking, Swedbank was fined SEK 4 billion in 2020 over anti-money-laundering failures in its Baltic branches, and former CEO Birgitte Bonnesen was convicted of gross fraud on appeal in 2024 for misleading statements (Svea Court of Appeal). Enforcement involves the Swedish Police, the Economic Crime Authority (Ekobrottsmyndigheten) and Finansinspektionen.
As a global wealth-management and commodity-trading centre, Switzerland's fraud exposure lies mainly in laundering, corruption and investment fraud rather than retail scams. Commodity trader Glencore, based in Baar, pleaded guilty in 2022 to bribery and market-manipulation charges in the US and UK (US DOJ; UK SFO, 2022), and Credit Suisse paid about $475 million in 2021 over the Mozambique 'tuna bonds' loans (US DOJ, SEC and UK FCA, Oct 2021). Domestic cases include Dieter Behring's Ponzi scheme, which caused losses estimated at CHF 800 million (Federal Criminal Court, 2016). Enforcement falls to the Office of the Attorney General, FINMA and the MROS financial-intelligence unit.
Payment service providers in Ireland reported more than €179 million in fraudulent payments in 2025, up 27% on 2024, with authorised push payment scams worth €74.86 million, driven by impersonation and investment scams (Central Bank of Ireland data, via BPFI, Sept 2026). The biggest fraud prosecutions stem from the 2008 banking crisis, especially Anglo Irish Bank, where executives were convicted over schemes to disguise the bank's position (Irish courts, 2016–2018). As an EU base for tech and financial firms, Ireland also handles large volumes of phishing, 'smishing' and money-mule activity. Enforcement is led by the Garda National Economic Crime Bureau, the Corporate Enforcement Authority and the Central Bank.
Luxembourg is a major fund-management and private-banking centre, so its fraud exposure is mainly as a place where investment vehicles are domiciled and illicit money may pass through, rather than as a source of retail scams. It featured in the Madoff fallout through feeder funds domiciled there, and in the 2014 collapse of the Espírito Santo group, whose holding company was registered in Luxembourg. The FATF's 2023 mutual evaluation rated Luxembourg's anti-money-laundering framework as largely effective. Enforcement falls to the Luxembourg public prosecutor's economic and financial unit, the CSSF regulator and the Cellule de renseignement financier (CRF).
The name is a translation of the Chinese term 'sha zhu pan' ('killing-pig game'), used from about 2016-2017 for scams that 'fatten' a victim with attention and fake profits before taking everything. It began as a scam aimed mainly at Chinese-speaking victims and was run by organised crime groups linked to online gambling. After Cambodia's 2019 ban on online gambling and the COVID-19 border closures, many casino and gambling compounds in Cambodia, Myanmar and Laos turned to industrial-scale scamming, often staffed by trafficked workers held against their will (UN OHCHR, Aug 2023). From about 2020 the scripts were translated and aimed at victims worldwide, mostly paid in cryptocurrency. The FBI now calls crypto investment fraud the single largest source of reported losses to Americans.
A stranger makes contact through a 'wrong number' text, a dating app or social media, and builds a friendly or romantic relationship over weeks. The conversation moves to an encrypted messaging app, and the contact mentions how much they earn trading crypto, gold or forex. The victim is steered to a fake trading website or app that shows invented profits, so they invest more and may even be allowed a small early withdrawal. When the victim tries to take the money out, they are asked for 'taxes' or 'fees', and then the platform and the contact disappear. Many of the people typing the messages are themselves trafficking victims forced to work in scam compounds.
This method has one well-documented state actor: North Korea. Hacking units the US and UN attribute to its Reconnaissance General Bureau (tracked as the , APT38 and 'TraderTraitor') first stole from banks, most notably the $81 million taken from Bangladesh Bank via SWIFT messages in 2016. From 2017 they turned to cryptocurrency exchanges in South Korea and elsewhere, then to crypto bridges, wallets and trading firms. Each year's haul has tended to set records, peaking with the roughly $1.5 billion Bybit theft in February 2025. The UN Panel of Experts has reported that the proceeds help fund the country's weapons programmes.
Attackers usually go after people, not code: they pose as recruiters or business contacts and send a fake job test, document or trading app that installs malware. Once inside, they steal the keys or sign-in sessions that control a company's wallets, or trick staff into approving a disguised transaction. The stolen coins are moved quickly through many wallets, swap services and mixers, often converted to bitcoin, and finally cashed out through brokers. Individuals are mainly at risk through fake job offers and fake remote IT workers.
The first known ransomware was the 1989 'AIDS Trojan' by biologist Joseph Popp, mailed on floppy disks to AIDS researchers; it hid files and demanded $189 sent to a post box in Panama. It stayed rare until cryptocurrency made anonymous payment easy: CryptoLocker (2013), linked by the FBI to Evgeniy Bogachev's GameOver Zeus botnet, showed how profitable encrypting files could be. In 2017 WannaCry and NotPetya spread worldwide and were later attributed by the US and UK to North Korea and Russia's GRU respectively. Since about 2019 the model has become 'ransomware-as-a-service', where developers rent their tools to affiliates and add 'double extortion' by threatening to leak stolen data.
Criminals get into a network through a phishing email, stolen passwords, or an unpatched internet-facing system. They quietly spread, copy sensitive data, and then lock the organisation's files with encryption. A ransom note demands payment, usually in cryptocurrency, for a decryption key and a promise not to publish the stolen data. Hospitals, schools, councils and companies are hit because downtime puts them under pressure to pay.
The scheme is named after , who in 1920 in Boston promised 50% returns in 45 days from arbitrage on international postal reply coupons, while in fact paying early investors with later investors' money. The idea was older: William '520 Per Cent' Miller ran a similar scheme in Brooklyn in 1899, and Charles Dickens described one in 'Little Dorrit' (1857). Ponzi's collapse after about eight months made his name the label. The method has repeated in every era, from Albania's pyramid-scheme collapse in 1997 to 's decades-long fraud revealed in 2008, and today often appears as crypto 'yield' or 'staking' programmes.
An operator promises unusually high or unusually steady returns from a secret or complicated strategy. Early investors are paid 'returns' that are really money from newer investors, which builds trust and word-of-mouth. The operator often discourages withdrawals by rolling profits over or offering bonuses for recruiting. The scheme collapses when new money slows or many investors ask for their money back at once.
BEC grew from older 'fake boss' and invoice scams done by phone and fax. In France, 'fraude au president' (CEO fraud) cases were documented from the mid-2000s, including those linked to Gilbert Chikli. The FBI began tracking BEC as its own crime type in 2013, as criminals used hacked or look-alike email accounts to redirect business payments. It has since spread to real-estate closings, payroll and vendor payments, and now uses AI voice and video deepfakes. It is consistently one of the two largest loss categories in FBI reporting.
A criminal gets into, or imitates, the email of an executive, supplier, lawyer or title company. They watch real conversations, then send a well-timed message asking for a payment, often saying bank details have changed or a deal is urgent and confidential. The money goes to an account the criminal controls and is quickly moved on through 'money mule' accounts. Some versions ask for gift cards, employee tax records or payroll changes instead.
CNP fraud began with mail-order and telephone-order sales in the 1970s and 1980s, when a card number and expiry date were enough to buy goods. E-commerce in the late 1990s made it global, and online 'carding' forums such as CarderPlanet (2001) and ShadowCrew (shut down by the US Secret Service in 2004) created markets for stolen card data. Large data breaches, such as those at TJX and Heartland in the 2000s, fed those markets. When chip cards made in-store fraud harder (the US shift in 2015), fraud moved further online. Today stolen card data comes from phishing, fake shops and 'web skimming' code on real checkout pages.
Criminals obtain card details through data breaches, phishing messages, fake online shops or malicious code hidden on legitimate checkout pages. The details are sold in bulk on criminal marketplaces. Buyers then use them to shop online, buy gift cards, or pay for services, often shipping to drop addresses. The cardholder usually finds out only when unfamiliar charges appear.
Hiding the source of criminal money is as old as crime, but the modern practice is usually traced to US Prohibition-era gangs; the popular story that the term comes from Mafia-owned laundromats is unproven folklore. Meyer Lansky is widely credited with moving mob money through offshore Swiss accounts from the 1930s, and the phrase 'money laundering' appeared in the press during the Watergate scandal in the 1970s. Governments responded with the US Bank Secrecy Act (1970), the Money Laundering Control Act (1986) and the creation of the Financial Action Task Force by the G7 in 1989. Today laundering runs through shell companies, trade invoices, real estate, 'money mule' accounts and, increasingly, cryptocurrency exchanges, mixers and stablecoins.
Laundering is usually described in three stages. 'Placement' puts criminal cash or crypto into the financial system, for example through small deposits, cash businesses or exchanges. 'Layering' moves it through many accounts, companies, countries or crypto wallets to hide the trail. 'Integration' brings it back as money that looks legitimate, such as property, luxury goods or company profits. Ordinary people are often drawn in as 'money mules' who let their accounts be used.
Market manipulation is as old as organised stock markets: the South Sea Bubble of 1720 and London's Great Stock Exchange Fraud of 1814, in which false news of Napoleon's death was spread to lift government bond prices, are early documented cases. Modern rules came after the 1929 crash, when the US Securities Act of 1933 and Securities Exchange Act of 1934 created the SEC and outlawed deceptive practices; the SEC's 1961 Cady, Roberts decision set out the modern ban on trading on inside information. Large accounting frauds (Enron 2001, WorldCom 2002, Wirecard 2020) showed that executives can falsify the books themselves, and rogue-trading losses at Barings (1995), Societe Generale (2008) and UBS (2011) showed how single traders could hide unauthorised positions. Today the same method includes crypto-token pump-and-dumps and social-media stock promotions.
Insiders or their contacts trade on confidential information, such as an upcoming merger or bad earnings, before the public knows. In accounting fraud, managers inflate revenue or hide debts so the company looks healthier than it is and the share price stays high. In rogue trading, an employee takes on unauthorised positions and hides losses with fake trades or booking tricks until they become too big to cover. In pump-and-dump schemes, promoters hype a thinly traded stock or token, then sell to the buyers they attracted.
Account takeover began with the first online accounts: in the mid-1990s, AOL users were targeted with fake messages and tools such as AOHell to steal their logins. As banking, email and shopping moved online in the 2000s, stolen passwords were reused across sites, and the term 'credential stuffing' (automated testing of leaked username-password pairs) came into use around 2011. From about 2017, SIM swapping, where criminals get a victim's phone number moved to their own SIM, became a common way to beat text-message security codes, especially to empty crypto accounts. Groups such as Scattered Spider now mix phone-based social engineering, fake help-desk calls and SIM swaps to take over personal and corporate accounts.
Criminals get a victim's login details through phishing, data breaches, malware, or passwords reused from other sites. To beat extra security they may trick the victim into reading out a one-time code, pose as the bank's fraud team, or talk a phone carrier into moving the victim's number to a new SIM. Once inside, they change the email, phone and password so the real owner is locked out, then move money, buy goods, or use the account to scam the victim's contacts.
The pay-old-investors-with-new-money scheme is named after , who in 1920 in Boston promised 50% returns in 45 days from postal reply coupons; earlier versions include William F. Miller's '520 Percent Miller' scheme (1899) and Sarah Howe's Ladies' Deposit Company (1880s). Boiler-room share frauds spread in the 20th century, and in 2008 's collapse became the largest Ponzi scheme on record. Online forex and binary-options platforms grew in the 2010s, followed by crypto schemes such as OneCoin. From about 2016 'pig-butchering' scams, which build a relationship before steering a victim to a fake trading app, spread from China-linked groups to industrial scam compounds in Southeast Asia, often staffed by trafficked workers.
Victims are promised high, steady returns, often from a secret strategy, a new technology or crypto trading. Early investors may be paid 'returns' out of later investors' money so the scheme looks real and spreads by word of mouth. Online versions show profits on a fake dashboard, then invent taxes, fees or 'unlock' charges when the victim tries to withdraw. The scheme collapses when new money slows down or the operators disappear.
Crypto exchange hacks began almost as soon as exchanges did: Mt. Gox, then the biggest bitcoin exchange, was breached in June 2011 and collapsed in 2014 after losing about 850,000 bitcoin, much of it stolen over several years. Other early cases included Bitfinex (2016, 119,754 BTC) and Coincheck (2018, about $530m in NEM tokens). From around 2017 North Korean state hackers, tracked as the and TraderTraitor, began targeting South Korean and then global exchanges, and later cross-chain bridges such as Ronin (2022). In February 2025, the FBI attributed the $1.5bn theft from Dubai-based Bybit, the largest crypto theft on record, to North Korea.
Attackers target the keys that control an exchange's 'hot' (online) wallets, or the software used to approve large transfers. Common routes in are phishing or fake job offers sent to staff, poisoned software updates, and compromised developer machines, which let attackers alter what signers see when they approve a transaction. Stolen coins are moved quickly through many wallets, token swaps, cross-chain bridges and mixers, then cashed out through brokers.
Wire fraud is a legal category rather than a single trick: it grew out of the US Mail Fraud Statute of 1872, and in 1952 Congress added a wire fraud law (18 U.S.C. 1343) covering schemes run over telegraph, telephone, radio or TV. As business moved to fax, email and online banking, the law came to cover most modern frauds, and prosecutors use it in cases from Ponzi schemes to crypto. The most common modern form is business email compromise (BEC), which the FBI began tracking in 2013: criminals impersonate executives, suppliers or lawyers to redirect bank transfers. Real-estate closing scams and fake 'change of bank details' requests are now routine versions.
The criminal gets a victim to send money by bank transfer under false pretences. In business email compromise, they hack or spoof an email account belonging to a boss, supplier or lawyer and send a convincing request to pay an invoice or deposit into a 'new' account. Because bank transfers settle fast and are hard to reverse, the money is usually moved on through mule accounts within hours.
The method goes back at least to the 'Spanish Prisoner' letters of the 19th century, in which a writer claimed a wealthy man was jailed in Spain and asked for money to free him in exchange for a share of his fortune; the New York Times reported on such letters in 1898. The modern '419' name comes from Section 419 of Nigeria's Criminal Code, which covers obtaining property by false pretences, after the scheme spread from Nigeria by post and fax in the 1980s. It moved to email in the 1990s with the familiar 'foreign prince' and 'inheritance' messages, and is now run worldwide through lottery, loan, job, inheritance and recovery-scam variants. It also overlaps with romance scams, where a fake partner asks for fees to release money or travel.
The victim is told a large sum is waiting for them, such as an inheritance, lottery win, business deal or loan, but must first pay a small fee, tax or bribe to release it. Each payment is followed by a new obstacle and a new fee, so the victim keeps paying in hope of the big payout. Fake official documents, bank letters and stamps are used to make the story believable, and the promised money never arrives.
The word 'phishing' was first recorded in January 1996 on the Usenet group alt.2600, describing people who tricked AOL users into giving up passwords; the 1995 AOHell toolkit included a tool for this. In the 2000s phishing moved to fake bank and PayPal emails, and 'spear phishing' targeted named people at companies and governments. Smartphones brought SMS 'smishing' and voice 'vishing', and phishing-as-a-service kits such as 16Shop and LabHost let people with no skills run campaigns. Today generative AI helps make messages fluent and personalised, and phishing is still the most-reported cybercrime to the FBI.
The criminal sends a message by email, text, phone or social media that pretends to come from a trusted brand, bank, employer or government office. It creates urgency, such as a locked account, missed delivery or unpaid fine, and pushes the victim to click a link to a fake login page or open a harmful attachment. Details entered on the page, including passwords, card numbers and one-time codes, go straight to the criminal, who uses them to take over accounts or steal money.
Card skimming began with physical devices glued onto ATMs and fuel pumps; its digital form started in retail tills. From the mid-2000s criminal crews planted RAM-scraping malware on point-of-sale (POS) systems, most famously the ring led by behind the TJX (2007) and Heartland (2008) breaches, and later BlackPOS in the 2013 Target breach. As shops moved online, attackers began injecting card-stealing JavaScript into checkout pages; researchers at RiskIQ named this activity 'Magecart' around 2015-2016 because early victims ran the Magento shopping platform. Magecart is now an umbrella label for many unrelated groups, and web skimmers are increasingly delivered through compromised third-party scripts (supply-chain attacks), as in the British Airways and Ticketmaster breaches of 2018.
Attackers break into a shop's payment environment, either a physical till or a website, rather than attacking the shopper directly. In POS attacks, malware reads card data from the till's memory in the split second before it is encrypted. In Magecart attacks, a few lines of hidden code on the checkout page (or in a third-party script it loads) copy what customers type and send it to a server the attackers control. The purchase still goes through normally, so neither shopper nor merchant notices until stolen cards are used or sold.
Decentralised finance (DeFi) runs lending, trading and bridging on public smart contracts, so a coding or design flaw can be abused by anyone. The first landmark case was the June 2016 attack on 'The DAO' on Ethereum, where about 3.6 million ether (roughly $50-60 million at the time) was drained through a re-entrancy bug, leading to Ethereum's hard fork. Flash-loan attacks, which borrow huge sums within a single transaction to manipulate prices, appeared with the bZx incidents in February 2020. Cross-chain bridges became the biggest targets from 2021-2022 (Poly Network, Wormhole, Ronin, Nomad), and the FBI has attributed several of the largest bridge thefts to North Korean state hackers. Today the category also covers oracle and price manipulation, governance attacks and private-key compromise of protocol operators.
A DeFi protocol holds users' pooled funds in smart contracts that follow their code literally. Attackers look for a flaw, such as a bug in how withdrawals are counted, a price feed that can be pushed around, or a bridge whose signing keys can be stolen, and use it to withdraw far more than they put in. Many attacks happen in a single transaction or a few minutes, often funded with a flash loan. Stolen tokens are then swapped, bridged between blockchains and sent through mixers to obscure the trail.
Pyramid schemes trace back at least to the late 19th century, and chain letters promising money to those who recruit others were common by the 1930s. The modern multi-level marketing (MLM) disguise grew in the US in the 1960s-70s with firms such as Holiday Magic and Glenn Turner's Koscot Interplanetary; the US Federal Trade Commission's 1975 Koscot ruling set the classic legal test - money paid mainly for the right to recruit others rather than for sales to real customers. In 1979 the FTC found that Amway was not a pyramid, and that ruling shaped how legitimate MLMs are distinguished from frauds. Mass collapses followed elsewhere, including Romania's Caritas (1992-94) and Albania's schemes of 1996-97, whose collapse contributed to civil unrest. Today many pyramids are pitched online, often as 'digital products', crypto or 'passive income' clubs.
Members pay to join, buy starter kits or meet monthly purchase quotas, and are told they will earn by building a 'downline' of recruits. Most of the money flowing up the chain comes from new members' fees and required purchases, not from selling products to outside customers. Because recruitment cannot grow forever, the scheme stalls and most participants - often the large majority - lose money, while early joiners and organisers at the top keep the gains.
Embezzlement - stealing money one has been trusted to look after - is as old as bookkeeping, and English law made it a distinct crime in the 18th century (the Embezzlement Act 1799 addressed clerks and servants who took their employers' money). It remains the most common form of workplace fraud, from bookkeepers skimming petty cash to officials diverting public budgets. Its largest modern forms are grand corruption, where state or sovereign funds are siphoned (1MDB in Malaysia, the Abacha loot in Nigeria), and the misappropriation of customer deposits, as in the FTX collapse (2022) and Vietnam's Van Thinh Phat / SCB case. Digital banking and crypto have made hidden transfers faster but also leave audit trails investigators increasingly follow.
Someone with legitimate access to money - an employee, finance officer, company founder or public official - quietly diverts it for personal use. Common routes include fake vendors or payroll entries, altered records, personal spending on company cards, or moving client or state funds into accounts the insider controls, often disguised as loans or investments. Because the person is trusted and often controls the records, the theft can continue for years until an audit, a cash crunch or a whistleblower exposes it.
SIM swapping grew out of the telecom practice of moving a phone number to a new SIM card when a phone is lost, combined with banks' reliance on text-message codes for security. Reports of criminals porting victims' numbers to intercept bank codes appeared in the UK and South Africa around 2010-2013. From about 2017-2018 young crews in the US and elsewhere turned it on cryptocurrency holders, with thefts such as the $24 million taken from investor Michael Terpin in January 2018. High-profile takeovers followed, including Twitter CEO Jack Dorsey's account in 2019 and the SEC's X account in January 2024, and SIM swaps have been used as an entry point by groups such as 'Scattered Spider' against large companies.
A criminal gathers the victim's personal details from data leaks or phishing, then persuades or bribes a phone-company employee - or uses a fake ID in store - to move the victim's number onto a SIM card the criminal controls. The victim's phone suddenly loses service, while the criminal receives their calls and text messages. They use these to reset passwords and pass SMS-based two-factor checks on email, bank and crypto accounts, then drain funds quickly.
High-yield investment programs (HYIPs) are online Ponzi schemes promising daily or weekly returns; they spread in the late 1990s and 2000s using digital payment systems such as e-gold and Liberty Reserve. Bitcoin gave them a new rail: the first widely cited bitcoin Ponzi was Trendon Shavers' 'Bitcoin Savings and Trust' (2011-2012), charged by the SEC in 2013. The model then scaled with MLM-style recruitment and 'mining', 'trading bot' or 'staking' stories - OneCoin (2014-2017), BitConnect (2016-2018), PlusToken (2018-2019) and HyperFund (2020-2022). Chainalysis still counts high-yield investment scams among the largest categories of crypto scam revenue.
The scheme promises fixed, high returns - often 1% a day or more - supposedly from mining, arbitrage, a trading bot or a new coin. Early investors are paid out of later investors' deposits, which builds trust and online testimonials; referral bonuses reward people for bringing in friends. Withdrawals are eventually limited, 'paused' or paid in the scheme's own token, and the operators disappear with the remaining funds.
Cheques developed from bills of exchange and were in use in England by the 17th century (a surviving cheque dates from 1659), and forged or altered cheques followed almost immediately. In the US, check forgery, 'paper hanging' (writing bad checks) and check kiting - exploiting the float between banks - were staple frauds through the 20th century; the investment bank E.F. Hutton pleaded guilty in 1985 to 2,000 counts over a kiting-style overdraft scheme, and 's widely publicised (and partly disputed) story made check forgery famous. Desktop publishing in the 1990s made counterfeit checks easy, and remote deposit by phone added new tricks. Since about 2020 US check fraud has surged again, driven by checks stolen from the mail and 'washed' or altered, and by counterfeit checks sold on social media and messaging apps.
Fraudsters steal real checks - often from mailboxes - and chemically 'wash' or alter the payee and amount, or copy the account details onto counterfeit checks. They deposit them into accounts they control or recruit 'money mules' to do so, then withdraw cash before the bank discovers the check is bad. Related scams send victims a fake check for more than they are owed and ask them to wire back the difference before it bounces. Kiting moves money between accounts at different banks to create a false balance during clearing delays.
Bribery has no single inventor: early legal codes and religious texts already prohibited paying officials for favours. The modern fight against cross-border bribery began with the US Foreign Corrupt Practices Act of 1977, passed after SEC inquiries in the mid-1970s (including the Lockheed scandal) revealed that US companies had paid officials abroad to win contracts. The OECD Anti-Bribery Convention (1997) and the UK Bribery Act (2010) extended the model internationally. Large 21st-century cases such as Siemens (2008), Odebrecht/Operation Car Wash (2014-2016) and Malaysia's 1MDB fund show bribes routed through consultants, shell companies and offshore accounts. In the crypto era the method also targets insiders: in May 2025 Coinbase disclosed that overseas support contractors had been bribed to leak customer data later used in impersonation scams.
Someone offers money, gifts, jobs or other benefits to a person with decision-making power, such as an official, procurement officer or company insider, in exchange for a contract, licence, favourable ruling or confidential data. Payments are usually disguised as consulting fees, commissions, donations or inflated invoices, and are often routed through intermediaries and shell companies. The cost is later recovered through overpriced contracts or poor-quality work, so taxpayers, shareholders or customers ultimately pay. Insider bribery can also leak customer data that fuels other scams.
Billing governments and businesses for goods never delivered, or at inflated prices, is as old as organised procurement. Contractor fraud during the American Civil War prompted the US False Claims Act of 1863 (the 'Lincoln Law'), which still underpins US procurement enforcement. In the late 1980s the FBI's Operation Ill Wind exposed bribery and bid-rigging in Pentagon purchasing. From around 2013 the method moved online as Business Email Compromise, where criminals send fake or altered supplier invoices by email; the FBI began tracking BEC as a category in 2013. The case (2013-2015), in which fake invoices mimicking a real hardware supplier fooled Google and Facebook, showed that even large tech firms were exposed.
A fraudster sends an invoice that looks like it comes from a real supplier, or tells the finance team that a supplier's bank details have changed, so payment goes to an account the criminal controls. Inside procurement, a corrupt employee or contractor may inflate prices, bill for work not done, split contracts to avoid oversight or rig bids with fake competing quotes. Criminals often first take over or imitate a genuine email account so the request fits an existing conversation. Funds are quickly moved through mule or shell-company accounts, often abroad.
Telephone confidence tricks are as old as the telephone, and high-pressure 'boiler room' telemarketing fraud flourished in the US from the 1980s. The term 'vishing' emerged in the mid-2000s as cheap internet (VoIP) calling and caller-ID spoofing let criminals impersonate banks at scale. From around 2013 to 2016, call centres in Ahmedabad, India impersonated the IRS and US immigration officials, leading to a 2016 US indictment of 61 people and entities. Fake 'tech support' calls and pop-ups (often claiming to be Microsoft or Apple) grew in parallel. Since 2022 the method has shifted to fake crypto-exchange and wallet support calls and to calls impersonating IT help desks to break into companies, as in the Scattered Spider intrusions.
The caller pretends to be a trusted organisation such as a bank, tax agency, police, tech company, crypto exchange or your employer's IT help desk, often with a spoofed caller ID. They create urgency: an account 'hack', a warrant, a refund or a security alert. The victim is then pushed to read out one-time codes or passwords, install remote-access software, move money or crypto to a 'safe' account, or buy gift cards. With help-desk calls, attackers use personal details found online to get passwords or multi-factor authentication reset for an employee's account.
Fake job offers are an old trick: US regulators have warned for decades about 'work-at-home' schemes such as envelope stuffing that required an upfront fee. Online, fake recruiters and 'reshipping' or 'payment processing' jobs later turned job seekers into unwitting money mules. Since about 2022, 'task scams' pay small sums for rating products or apps, then demand crypto deposits to 'unlock' earnings. Fake jobs are also a hacking lure: North Korea-linked campaigns (dubbed 'Operation Dream Job' by researchers from 2020) send tailored job offers with malicious files, and a fake offer is reported to have opened the door to the $625m Ronin/Axie Infinity theft in 2022. Fake overseas job ads are also used to recruit people into scam compounds in Southeast Asia.
Scammers post or send attractive job offers, often remote, high-paying and requiring little experience, via job sites, LinkedIn, WhatsApp or text. The 'employer' then asks for money for training, equipment or to unlock task earnings, collects ID and bank details, or has the new 'employee' move money that turns out to be stolen. In the hacking version, a fake recruiter runs convincing interviews and sends a document, coding test or app that installs malware giving access to the target's employer systems or crypto wallets. Some overseas job ads lead to trafficking into forced-scam operations.
Affinity fraud is not a separate trick but a way of targeting: the fraudster exploits the trust inside a religious, ethnic, professional or community group. US securities regulators were using the term by the 1990s, when church-linked schemes such as Greater Ministries International and the Baptist Foundation of Arizona collapsed, each costing investors hundreds of millions. 's Ponzi scheme, exposed in 2008, drew heavily on trust within Jewish communities and charities and is often cited as the largest affinity fraud. In the crypto era, schemes such as AirBit Club targeted Latino and immigrant communities with promises of crypto mining profits. Regulators including NASAA continue to warn about frauds using religion and community ties.
The promoter is, or poses as, a member of a group such as a congregation, ethnic community, language group or professional network, and often recruits respected leaders first. Their endorsement makes others invest without checking, and members are discouraged from going to outside regulators. The 'investment' is usually a Ponzi scheme, fake crypto or trading programme, or an unregistered security with promised high, steady returns. Because victims feel loyalty or shame, fraud is reported late and losses spread through whole communities.
Companies that exist only on paper became easy to create after US states such as New Jersey (1889) and Delaware (1899) passed permissive incorporation laws; offshore centres followed, notably the British Virgin Islands' International Business Companies Act of 1984. Shell companies are legal in themselves, but anonymous ownership makes them a favoured tool for hiding bribes, stolen money and sanctions evasion. The Panama Papers (2016) and Pandora Papers (2021) leaks, published by ICIJ, showed how widely they were used by officials and criminals. Cases such as Moldova's $1bn bank theft (2014) and Malaysia's 1MDB used chains of shells to move money. In the crypto era, shell companies with US bank accounts are used to receive and launder scam victims' funds, as in the case.
A company is registered with nominee directors or hidden owners and no real business, often in a jurisdiction that does not publish ownership. It is used to open bank accounts, sign fake contracts or invoices, or pose as a legitimate supplier or investment. Money is passed through several such companies across countries so it becomes hard to trace to its criminal source. Victims may be sent to pay a 'company' account that looks legitimate but is controlled by fraudsters.
Organised price manipulation flourished in 1920s US stock markets, where 'pools' of traders bid up shares, talked them up in the press and sold to the public, as exposed by the Senate's Pecora hearings (1932-1934). The Securities Exchange Act of 1934 outlawed such manipulation. In the 1980s-1990s 'boiler room' brokerages such as 's Stratton Oakmont cold-called investors to push penny stocks they then sold. The internet moved the pitch to message boards and spam emails, and from around 2017 to crypto: Telegram 'pump groups', paid influencer touting of ICOs, and market makers faking trading volume. In October 2024 the FBI created its own token in 'Operation Token Mirrors' to catch crypto market-manipulation firms.
Insiders or promoters quietly buy a cheap, thinly traded stock or token. They then hype it with false or exaggerated claims through calls, social media, influencers, chat groups or fake trading volume (wash trading), so the price rises as new buyers pile in. Once the price is up, the promoters sell their holdings, the price collapses, and late buyers are left with large losses. With new crypto tokens, creators may also control most of the supply or the liquidity pool and pull it out (a 'rug pull').
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
THE PEOPLE AROUND ENRON
CASE TIMELINE
HOW IT WORKED
HOW ENRON HID THE DEBT — DEFENSIVE LEVEL
WHAT THIS CASE ESTABLISHED
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — ENRON (1,600 WORDS)
Everyone knows the name. Fewer know what the charges were.
Enron Corporation was the seventh-largest company in the United States at its peak in 2000 — an energy trading and utilities conglomerate with revenues that made it appear to be one of the most successful businesses in the country. Its stock had risen tenfold through the 1990s. Wall Street analysts rated it a buy. Its management were celebrated as the smartest people in the room.
The charges: structures built to move debt off the balance sheet where investors could not see it, and statements to investors and analysts that the company's financial picture was sound when, per the government, the people making those statements knew it was not.
The corporate fraud category of this series had three cases before Enron was added: Ebbers (024, WorldCom), Rigas (037, Adelphia), Kozlowski (038, Tyco). Enron is the fourth and most significant — not because the mechanism was more sophisticated, but because the scale was larger, the name became a word, and the case produced the law that the entire series' compliance thesis rests on.
Enron's fraud had two primary components, stated plainly per the DOJ and the trial record.
The first: special-purpose entities. Enron created dozens of partnerships and SPEs — including entities known as LJM Cayman, LJM2, and the Raptors — and used them to move debt off Enron's consolidated balance sheet. The debt was real; the balance sheet did not show it. The entities were structured to appear independent while effectively being controlled by Enron. Under accounting rules of the period, if a structure was sufficiently independent, Enron could exclude it from its consolidated financial statements.
Andrew Fastow, Enron's CFO, was the architect of the SPE structure and the primary government witness at trial after pleading guilty in 2004. He was sentenced to 6 years. [SOURCE: DOJ Fastow plea; court record]
The second component: false statements. While the debt was being moved off the balance sheet and trading operations were presented as generating profits that the underlying economics did not support, Skilling, Lay, and others made public statements — to analysts, investors, and in SEC filings — that affirmed Enron's financial health. The government's case was that these statements were knowingly false.
Enron also used mark-to-market accounting — a method that allows a company to book the projected future value of a contract at the time it is signed, rather than as cash is received. Legitimately applied, this is an accepted accounting method. The government alleged that Enron used it to inflate earnings by booking projected profits from contracts whose actual economics were poor.
Jeffrey Skilling resigned as CEO on August 14, 2001 — approximately six months after taking the position — citing personal reasons. Kenneth Lay, the company's founder, returned to the CEO role. Analysts began asking harder questions. In October 2001, Enron disclosed a $618 million third-quarter loss and the unwinding of some of the SPE structures. Fastow was placed on leave.
The stock — which had traded above $90 in August 2000 — had fallen to approximately $15 by October 2001. It continued falling as each new disclosure arrived. On December 2, 2001, Enron filed for Chapter 11 bankruptcy — at the time, the largest corporate bankruptcy in US history, with assets of approximately $63 billion.
The human consequences: approximately 4,000 to 5,700 Enron employees lost their jobs, depending on how the accounting is made (the figures vary by source — verify before asserting a specific number). Many had been encouraged to hold concentrated Enron stock in their 401(k) retirement accounts — and did, because the company's leadership was saying the stock was safe. When the stock collapsed, those accounts were worthless. Employee pension losses are estimated at approximately $2 billion. [SOURCE: Enron retirement-plan litigation; Congressional testimony]
Arthur Andersen, Enron's auditor, was indicted for obstruction of justice related to the shredding of Enron documents. It was convicted in 2002. The Supreme Court later overturned the conviction — but by then Andersen had effectively ceased to exist. One of the Big Five accounting firms was destroyed.
Skilling was indicted in 2004 in the Southern District of Texas. He was convicted on May 25, 2006 on 19 counts — including conspiracy, securities fraud, wire fraud, and a smaller number of insider trading counts. He was acquitted on nine insider-trading counts. [SOURCE: DOJ; trial record]
On October 23, 2006, Judge Simeon Lake sentenced Skilling to 24 years and 4 months in federal prison.
He appealed. In 2010, the United States Supreme Court issued a ruling in Skilling v. United States, 560 U.S. 358 (2010), that narrowed the interpretation of the 'honest services' fraud statute (18 U.S.C. § 1346). The Court held that the statute covers only bribery and kickbacks — not, as it had been more broadly applied, any breach of fiduciary duty. Skilling's honest-services conspiracy count was affected by this ruling.
On remand, the Fifth Circuit found the honest-services count error harmless as to the overall conviction — Skilling remained convicted. But the resentencing produced a reduction. On June 21, 2013, as part of a negotiated settlement in which Skilling agreed not to pursue further appeals and to forfeit approximately $42 million for the victims, Judge Lake resentenced him to 168 months — 14 years.
He was released from federal custody on February 21, 2019, after about 12 years in prison and six months in a halfway house in Texas. He served at FCI Englewood, Colorado, and later at the Federal Prison Camp in Montgomery, Alabama. [SOURCE: BOP; Reuters; Houston Chronicle]
Kenneth Lay founded the company that became Enron in 1985. He was its chairman throughout, and returned as CEO after Skilling's resignation in August 2001.
He was charged separately. He was convicted on May 25, 2006 — the same day as Skilling — on 6 counts of conspiracy and fraud in the corporate fraud trial. He was separately convicted on 4 bank fraud charges in an individual trial. [SOURCE: DOJ]
He died on July 5, 2006, at his vacation home in Aspen, Colorado — of a massive heart attack. He was 64 years old. He had not yet been sentenced. His appeal had not yet been heard.
On October 17, 2006, Judge Sim Lake of the Southern District of Texas vacated Lay's conviction — not because the evidence was re-examined, and not because of any finding of innocence. The vacatur was automatic under the legal doctrine of 'abatement ab initio': in US law, when a defendant dies before exhausting appeals, the case is treated as if it never reached final judgment. The conviction is vacated, the indictment is dismissed, and any forfeiture orders are dissolved.
This means: the jury's verdict of guilty was never made final by the appellate process. It does not mean the jury was wrong. It does not mean Lay was innocent. It means he died before the case was concluded, and US law treats an unconcluded case as no case at all.
The brief for this case flags the Lay vacatur as the most commonly botched fact in Enron coverage. Coverage that describes Lay as 'cleared,' 'acquitted,' or 'found innocent' is wrong. The accurate description: convicted, died before sentencing, conviction vacated as a matter of law. That is the sequence.
Enron collapsed in December 2001. WorldCom collapsed in June 2002. Between them, they produced Sarbanes-Oxley — the Public Company Accounting Reform and Investor Protection Act, signed by President Bush on July 30, 2002.
Sarbanes-Oxley requires CEOs and CFOs to personally certify the accuracy of their companies' financial statements. It imposes criminal penalties for knowingly false certifications. It established the Public Company Accounting Oversight Board. It strengthened protections for whistleblowers. It mandated new audit committee independence requirements.
The series' thesis about governance — that the compliance function must be independent of the party it checks, and that the CEO must bear personal accountability for what the financial statements say — is, in large part, Sarbanes-Oxley's thesis. Sarbanes-Oxley is, in turn, Enron's thesis.
And Skilling's appeal produced a narrowing of the honest-services fraud statute that matters beyond his own case: the Supreme Court's ruling in Skilling v. United States limits how broadly the government can use the honest-services theory in future corporate fraud prosecutions. The case changed the law it was tried under, which is why the sentence dropped.
SOURCES
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
COURT RECORD — THE JUDGE SPOKE
JUDGE ENGELMAYER — SENTENCING DEC 11 2025 — SDNY
COURT EXHIBITS — HIS OWN WORDS
MAY 9, 2022 — AS UST COLLAPSED
@stablekwon · May 9 2022 · cited by Judge Engelmayer at sentencing as devastating to investors [SOURCE: court record]
RESPONSE TO CRITICS
@stablekwon · cited by Judge Engelmayer as emblematic of Kwon’s posture toward critics [SOURCE: Decrypt / Inner City Press]
HOW THE FRAUD WORKED
THE TWO DEPEGS — ONE LIE
KNOWN ASSOCIATES
CASE TIMELINE
WHAT THIS CASE ESTABLISHED
THE FULL STORY — 13 PARTS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — $40 BILLION. FIVE DAYS. TWO DEPEGS, ONE LIE. (3,900 WORDS)
On May 9, 2022, as TerraUSD began to lose its dollar peg and the price of LUNA started the free-fall that would erase tens of billions of dollars in the coming days, Do Kwon posted on X — then Twitter.
"Deploying more capital — steady lads."
Posted May 9, 2022, as UST began its terminal depeg. Cited by Judge Engelmayer at sentencing as devastating to investors. [SOURCE: court record / Decrypt sentencing coverage]
The message landed on hundreds of thousands of followers who had built their savings in an ecosystem he had spent years promoting as mathematically sound, self-correcting, and engineered to hold its value regardless of market conditions. The algorithm was the product. Steady lads was the assurance.
Within five days, approximately $40 billion in value had been wiped from the Terra ecosystem. [SOURCE: BBC, Dec 2025] UST never recovered its dollar peg. LUNA collapsed from its all-time high of over $100 (April 2022) to fractions of a cent. The algorithm — the thing the product was supposed to be — had failed.
And before that terminal collapse, the algorithm had already failed once. In May 2021. And when it failed that first time, Do Kwon had not told investors the algorithm had been bailed out by a trading firm secretly buying millions of dollars of the coin. He had told them the algorithm had fixed it. [SOURCE: court documents cited by BBC]
That lie — not the collapse itself, but the lie about what had caused the recovery — is the crime. The code was real. The promise was not.
He sold a mathematical promise. When the math failed, he replaced it with a buy order and told the world the machine had done it. That is the fraud.
Kwon Do-hyung — Do Kwon, as the world knew him — grew up in South Korea and attended Stanford University, the California institution that has produced a disproportionate share of the technology industry's most significant founders, products, and failures.
He graduated with a computer science degree. The academic credentials gave him something that proved useful in the world he moved toward: the appearance of technical authority. When he described how TerraUSD worked, how the algorithm maintained the peg, how the mathematics guaranteed stability, he was not describing it as a layman speculating about what computers could do. He was describing it as a Stanford-educated computer scientist who had designed the system himself.
He co-founded Terraform Labs in 2018 and based it in Singapore — a jurisdiction with established crypto infrastructure, regulatory sophistication, and access to global capital. The firm built two linked products: TerraUSD (UST), an algorithmic stablecoin intended to hold a stable value of one US dollar, and LUNA, a companion token whose value was designed to absorb UST's volatility and maintain the peg through a mint-and-burn mechanism.
He called himself the 'crypto king.' His followers, who called themselves Lunatics, were devoted in the way that online communities devoted to a founder who speaks their language tend to be devoted — with the specific intensity of people who have bet money on the vision and need the vision to be true.
He was 34 years old when he was sentenced. [SOURCE: Decrypt, Dec 2025] He had built a multi-billion dollar ecosystem, attracted institutional investors, and established himself as one of the most prominent figures in the cryptocurrency world. He had also, according to the court that sentenced him, chosen to lie. [SOURCE: Judge Engelmayer, sentencing record]
A stablecoin is a cryptocurrency designed to hold a stable value — typically pegged to one US dollar. The utility is obvious: in a market where Bitcoin can move 20% in a day, an asset that reliably equals one dollar lets you hold crypto exposure without the volatility.
There are two main ways to build a stablecoin. The first is to back every token with real dollars or dollar-equivalent assets held in reserve. This works reliably — USDC and Tether operate roughly this way — but requires capital, creates counterparty risk, and places control with whoever holds the reserves.
The second way is to use an algorithm. This was UST's proposition. Instead of reserves, UST would maintain its dollar peg through a mathematical relationship with LUNA. When UST traded below a dollar, market participants could burn UST and receive LUNA at a profit — reducing UST supply and pushing the price back up. When UST traded above a dollar, participants could mint new UST by burning LUNA — increasing supply and pushing the price back down. Automatic. Decentralized. No human custodian of reserves. The code does it.
This was the product. Not just a stablecoin — an algorithmic stablecoin. A mechanism that maintained value through code rather than custody. The entire value proposition rested on the mechanism working.
The Anchor Protocol — Terra's own savings product — offered 20% annual yields on UST deposits. [SOURCE: Decrypt sentencing coverage, citing victim testimony] For context, US savings accounts in the same period offered under 1%. A man from Ukraine testified at Kwon's sentencing that he had placed 17 years of savings into the system after Kwon's assurances convinced him it was safe. [SOURCE: Decrypt, Dec 2025]
The 20% yield required that the algorithm sustain the peg. If the peg broke, the yield was fiction. If the algorithm was fiction, the peg was fiction. If the peg was fiction, 17 years of savings was fiction.
In May 2021, TerraUSD lost its dollar peg for the first time.
What happened next is the core of the fraud as stated in the court documents. According to those documents, when UST fell below $1, Kwon arranged for a trading firm to secretly purchase millions of dollars of the coin to artificially restore its price. [SOURCE: BBC Peter Hoskins, Dec 12 2025, citing court documents]
Then he told investors that a computer algorithm had restored the value.
That was false.
The distinction is not subtle. The entire pitch of an algorithmic stablecoin — the reason people chose UST over a reserve-backed stablecoin — was that no human intervention was required. The code did it. That was the product. When the code failed in May 2021 and a trading firm had to step in and buy the coin to prop the price, the product had demonstrably not worked as described.
Kwon knew this. He said the algorithm had fixed it. The investors who read that, who saw the price recover, who kept their UST deposits in Anchor Protocol, who told their friends the system worked — they believed something that was not true. And they kept believing it for another year.
When the algorithm failed, he used a human to fake it — then told the world the machine had done it. That is the moment the product became a lie, and telling it is the crime.
Do Kwon had an online presence that Judge Engelmayer would later characterise — from the bench at sentencing — as that of a cult leader who traded on victims' trust. [SOURCE: Decrypt sentencing coverage, Dec 2025]
The characterisation was not invented by the judge. It was observable from the public record of Kwon's own posts.
"I don't debate the poor."
Posted publicly on X. Cited by Judge Engelmayer at sentencing as emblematic of Kwon's posture toward critics. [SOURCE: Decrypt / Inner City Press sentencing coverage]
Critics who raised technical concerns about the stability of the UST-LUNA mechanism — and there were credible ones, documented publicly — were often dismissed, mocked, or ignored. Kwon's confidence was absolute and performed. The community around Terra reflected that confidence. The Lunatics believed because their leader believed, and their leader communicated belief with the specific certainty of someone who had either done the mathematics or decided the mathematics could be safely ignored.
The Anchor Protocol's 20% yield attracted retail investors who would not normally have engaged with algorithmic DeFi products. It attracted them because 20% is a number that needs no technical explanation. 20% sounds real regardless of whether the mechanism that produces it is real.
Kwon promoted the ecosystem constantly. He promoted it on Twitter. He promoted it in interviews. He promoted it to institutional investors, to retail depositors, to the Korean community that had adopted Terra with particular enthusiasm. The persona was the marketing. The marketing was the confidence. The confidence was, in the end, a lie about what the algorithm had done in May 2021.
The terminal collapse began in the first week of May 2022.
Large withdrawals from the Anchor Protocol began. UST started trading below its dollar peg. The mint-and-burn mechanism activated — exactly as designed — but the scale of the depegging triggered a dynamic that the algorithm was not built to handle: as LUNA was minted to absorb UST's excess supply, LUNA's price fell, which reduced the value of the mechanism that was supposed to restore the peg, which caused more depegging, which required more LUNA to be minted, which further reduced LUNA's value.
It was a death spiral. Not a bug — a structural vulnerability in the design that critics had identified publicly before the collapse. The faster the algorithm tried to fix the peg, the faster it destroyed the value of the mechanism doing the fixing.
Steady lads was posted into this.
Over five days, LUNA fell from approximately $80 (its pre-collapse trading price in early May 2022) to fractions of a cent. UST broke and did not recover. Approximately $40 billion in market value was destroyed. [SOURCE: BBC; DOJ/SDNY] The figure is market value lost — the aggregate decline in the value of tokens people held. It is not a theft figure. Nobody took $40 billion from an account. But the people holding UST because they believed a dollar would always be a dollar, and the people holding LUNA because the ecosystem had always recovered, watched the numbers go to near zero and did not get them back.
First depeg. Trading firm secretly buys UST to prop price. Kwon publicly attributes recovery to the algorithm. [Court documents / BBC]
Terminal depeg begins. Large Anchor withdrawals trigger UST falling below $1. LUNA death spiral activates.
'Deploying more capital — steady lads.' Posted to Twitter as the collapse accelerates. [Court exhibit / Decrypt]
LUNA collapses from ~$80 (pre-collapse price, May 2022) to fractions of a cent. UST loses peg permanently. ~$40B in market value destroyed. [BBC / DOJ]
Terra's collapse triggers contagion across the crypto market. Several other firms including Celsius and Three Arrows Capital subsequently fail in part due to Terra exposure.
After the collapse, Do Kwon went on the run.
He denied it publicly. Asked in interviews whether he was hiding, he said he was not. He maintained that he was cooperating with authorities, that the collapse was a market event rather than a fraud, that the code had done what it was designed to do. South Korean authorities disagreed. In September 2022, they issued an arrest warrant. Interpol issued a Red Notice — the international alert used for wanted fugitives. [SOURCE: Interpol / widely documented]
South Korean prosecutors believed he was in Serbia, which had no extradition treaty with South Korea. Montenegro, which borders Serbia, has dramatic coastline and mountains and, according to reporting at the time, a politician with whom Kwon had a long-standing association and whose campaigns he may have funded. [SOURCE: Fortune, June 2023 — cited as allegation from reporting] Whether Montenegro felt like a safe harbour or simply the next stop on a route, he ended up there.
On March 23, 2023, Kwon attempted to board a flight at Podgorica Airport — Montenegro's capital — bound for Dubai. He was carrying a Costa Rican passport. Montenegro police detained him. His identity was confirmed through photographic and biometric data. Also found in his luggage: Belgian passports, a South Korean passport, laptop computers, and other devices. [SOURCE: Coindesk / The Block / widely documented from police statement]
Han Chang-joon, Terraform Labs' former chief financial officer, was arrested alongside him.
Kwon told the Montenegrin court that he had acquired the Costa Rican passport through a legitimate agency in Singapore, recommended by a friend. He acquired the Belgian passport through another agency. A Montenegro court sentenced him to four months for using forged documents — time he had already largely served in pretrial detention. [SOURCE: The Register, June 2023; widely documented] The extradition battle between South Korea and the United States took longer.
The US won. Kwon arrived in American custody and appeared before Judge Paul A. Engelmayer in the Southern District of New York. In January 2025 he pleaded not guilty. In August 2025 he changed his plea — guilty to wire fraud and conspiracy to defraud. [SOURCE: DOJ/SDNY; Reuters]
On December 11, 2025, Do Kwon stood before Judge Paul A. Engelmayer in a Manhattan courtroom wearing a yellow prison jumpsuit. He was 34 years old.
The victims spoke first. A man from Ukraine described losing nearly $200,000 — seventeen years of savings — after Kwon's public assurances had convinced him that the system was safe. He had invested through Anchor Protocol, attracted by the 20% annual yield, trusting the man who had told him and hundreds of thousands of others that the algorithm held. [SOURCE: Decrypt sentencing coverage, Dec 2025]
Then the judge spoke.
"In the history of federal prosecutions, there are few frauds that have caused as much harm as you have."
"You chose to lie." — "You chose poorly."
"You have been bitten by the crypto bug and I don't think that's changed. You must be incapacitated."
The judge compared Kwon to the leader of a cult, who traded on victims' trust.
He described the $40B figure as 'eye-popping,' even for the Southern District of New York, where some of the largest financial crimes in history have been prosecuted.
Engelmayer described Kwon's famous tweets — 'Deploying more capital — steady lads' and 'I don't debate the poor' — as devastating to investors and emblematic of the posture that had made the fraud possible. He compared Kwon to a cult leader not as a rhetorical flourish but as a characterisation of how the scheme had functioned: by substituting the leader's authority for the independent verification that might have revealed the product's failure.
Prosecutors had sought 12 years. Kwon's lawyers had sought 5 years. Kwon himself, in written submissions, had deemed 5 years a fair punishment. [SOURCE: Forklog / The Block, Dec 2025]
Kwon addressed the court.
Judge Engelmayer acknowledged the letter Kwon had written to the court, noting it was 'beautifully written, for your daughter one day.' He gave credit for 17 months and 8 days served in pre-extradition custody. He stated that 15 years was the least he could impose under the circumstances. And he delivered it.
15 YEARS
US District Court · Southern District of New York · Judge Paul A. Engelmayer
Credit: 17 months and 8 days served pre-extradition (US + Montenegro)
South Korea, separately, faces Kwon with proceedings that could produce a sentence of up to 40 years. The Manhattan sentence does not preclude further accountability in his home country. [SOURCE: Sharpe.ai aggregating Korean Times reporting, Dec 2025]
The Ukraine victim is one person. There were hundreds of thousands.
Terra's ecosystem was estimated to have drawn in well over a million users across the Anchor
Protocol and the wider Terra applications before the collapse. The number of individual holders
of UST and LUNA ran into the hundreds of thousands. When both tokens went to near zero, every
one of them was holding a claim on value that no longer existed.
The geographic concentration was not uniform. South Korea, Kwon's home country, had adopted
Terra with particular enthusiasm — the community was large, vocal, and heavily invested. After
the May 2022 collapse, reporting from Korea documented a surge in distress, including a
documented spike in calls to suicide-prevention services and multiple suicides attributed by
local media to the losses. [SOURCE: Korean media reporting, 2022 — verify before publication]
That is the part the numbers hide. A 20% yield, marketed to people who had never touched
decentralised finance, promising a dollar that would always be a dollar — and behind it, a
mechanism that could not hold. The people who trusted it were not sophisticated arbitrageurs.
They were the ordinary end of the market, attracted by a number they understood.
Anchor Protocol was Terra's own savings product. It offered approximately 20% annual yield on
UST deposits — in a period when US savings accounts paid under 1%. [SOURCE: Decrypt; court
testimony]
That single number is the reason the scheme grew as fast as it did. A 20% return needs no
technical explanation. It does not require the depositor to understand mint-and-burn mechanics,
algorithmic peg restoration, or the difference between a reserve-backed stablecoin and a
synthetic one. It requires only the belief that the number is real — and the authority of the
man saying it.
The mathematics, however, were always against it. The yield had to come from somewhere. In
Anchor's design, it was subsidised — meaning it was paid from capital that had to keep arriving.
A 20% rate paid from fresh deposits is, structurally, a Ponzi-shaped obligation regardless of
whether anyone intends a fraud: it works exactly as long as inflows exceed the cost of the
yield, and stops the moment they do not.
In May 2022, inflows reversed. The largest withdrawals in Anchor's history began. That is the
trigger — not a hack, not a bug, but depositors doing what depositors do when confidence shifts.
Terra did not fall alone.
The $40 billion destroyed inside the Terra ecosystem was the headline. The secondary damage was
larger and harder to price. Firms that held Terra exposure, or that had borrowed against it, or
that had built strategies around its yield, failed in the months that followed:
in July 2022. Its collapse is directly tied to the post-Terra credit contraction. Its founder,
, later pleaded guilty to fraud in a separate case.
liquidation in 2022, having held substantial LUNA exposure.
compounding the next as the credit that had flowed freely in the bull market reversed.
The chain reaction matters to the story because it reframes the scale. Terra's own collapse was
a $40 billion event. The industry damage it set off was larger — and it happened because tens of
thousands of market participants had treated an algorithmic promise as a foundation. One broken
product, used as an assumption by an entire sector, collapsed a chain no single fraudster
controlled.
The mechanism that destroyed Terra was not discovered in May 2022. It was described publicly,
in technical terms, by critics long before the collapse.
The core objection was always the same, and it was correct: the design worked only while LUNA
had value. In a depeg, the protocol would mint LUNA to absorb excess UST supply — but minting
LUNA dilutes it, which lowers its price, which reduces the value of the mechanism meant to
restore the peg, which causes more depegging, which requires more LUNA. The death spiral was
not an unforeseen failure. It was the design's predictable end state, articulated by critics
before the token was ever large.
Those critics were dismissed. Kwon's own public posture — "I don't debate the poor" — was a
statement not about poverty but about the refusal to engage. Technical challenges were met with
the founder's confidence rather than with independent verification. The community around Terra
adopted the founder's certainty as its own.
The parallel to is exact in structure, if opposite in scale. In Madoff, a whistleblower
spent eight years telling the regulator the numbers were impossible, and the warning did not
land before the collapse. In Terra, the warning was public, technical, and repeated — and it was
mocked. In both cases, the failure was not that nobody knew. It was that the knowing was not
enough against a founder's authority.
Each case in this series is built on a thesis.
(): the persona was the marketing. A crafted identity, sold so convincingly
that the fraud was invisible inside it.
(): the speed. Twenty years old, caught within a month, because the spending
was louder than the theft.
(Madoff): the duration. Forty-eight years, built on the trust of a name nobody thought
to question.
Case 003 (Do Kwon): the product was the lie. The others sold themselves. He sold a mechanism —
an algorithmic stablecoin that was advertised to work by mathematics, with no human in the loop.
When the machine failed in May 2021, a human bought the coin to fake the recovery, and he told
the world the machine had done it. That is the fraud, and it is the whole fraud.
The code was real. The promise was not.
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
KNOWN NETWORK & CO-CONSPIRATORS
HOW THE FRAUD WORKED
PONZI MECHANISM — THREE STEPS
CASE TIMELINE
WHAT THIS CASE ESTABLISHED
THE FULL STORY — 9 CHAPTERS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — 48 YEARS. NOBODY ASKED. (3,800 WORDS)
For 48 years, nobody asked the question that would have ended it.
The question was simple enough. The returns Bernie Madoff reported — steady, consistent, market-defying — should have attracted scrutiny from the first year they appeared implausible. Instead they attracted more investors. The more consistent the returns, the more people wanted in. The more people who wanted in, the more legitimate the operation appeared to those who were already there. Trust compounded the way the returns claimed to.
Bernard Lawrence Madoff founded his investment firm in 1960. He was arrested on December 11, 2008. In between: 48 years of fabricated account statements, approximately 4,800 client accounts showing $64.8 billion that did not exist, and a reputation so solid that when a whistleblower told the SEC what he had found, the regulator did not act in time to prevent the collapse. [SOURCE: SEC Press Release 2008-293; SDNY]
When the scheme finally ended, it ended not because regulators caught it, not because an investigator broke it, but because the 2008 financial crisis forced redemption demands that exceeded what the scheme could pay. And even then, the arrest came not from outside — it came from his own sons.
Bernard Lawrence Madoff was born on April 29, 1938, in Queens, New York.
He was not born into money. He was not a legacy admission at a white-shoe firm. He did not inherit a seat on any exchange. The Madoff story — the one he told and the one that made him — was the story of a man who built something from nothing, who understood the markets before the markets understood themselves, who earned every credential through intelligence and application and relentless, patient work.
He founded Bernard L. Madoff Investment Securities LLC in 1960 with $5,000 he had saved from working as a lifeguard and a sprinkler installer — as Madoff himself described it and as widely repeated in the federal record. [SOURCE: Madoff's own account; widely reported in federal record commentary] He was twenty-two years old.
He built the firm into a legitimate force. Madoff Investment Securities became a market maker — a firm that stood ready to buy and sell securities, providing liquidity to the market, operating in the space between the buyer and seller that most people never think about. The firm was real. The market making operation was real. The trades were real.
And Bernie Madoff became, through decades of legitimate operation, one of the most respected figures on Wall Street. He served as chairman of Nasdaq — the electronic stock exchange — a position that placed him at the very centre of the American financial system's infrastructure. When regulators sought industry input on market structure, Madoff was the kind of person they called.
This is the detail that makes everything else possible: he was not an outsider running a scam. He was an insider, fully embedded in the system, trusted by the system, decorated by the system. The fraud did not fool Wall Street from outside. It ran in Wall Street, wearing Wall Street's own credentials.
The investment advisory side of the business was the fraud. Not the market making. Not the trading operation. A separate function, kept deliberately apart, in which Madoff accepted money from clients and promised to invest it using a strategy he called the split-strike conversion.
The split-strike conversion is a real options strategy. It involves buying a basket of large-cap stocks while simultaneously selling call options above the current price and buying put options below it, limiting both the upside and the downside. It is a legitimate technique that produces modest, consistent returns with reduced volatility.
Madoff used it as a story. He never executed the strategy. He never bought the stocks. He never executed the options. He simply described the strategy, fabricated the account statements showing it working, and paid withdrawals from new investor deposits. [SOURCE: US v. Madoff, 09 Cr. 213 (DC) — guilty plea; SDNY]
The mechanism of a Ponzi scheme is precisely this simple:
The scheme survived for reasons that are, in retrospect, a catalogue of institutional failure. The returns were too consistent — markets do not move that smoothly — but consistency is not alarming when you trust the person reporting it. The strategy was described but never independently verified. The auditor was a tiny, obscure firm, not the Big Four accountant a firm of this scale should have used. [SOURCE: SEC / DOJ record] These were all flags. They were not read as flags.
The compliance officer was his brother.
Peter Madoff — Bernard's younger brother — served as senior managing director and chief compliance officer of Bernard L. Madoff Investment Securities. The chief compliance officer is, in theory, the internal guard. The person whose job is to ensure the firm follows the law. The check on the founder. [SOURCE: US v. Peter Madoff, S7 10 Cr. 228 (LTS), SDNY]
In this firm, the check on the founder was the founder's brother. The result was not compliance — it was the appearance of compliance, maintained by the same family loyalty that ran everything else in the operation.
Peter Madoff pleaded guilty and was sentenced to 10 years in federal prison. [SOURCE: SDNY]
Shana Madoff — Peter's daughter, Bernard's niece — served as the firm's rules and compliance attorney. She has maintained that she had no knowledge of the fraud.
Mark Madoff and Andrew Madoff — Bernard's sons — both worked at the firm in the legitimate trading business, separated from the investment advisory operation their father ran. On December 10, 2008, their father told them the investment advisory business was 'one big lie.' They went home. The next morning, December 11, 2008, they called their attorney and turned their father in to federal authorities. [SOURCE: DOJ; widely reported from federal record]
The sons did not know. When they found out, they reported him. They spent the years that followed living under the weight of a name they shared with the man who had built one of the largest frauds in history, and who had been exposed by them.
The 4,800 client accounts held a combined $64.8 billion in fabricated value as of November 30, 2008. That number — $64.8 billion — is the prosecutors' estimate of the fraud. [SOURCE: SDNY prosecutors, cited in sentencing] It is the number in the account statements. It is not what investors actually lost.
The actual principal lost — money that went in and did not come back — was approximately $17 billion, based on the Irving Picard trustee's calculations. [SOURCE: SIPC / Trustee record] Some investors had already withdrawn more than they put in, having received years of fake returns that came from other investors' deposits. Those investors made money — from other victims. The moral accounting is not clean.
The victims were not all institutions. They were not all sophisticated investors who should have known better. Many were retirees, charitable foundations, and individuals who had trusted Madoff with their savings over decades. Jewish communities in particular were heavily targeted — Madoff operated extensively within Jewish philanthropic and social circles, which gave the scheme a warm referral network built on community trust. [SOURCE: DOJ / widely documented in federal record commentary]
The charities that lost money did not simply lose returns. They lost principal. Some could not make grant payments. Some closed. The damage ran downstream from the account statements into hospitals that did not get funded, scholarships that were not awarded, organisations that had built their endowments over decades and discovered those endowments were fiction.
Forfeiture ordered: $170.8 billion. [SOURCE: SDNY preliminary forfeiture order, June 26, 2009] This is a legal figure: what prosecutors said flowed through the scheme's main account. It is not restitution and not assets he held. It is not the same as the fabricated account value or the actual principal lost. Three numbers, three meanings.
In 1999, a financial analyst named Harry Markopolos was asked by his employer to reverse-engineer Bernie Madoff's investment strategy. His employer wanted to replicate the returns.
Markopolos looked at the numbers for — by his own account, in Congressional testimony — four hours, and determined they were mathematically impossible. [SOURCE: Markopolos Congressional testimony; widely documented from public record] The consistency of the returns, the strategy as described, the market conditions during the periods in question — they did not add up. He concluded that Madoff was either front-running — trading on advance knowledge of customer orders — or running a Ponzi scheme. [SOURCE: Markopolos testimony; widely documented]
He went to the SEC. In 2000. He told them what he had found. He submitted a formal complaint in 2005 entitled 'The World's Largest Hedge Fund Is a Fraud' — naming Madoff directly, providing the mathematical analysis, explaining exactly what the numbers showed. [SOURCE: widely documented from SEC record]
The SEC investigated. They did not find the fraud.
They investigated again. They did not find the fraud.
Markopolos continued warning. The SEC continued not finding. By 2008, he had submitted his findings multiple times over eight years. The regulator charged with protecting investors from exactly this kind of fraud had been told, explicitly, in writing, with the mathematics laid out, that the largest Ponzi scheme in history was operating on their watch.
The scheme collapsed anyway. Not because of the SEC. Because of the financial crisis.
The 2008 financial crisis was the specific event that ended it.
As markets collapsed in the autumn of 2008, investors everywhere needed cash. The redemption requests that came into Bernard L. Madoff Investment Securities in November and December 2008 were approximately $7 billion — more than the scheme had available to pay. [SOURCE: widely documented from SDNY record] For 48 years, inflows had exceeded or matched outflows. Now they did not. The mathematics of a Ponzi scheme are simple: it ends when it cannot pay withdrawals from new deposits.
Madoff confessed to his sons on December 10, 2008. He told them the investment advisory business was a fraud. He said he intended to surrender to authorities in a week, after distributing approximately $300 million in remaining assets to employees, family, and select investors. [SOURCE: DOJ record / federal complaint]
His sons did not wait a week. They called their attorney that night. The next morning — December 11, 2008 — federal agents arrested Bernard Madoff at his New York apartment. He did not resist. He said he knew why they were there.
The arrest was quiet. Forty-eight years of the largest Ponzi scheme in history ended with a door opening and federal agents standing in a hallway.
The numbers are easier to state than what happened to the people.
On December 11, 2010 — exactly two years to the day after his father's arrest — Mark Madoff died by suicide. He was 46 years old. He had cooperated with authorities. He had turned his father in. He spent the two years following the arrest under public scrutiny, named in civil lawsuits as a consequence of bearing the Madoff name, separated from his family by the weight of what the name now meant. [SOURCE: widely documented from public record]
Andrew Madoff, Bernard's younger son, was diagnosed with mantle cell lymphoma in 2003 — before the arrest. He died on September 3, 2014, from that disease. He was 48 years old. Like his brother, he had turned his father in. He lived to see his father imprisoned but not to see the full legal proceedings conclude. [SOURCE: public record; widely documented]
Peter Madoff — the brother, the chief compliance officer — was sentenced to 10 years in federal prison. He cooperated with investigators. His daughter Shana, the compliance attorney, was not charged.
Ruth Madoff, Bernard's wife of 49 years, was not charged. She initially attempted to keep $70 million in assets. Under a settlement with prosecutors, she was permitted to keep $2.5 million. She has lived under the Madoff name since. [SOURCE: DOJ / SEC record]
The investors — the charities, the retirees, the foundations — rebuilt where they could and did not where they could not. The Irving Picard trustee appointed to recover assets eventually distributed billions to victims over more than a decade of litigation. The accounting is ongoing.
On June 29, 2009, Judge Denny Chin sentenced Bernard Lawrence Madoff to 150 years in federal prison.
It was the maximum. Prosecutors had asked for it. The victims who spoke at sentencing had asked for it. Judge Chin delivered it.
In the sentencing, Chin noted that the crimes were 'extraordinarily evil,' that Madoff had 'coldly and deliberately hurt thousands of people,' and that a severe sentence was required both for punishment and to send a message about the seriousness of financial fraud at this scale. [SOURCE: SDNY sentencing record, June 29, 2009]
Madoff spoke at sentencing. He apologised. He said he had lived for decades in fear and torment, that the pressure had been 'unbearable,' that he would live with the regret for the rest of his life. Whether any of this was true or performed, the victims present had no obligation to receive it as true, and most did not.
He was 71 years old at sentencing. The 150-year term was symbolic in the way that only mathematics makes something symbolic — he would serve the rest of his natural life regardless of the specific number. But the number mattered to the victims, who needed the court to say, in the language courts speak, that what had been done to them was of a scale and a deliberateness that required the maximum the law allowed.
He was housed at the Federal Medical Center in Butner, North Carolina — a facility for inmates with serious medical conditions. In 2020, his attorney requested compassionate release, stating that Madoff suffered from end-stage renal disease and other chronic conditions and had less than 18 months to live. The request was denied. Judge Chin noted that the criminal conduct went on for decades and he was caught only because the scheme unravelled — not because he stopped. [SOURCE: AP / Bureau of Prisons; court denial record]
The series argument sharpens here. and were both about visibility — the compulsion to display the crime, to have an audience for it, to post it, stream it, flex it into the public record.
Madoff was the opposite.
He did not display the fraud. He concealed it inside a respectable operation, surrounded it with credentials and family and institutional legitimacy, and then let time do the rest. Every year the scheme survived was a year that added credibility to it. Every consistent return was evidence, in the minds of the investors receiving it, that the returns were real. The longer it ran, the more impossible it became to question.
ran for nine years and built a brand that 2.5 million people followed. ran for fourteen months and spent faster than he could count. Madoff ran for 48 years and never once posted a photo of the money.
The mechanism of trust is what the Madoff case documents. Not the mechanism of deception — the mechanism of trust. How trust compounds over time. How a reputation, once established, becomes self-reinforcing. How institutions designed to check that trust can fail to do so for decades. How the very qualities that make someone trustworthy — consistency, patience, restraint, the refusal to make spectacular claims — can be the disguise.
Harry Markopolos told the SEC. Eight years of warnings. The scheme ran eight more years after the first one. That is not a story about one man's cleverness. It is a story about institutional failure at scale — the failure of the regulator, the failure of the auditor, the failure of the due diligence that sophisticated investors are supposed to perform and did not.
On April 14, 2021, Bernard Lawrence Madoff died at the Federal Medical Center in Butner, North Carolina.
He was 82 years old. Cause of death: hypertension caused by heart and kidney disease. [SOURCE: Associated Press / Bureau of Prisons confirmation, April 14, 2021]
He had been imprisoned for twelve years. He died having served approximately 8% of his 150-year sentence — which was the entirety of his remaining life, as the mathematics of the sentence had always intended.
His attorney had tried to get him out in 2020. The court denied it. Judge Chin's words at the denial: he was caught only because his scheme began to unravel with the financial crisis, when he was unable to keep up with the increasing requests for redemptions. He had not stopped. He had been stopped.
Mark was already gone. Andrew was already gone. Peter had served his time. Ruth was living under what the name now meant.
The victims were still in court. The Picard trustee was still recovering assets. The foundations that had lost their endowments were still trying to rebuild. The accounting that a 48-year scheme produces does not resolve quickly, and it does not resolve completely. Some losses are permanent.
He died in a federal medical facility in North Carolina. Not in the apartment on the Upper East Side. Not at the Palm Beach house. Not in the French Alps property his firm had paid for. In a federal medical facility, from kidney disease, at 82, with a 150-year sentence that had always been a statement rather than a calculation.
Three figures, three meanings: $64.8B (fabricated account value), $50B (Madoff's own liability statement), $170.8B (forfeiture ordered). Do not conflate them. Markopolos warning timeline verified from public record. Andrew Madoff death (September 2014, lymphoma) verified from public record. Mark Madoff death (December 11, 2010) verified from public record — handled in the text with appropriate weight.
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
THE PEOPLE AROUND THE LEDGER
WHERE THE MONEY WENT
CASE TIMELINE
HOW IT WORKED
HOW THE BOOKS WERE COOKED — DEFENSIVE LEVEL
WHAT THIS CASE ESTABLISHED
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE LEDGER (1,000 WORDS)
The fraud was a filing decision.
WorldCom paid other telecommunications carriers to use their networks — a cost called 'line costs.' Line costs are expenses. They reduce profit. If a company is under pressure to hit a quarterly earnings target, line costs are the number standing between the reported result and the target.
The accounting decision, as the DOJ and SEC later established, was to book those expenses as capital expenditure — turning operating costs into investments spread across future years. This transformed losses into reported profits. Nobody moved money to an offshore account. Nobody invented a product that did not exist. The fraud was entries in a spreadsheet — line costs, classified as capital expenditure, quarter after quarter.
The entries added up to approximately $11 billion in overstated earnings. When they were found — by an internal auditor named Cynthia Cooper who refused to stop asking questions — the company was already insolvent. [SOURCE: DOJ; SEC; widely reported from trial record]
On July 21, 2002, WorldCom filed for bankruptcy — then the largest in US history, with assets of approximately $107 billion. Approximately 30,000 people lost their jobs. Employees who held WorldCom stock in retirement accounts saw it fall to nothing. [SOURCE: DOJ; widely reported]
Bernard John Ebbers was born August 27, 1941, in Edmonton, Alberta, Canada. He co-founded LDDS — Long Distance Discount Service — in 1983. Through a series of acquisitions across the 1990s, most significantly the 1998 acquisition of MCI (then America's second-largest long-distance carrier), LDDS became WorldCom and WorldCom became a major force in telecommunications.
At its peak, WorldCom had a market capitalisation of approximately $180 billion. It was America's second-largest long-distance carrier, a major data and internet provider, and — to Wall Street — a model of the new communications economy. Ebbers was its face: a physically imposing, folksy CEO who drove pickup trucks and wore cowboy boots.
The pressure to sustain the stock price of a $180 billion company was the context in which the fraud began. Quarter after quarter, the company had to hit its numbers. When the numbers could not be hit legitimately, they were made to appear hit through accounting.
The fraud was operated primarily by Scott Sullivan, WorldCom's CFO, who pleaded guilty and cooperated with prosecutors. The prosecution's theory: Ebbers set the targets and created the culture of pressure; Sullivan made the accounting decisions to meet those targets. The entries reclassified 'line costs' — fees paid to other carriers for network access — as capital expenditure.
This is called capitalisation of operating expenses. Some expenses can legitimately be capitalised when they produce long-lived assets. Line costs do not qualify — they are purely operating costs that reduce the current period's profit. Reclassifying them as capital expenditure hid them from the profit-and-loss statement and put them on the balance sheet as assets instead.
The result: a company that was losing money appeared to be making money. Quarter after quarter, from approximately 1999 to 2002, for a total overstatement of approximately $11 billion. Analysts had targets. The targets appeared to be met. The stock held.
Cynthia Cooper, vice president of internal audit, discovered the fraud in 2002. She and her team worked nights and weekends, avoiding advance notice to senior management, tracing entries back to their source. When she brought the findings to the audit committee in June 2002, the company had no survivable path. The bankruptcy filing came July 21, 2002.
Ebbers' defence was that he was not an accountant. That he had trusted his CFO. That he had not known the specific entries were being made. The prosecution's theory was different: he had set the targets, maintained the pressure, and received fabricated results, knowing or recklessly disregarding that they could not be legitimate.
The jury found the prosecution's theory compelling. Ebbers was convicted on all counts in March 2005 — securities fraud, conspiracy, and seven counts of false regulatory filings. He was sentenced to 25 years in federal prison in July 2005.
The appellate courts upheld the conviction through multiple rounds of appeal.
In December 2019, after serving about 13 years, Ebbers was released on compassionate grounds: Judge Valerie Caproni ordered it on 18 December and he walked out on 21 December. He was 78, legally blind and in failing health. He died on February 2, 2020 — approximately six weeks after release.
Approximately 30,000 WorldCom employees lost their jobs when the company entered bankruptcy. Many held WorldCom stock in their 401(k) retirement accounts — accounts the company had encouraged them to concentrate in WorldCom equity. When the stock went to nothing, those accounts went with it. People who had worked for decades lost their retirement savings. [SOURCE: widely reported from congressional testimony and DOJ record]
The legislative response was Sarbanes-Oxley — the Public Company Accounting Reform and Investor Protection Act, signed July 30, 2002. It required CEOs and CFOs to personally certify the accuracy of financial statements, imposed criminal penalties for false certifications, strengthened audit committee independence, and mandated enhanced internal controls. The corporate governance regime governing US public companies today was substantially shaped by WorldCom. [SOURCE: Sarbanes-Oxley Act, 2002]
The biggest accounting fraud in US history was a filing decision. Repeated.
SOURCES
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
THE BANKS THAT HELD THE PIECES
CASE TIMELINE
HOW IT WORKED
HOW THE EXPOSURE WAS HIDDEN — DEFENSIVE LEVEL
WHAT THIS CASE ESTABLISHED
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE TOTAL PICTURE (1,300 WORDS)
In March 2021, several of the world's largest banks received margin calls on positions they had built for a family office called Archegos Capital Management. Each bank had lent the family office exposure to the same stocks — large, concentrated positions in a handful of companies. When those stocks fell, the banks were forced to liquidate. Because several of them were liquidating the same names at the same time, the selling accelerated the decline. The losses were counted in ten places.
The largest single loss: Credit Suisse, approximately $5.5 billion. Nomura: approximately $2 billion. Morgan Stanley: approximately $1 billion. UBS and Mizuho: hundreds of millions each. The total across all counterparties: approximately $10 billion. [SOURCE: Reuters/Bloomberg/FT; per-bank disclosures — verify exact figures before publication]
Bill Hwang, the founder of Archegos, had used a financial instrument called a total-return swap — a derivative that gave him the economic exposure to a stock's performance without owning the stock directly. The bank owned the shares; Hwang received the returns or absorbed the losses. The arrangement allowed him to build enormous, concentrated positions across multiple banks simultaneously, with each bank seeing only its own piece. None of them could see the total.
That is the whole case. The positions were enormous — a notional market value that prosecutors described as exceeding $100 billion. The exposure was concealed — not through one hidden account but through the structure of the swaps and the fact that no institution had a consolidated view. When it unwound, the losses cascaded. And one bank did not survive it in recognizable form.
Archegos Capital Management was a family office — a vehicle that manages the personal wealth of a single family, without outside investors. This structure carries significantly lighter regulatory disclosure obligations than a hedge fund or investment manager with outside clients. A family office is not required to report its positions to the SEC in the same way a fund manager is. The structure was not illegal; it was a permission slip.
Hwang had managed outside money before. Tiger Asia, his hedge fund, was a protégé operation from the Tiger Management network founded by Julian Robertson. In 2012, Tiger Asia settled insider-trading charges with the DOJ and SEC for approximately $60 million and agreed to return outside capital. Hwang subsequently converted the operation into Archegos — a family office, managing only his own money, operating with less transparency. [SOURCE: SEC/DOJ 2012 settlement; public record]
The total-return swap is a legitimate instrument: a bank buys shares, a client pays a fee and receives the economic return on those shares (or absorbs the loss). The swap allows leverage — the client can control a large position with a smaller cash outlay — and because the bank holds the shares, the client's position is not visible in public stock-ownership filings. Used across multiple banks for the same underlying stocks, the aggregate exposure is invisible to any single counterparty.
This is what the DOJ and SEC allege Hwang did: he built concentrated positions in a small number of stocks — ViacomCBS, Discovery, GSX Techedu, and others — through swaps with approximately ten banks. Each bank understood it had its own exposure. None knew the others' exposures. The banks' individual risk models did not flag what the aggregate model would have found: a single actor with enormous, undisclosed, concentrated leverage in the same names across their entire counterparty roster.
The event that triggered it was a stock offering. ViacomCBS announced a share offering in March 2021. The share price began to fall. Archegos's positions — largely in ViacomCBS and Discovery — came under pressure. Margin calls arrived from the banks.
Archegos could not meet them. The banks began liquidating. Because multiple banks were selling the same stocks at the same time — all of them holding concentrated positions in the same names for the same client — the selling pressure was self-reinforcing. The stocks fell further. The margin calls increased. The positions unwound over days.
Credit Suisse was the bank most severely exposed. Its loss of approximately $5.5 billion from the Archegos collapse was the largest single counterparty loss from the event and represented a significant fraction of its total equity. Credit Suisse had been weakened by several concurrent events in early 2021 — including its exposure to the Greensill Capital collapse — and the Archegos losses compounded an already fragile situation. [SOURCE: Credit Suisse disclosure; FT/Bloomberg]
Credit Suisse did not recover. In March 2023 — two years after the Archegos collapse — it required emergency intervention from the Swiss National Bank, and was taken over in a government-brokered rescue merger by UBS. Multiple investigations attributed the Archegos losses as a contributing factor to the bank's deterioration. A family office had contributed to the end of one of the oldest banks in Switzerland. [SOURCE: Bloomberg; FT; Reuters 2023]
Hwang was charged in April 2022 by the SDNY on 11 counts: one of racketeering conspiracy, three of fraud and seven of market manipulation. The government's case: Hwang and associates concealed Archegos's true exposure from counterparty banks, and separately manipulated the prices of the stocks Archegos held — pumping prices through coordinated buying to maintain the inflated values that justified keeping the positions open.
The jury convicted him on 10 of the 11 counts on July 10, 2024, acquitting him on one market-manipulation count. Judge Alvin Hellerstein sentenced him to 18 years in federal prison on November 20, 2024. He is currently free on bail pending appeal. He has not reported to prison. [SOURCE: DOJ July 2024; DOJ/court November 2024; Reuters]
The governance lesson the case teaches is the same as Leeson (), scaled to the modern global banking system: a control that is siloed is not a control. Leeson's losses were visible to nobody because he controlled both the trading and the back office. Hwang's exposure was visible to nobody because each bank held a fragment it could not see the aggregate of. The mechanism of failure is identical — the person taking the risk is also, in effect, the person recording it, because no external party has the consolidated picture.
The series' thesis about governance — that the check must be independent of the party it checks, and must have the complete picture — is proven here, at the scale of ten global prime brokers and $10 billion in losses.
SOURCES
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
THE PEOPLE AND THE PLATFORM
BY NUMBER OF VICTIMS
CASE TIMELINE
HOW IT WORKED
HOW EZUBAO WORKED — DEFENSIVE LEVEL
WHAT THIS CASE ESTABLISHED
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE NINE HUNDRED THOUSAND (1,400 WORDS)
Madoff () defrauded approximately 37,000 investors. That figure appears throughout his case file as a marker of scale.
Ding Ning's Ezubao operation is estimated to have defrauded approximately 900,000 investors — twenty-four times that number. By the official victim count, it is one of the largest Ponzi schemes ever recorded. [SOURCE: Chinese state media / official court record]
The platform raised 59.8 billion yuan — approximately $9 billion at 2015-2016 exchange rates — through a peer-to-peer lending operation that ran from 2014 to December 2015. Most of the investment projects listed on the platform were fabricated. Investors were promised returns of 9 to 14.6 percent annually. The money that came in was used to pay the returns of earlier investors — the Ponzi cycle — and to fund a lifestyle of extraordinary personal extravagance that included gifts such as a pink diamond ring reportedly worth 12 million yuan and a Singapore villa worth 130 million yuan for the company's president, Zhang Min. [SOURCE: CBS; Chinese state media]
In December 2015 Chinese police moved on Ezubao; 21 people, including Ding Ning, were formally arrested in January 2016. On 12 September 2017 a Beijing court sentenced him to life imprisonment and a fine of 100 million yuan. His brother Ding Dian also received life; 24 other defendants received 3 to 15 years.
Peer-to-peer lending — P2P — was one of the fastest-growing financial sectors in China between 2012 and 2018. The model: an online platform connects borrowers who need capital with investors who want returns. The platform takes a fee. The investor gets interest from the borrower.
The appeal in China was specific to the moment. Traditional Chinese banks channeled credit primarily to state-owned enterprises and large corporations. Small businesses and individuals struggled to access loans. Retail investors, simultaneously, had limited high-yield options — bank deposit rates were low, the stock market volatile. P2P platforms offered both sides of this equation a solution: borrowers could get capital, investors could earn 9 to 15 percent. Thousands of platforms emerged.
Regulation was minimal and slow to develop. The industry grew faster than oversight could follow. At its peak, there were estimated to be over 3,000 active P2P lending platforms in China. Most were legitimate. Some were not. Ezubao, operated by Anhui Yucheng Holdings Group under Ding Ning's leadership, was the largest and the most fraudulent.
Ezubao launched in 2014. Within a year it had grown to one of the country's largest P2P platforms by volume, attracting investors with promises of returns between 9 and 14.6 percent annually. The platform appeared to be matching investors with real financing projects — equipment leasing, infrastructure loans, business credit. Most of these projects, per the prosecution, were fictional. Ding Ning's company created fake project listings to give investors the appearance of understandable, specific investments.
The prosecution established that approximately 95 percent of Ezubao's listed investment projects were fabricated. [SOURCE: Chinese state media citing prosecution; Reuters — verify exact percentage and its source]
The mechanism was a classic Ponzi: early investors received their promised returns, funded by the influx of new investor capital rather than by real investment returns. The platform appeared healthy and transparent. Its marketing emphasized the specific, real-world nature of its lending — names, addresses, and details for projects that did not exist.
The scale of personal enrichment was also documented in the prosecution: Ding Ning spent hundreds of millions of yuan on luxury goods, real estate, and personal expenses. Chinese state media reported that he spent more than 1 billion yuan on gifts, including 550 million yuan in cash, a Singapore villa and a 12 million yuan pink diamond ring for Zhang Min, president of Yucheng Global. He and his family received hundreds of millions in transfers from the Ezubao operation. [SOURCE: Chinese state media — treat as official prosecution account]
The collapse came in December 2015 when police moved in; 21 people were formally arrested in January 2016. Investigators later dug up about 1,200 documents, in 80 bags, buried six metres underground outside Hefei. The platform froze and hundreds of thousands of investors could not access their funds. The human consequence was severe — many investors had placed life savings, retirement funds, or borrowed money into the platform. Reports at the time documented protests outside government buildings in multiple cities by investors demanding their money back.
Every other Ponzi case in this series involves a relatively contained investor group: Madoff's clients were wealthy individuals and institutions. Stanford's () were CD buyers. at least targeted people with some financial sophistication.
Ding Ning's victims were mass market. P2P platforms in China targeted ordinary wage earners who were depositing small amounts — some as little as a few hundred yuan — into what they understood to be supervised investment products. The ~900,000 investor count reflects that reality. It is not 900,000 sophisticated investors who should have known better. It is ordinary people who had few alternatives and trusted a regulated-looking online platform.
This is the Ponzi case where the victim count is the thesis. In every other case in this series — Madoff, Stanford, Ponzi himself — the dollar figure is the defining number. Ezubao's dollar figure (~$9 billion) is significant but comparable to Stanford ($7.2 billion). The victim count is not comparable to anything else. It is the largest in history.
On 12 September 2017, the Beijing No. 1 Intermediate People's Court sentenced Ding Ning to life imprisonment and a 100 million yuan fine; he was also convicted of illegally possessing guns and smuggling precious metals. His brother Ding Dian received life and a 70 million yuan fine. 24 other defendants received 3 to 15 years. The court put the fraud at more than 50 billion yuan from about 900,000 investors. [SOURCE: Reuters; Xinhua — verify exact sentencing date and court]
The prosecution was the highest-profile output of China's crackdown on P2P lending fraud. The broader P2P collapse — thousands of platforms failing between 2016 and 2020 — generated additional prosecutions across the country, but none reached the scale of Ezubao.
By 2020, the Chinese government had effectively closed or converted the entire P2P lending sector. Every platform operating in the space was required to either obtain a banking licence — a bar very few could meet — or shut down. The regulatory response was total: an entire financial sector was eliminated as a consequence, in part, of what Ding Ning had done to the most visible platform in it.
The investor recovery was limited. The assets Ding Ning and his co-defendants accumulated were seized and distributed through a restitution process, but the amounts recovered represent a fraction of what investors lost. The gap between the fraud's scale and the recovery is the usual story of a Ponzi — by the time the scheme collapses, most of the money is gone.
SOURCES
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
HOW THE FRAUD WORKED
THE MECHANISM — CUSTOMER FUNDS TO ALAMEDA
NETWORK & CO-CONSPIRATORS
JUDGE KAPLAN — SENTENCING MARCH 28 2024
FROM THE BENCH
CASE TIMELINE
WHAT THIS CASE ESTABLISHED
THE FULL STORY — 10 CHAPTERS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — “FTX IS FINE” (3,600 WORDS)
On November 7, 2022, as the collapse of his empire began in earnest, Sam Bankman-Fried posted on Twitter.
Four days later, on November 11, 2022, FTX filed for bankruptcy. The exchange had run out of money after customers tried to withdraw approximately $6 billion in 72 hours and discovered the funds were not there. [SOURCE: Axios/Reuters collapse timeline]
The assets were not fine. The assets were in Alameda Research, the connected trading firm that had been using FTX customer deposits to cover its own losses, service its own obligations, and fund the lifestyle of an operation that had purchased at least 19 properties in the Bahamas worth $121 million while its CEO slept on a beanbag and told the world he didn't care about material things. [SOURCE: Fortune, November 2022; DOJ trial record]
Samuel Benjamin Bankman-Fried — SBF, to everyone who followed him — had been the person the cryptocurrency industry most wanted to believe was the good one. He was MIT, Jane Street, effective altruism, the beanbag, the cargo shorts, the billions pledged to charity. He was the billionaire who made you think maybe the whole thing was serious after all.
He was convicted by a unanimous jury in November 2023 on all seven counts of fraud, conspiracy, and money laundering. He was sentenced to 25 years. His appeal was denied. He is serving time at a federal prison in California. He is eligible for release in 2044.
Samuel Benjamin Bankman-Fried was born on March 6, 1992, at the hospital on the campus of Stanford University in California.
His parents, Joseph Bankman and Barbara Fried, were — and remain — law professors at Stanford Law School. He was, quite literally from birth, inside the academic establishment that produces the credentialed elite of American professional life. The family is not incidental background. The family is the foundation of every door that opened.
He attended the Massachusetts Institute of Technology, where he studied physics. He has said he chose MIT over Caltech by flipping a coin. [SOURCE: Fortune trial timeline] He majored in physics and minored in mathematics. He was less interested in his classes, by his own account, than in spending time in the Epsilon Theta fraternity — a group whose members would later include several future FTX employees, among them co-founder Gary Wang.
At MIT he also encountered effective altruism — the philosophical framework developed in part by William MacAskill that holds that the right way to do good in the world is to reason carefully about which interventions produce the most benefit per dollar and direct your money and energy accordingly. One strand of effective altruism, called 'earning to give,' holds that someone capable of earning large amounts in finance should do so and donate most of the proceeds, rather than taking lower-paying work directly in the nonprofit sector.
Bankman-Fried found this argument compelling. He graduated in 2014 and took a job at Jane Street Capital — the quantitative trading firm — and reportedly gave away half his salary. [SOURCE: biography.com citing multiple sources] He had not yet made much money. He was already planning what he would do when he did.
The effective altruism framing was the most important thing about Sam Bankman-Fried that was not about money. It was the thing that made the money story different.
Most people who get rich in finance are not particularly interesting to the public as moral characters. They make money, they spend money, they give some of it away. The story is familiar enough to be unremarkable.
Bankman-Fried's story was different because the explicit, loudly-stated purpose of making money was to give it away. He had taken a philosophical position — not vaguely charitable, but specifically reasoned — that the highest use of his capabilities was to earn as much as possible in order to donate as effectively as possible to causes that reduced the most suffering. He had committed to giving away his entire wealth. He had signed the Giving What We Can pledge. He talked about pandemic prevention and animal welfare and the long-term future of humanity.
He also dressed badly. The T-shirts and cargo shorts and uncombed hair were not an accident. They were a signal: I am not doing this for the lifestyle. I do not care about the markers of success. I am accumulating money as a tool, not as an end.
He slept on a beanbag at the office. He took investor meetings while playing video games. He was vegan. He occasionally cooked vegan meals for the ten FTX employees who lived with him in the Bahamas penthouse that the company had purchased for $30 million. [SOURCE: Fortune / biography.com] The beanbag and the penthouse coexisted without apparent discomfort, because the penthouse was framed as a business necessity and the beanbag was the real him.
The effective altruism community celebrated him. He was profiled in magazines as proof that the framework produced good actors. He was the case study that 80,000 Hours and similar organisations pointed to when people asked whether 'earning to give' was a viable path to doing good. He donated $5 million to Joe Biden's 2020 presidential campaign. He donated approximately $40 million to Democratic politicians in the 2022 midterms, making him one of the largest political donors in the party. He said he had given similar sums to Republicans through dark money, because he feared liberal backlash. [SOURCE: biography.com; widely documented]
He was also — prosecutors at trial alleged, and a jury agreed — directing the misappropriation of $8 billion in customer funds into a trading firm that he controlled, while telling the world the exchange was fine.
He left Jane Street in 2017. He worked briefly at the Centre for Effective Altruism as development director. Then he started trading Bitcoin.
The opportunity he spotted was arbitrage — the same coin trading at different prices on different exchanges in different countries. In Japan, Bitcoin was trading for roughly 10% more than it was elsewhere. If you could buy it cheaply, move it to Japan, and sell it there, the margin was significant. Within months, Alameda Research — the quantitative trading firm he co-founded — was at times making approximately a million dollars a day. [SOURCE: Encyclopaedia Britannica; Cointelegraph]
He founded FTX in April 2019 with Gary Wang, his MIT fraternity housemate, as co-founder. The exchange launched the following month. FTX was built to be better than the existing crypto exchanges — more sophisticated derivatives products, a cleaner interface, better risk management. It signed naming rights to the Miami Heat's arena in a deal reportedly worth $135 million. [SOURCE: Al Jazeera timeline] Tom Brady and Gisele Bundchen appeared in its advertising. In July 2021, it raised $900 million at an $18 billion valuation. In January 2022, it raised $400 million at $32 billion. [SOURCE: Al Jazeera / Axios timelines]
By 2021, Forbes had named Bankman-Fried the richest person under 30 in the world, with a net worth of approximately $22.5 billion. By the peak it was $26.5 billion. [SOURCE: Forbes / Effective Altruism Forum]
He moved operations to Hong Kong, then in 2021 to the Bahamas. The Bahamas offered a tax environment and a regulatory posture that suited his purposes. He and his colleagues purchased at least 19 properties in the country worth approximately $121 million in total. [SOURCE: Fortune, November 2022] He lived in a $30 million penthouse at the Albany resort compound — a 600-acre property on New Providence island that had hosted Tiger Woods and Justin Timberlake at its grand opening and sold individual homes for tens of millions.
Ten FTX employees lived in the penthouse. One of them was .
The brief for this case contains an explicit instruction: must be covered in full detail. She ran Alameda Research, she was his girlfriend, and she was the prosecution's key witness. That is not a side note. This is that section.
was born in November 1994 in Boston, Massachusetts. Her parents — Glenn Ellison and Sara Fisher Ellison — are both MIT economics professors. Like Bankman-Fried, she did not come from nowhere. She came from a household where quantitative economic reasoning was the intellectual medium of daily life.
She attended Stanford University. She then went to Jane Street Capital — the same firm where Bankman-Fried had worked, and where the two had met. This is where she built the trading skills she would later bring to Alameda.
Bankman-Fried persuaded her to join Alameda Research. She was, like him, attracted to the effective altruism framing — the idea that they were earning money in order to give it away to causes that mattered. She rose to become co-CEO of Alameda in 2021. When her co-CEO Sam Trabucco stepped down in August 2022 — three months before the collapse — she became sole CEO.
She and Bankman-Fried were romantically involved. On and off, across years. They lived in the Bahamas penthouse together. The relationship was not beside the work. It was inside it. She ran the firm he had founded. He was, per the DOJ's own sentencing letter, exercising the real control while she held the nominal title of CEO. [SOURCE: DOJ sentencing letter, September 17, 2024]
She directed the use of FTX customer funds to cover Alameda's losses and obligations. She knew the real balance sheet. She knew the gap between what the public statements said and what the numbers actually showed. That knowledge — of the mechanics and the reasoning and the decisions — is what made her testimony at trial decisive.
When FTX collapsed in November 2022 and the federal investigation began, she started speaking to the government before she was charged. She pleaded guilty in December 2022, immediately. She underwent extensive document review. She helped identify evidence in an investigation that was, in the government's words, 'hamstrung by Bankman-Fried's systematic destruction of evidence.' [SOURCE: DOJ sentencing letter, September 17, 2024]
He responded by leaking her private personal writings to the press while they were both facing charges. A federal judge found that this likely amounted to witness tampering and revoked his bail. [SOURCE: Yahoo News / Fortune reporting on the bail revocation] The government's sentencing letter states that she 'persevered despite harsh media and public scrutiny and Bankman-Fried's efforts to publicly weaponize her personal writings to discredit and intimidate her.' [SOURCE: DOJ sentencing letter, September 17, 2024]
She testified in open court in October 2023 and named him. She described what he had directed. She explained the why — the decisions, the reasoning, the conversations. The jury convicted on all seven counts.
On September 24, 2024, Judge Kaplan sentenced her to two years in federal prison. She was tearful in the courtroom. [SOURCE: AP News, September 24, 2024] She was ordered to forfeit $11 billion — a legal forfeiture figure, not a personal theft amount. She has been released.
Bankman-Fried was sentenced to 25 years. Ellison to 2 years. The cooperation credit was 23 years.
The mechanism is simple to state and catastrophic in consequence.
FTX was a cryptocurrency exchange. When customers deposited money on FTX, that money was supposed to sit in FTX's custody — available for trading, available for withdrawal. It was customer money. The exchange held it on their behalf.
Alameda Research was a connected trading firm founded and controlled by Bankman-Fried. It made speculative bets in cryptocurrency markets. A trading firm is not supposed to have access to an exchange's customer deposits. The two entities are supposed to be entirely separate.
At FTX, they were not separate. Alameda borrowed from the FTX customer pool — billions of dollars, used for speculative investments, for political donations, for expensive real estate in the Bahamas, for loans to executives, for obligations the trading firm could not otherwise meet. [SOURCE: Second Circuit opinion, June 12, 2026; DOJ trial record]
The public-facing balance sheets showed a different picture. Investors and customers saw statements that did not reflect the reality of where their money was. When crypto markets fell in 2022 and Alameda's speculative positions lost value, the customer deposits it had been using as a backstop were insufficient. When customers tried to withdraw from FTX, the money was not there.
The new CEO appointed after the bankruptcy — John J. Ray III, who had overseen the Enron bankruptcy — said in a court filing: 'Never in my career have I seen such a complete failure of corporate controls and such a complete absence of trustworthy financial information as occurred here.' [SOURCE: People Matters / court filing, November 2022]
Ray had supervised one of the most notorious corporate collapses in American history. He had not seen anything like this.
It took nine days to end it.
Nine days from the CoinDesk article to the bankruptcy filing. Three years of building — the exchange, the Bahamas empire, the effective altruism brand, the political donations, the magazine covers — collapsed in nine days when customers tried to take their money out and discovered it was not there.
He did not flee. Not right away. After the bankruptcy filing he remained in the Bahamas, giving interviews, posting online, texting journalists, attempting to articulate a version of events in which the collapse was a liquidity crisis rather than a fraud.
He was scheduled to testify before Congress on December 13, 2022. On December 12 — the day before — Bahamian authorities arrested him at the request of the US government, based on a sealed indictment filed by the Southern District of New York. [SOURCE: PBS / AP / SDNY statement]
He was extradited to the United States. He appeared before a federal court in Manhattan. He pleaded not guilty to the charges — wire fraud, securities fraud conspiracy, commodities fraud conspiracy, money laundering conspiracy, and related counts.
Gary Wang and had already pleaded guilty and begun cooperating. Nishad Singh, FTX's engineering director, also pleaded guilty and cooperated. [SOURCE: trial record; Second Circuit opinion]
While on bail, he was accused of sharing Ellison's private personal writings with a reporter, in what a federal judge found 'likely amounted to witness tampering.' His bail was revoked and he was held in pretrial detention. [SOURCE: Fortune / Yahoo News citing federal court record]
The trial opened in October 2023 before Judge Lewis A. Kaplan in the Southern District of New York.
Bankman-Fried's defense strategy was built around a single claim: he had not intended to defraud anyone. He believed FTX was solvent. He believed the customer funds could be returned. The things that went wrong went wrong because of market conditions and poor accounting, not because of fraudulent intent.
The prosecution's response was the people who were there.
Gary Wang, the co-founder who built the code, testified about how the system worked. Nishad Singh, the engineering director, testified about what he had witnessed. And , CEO of Alameda Research and Bankman-Fried's former girlfriend, testified about the decisions, the directions, the conversations, the reasoning. She told the court not just what had happened but why — which is the specific knowledge that only the person closest to the decision-maker possesses.
The government described her testimony as 'a cornerstone of the trial.' [SOURCE: DOJ sentencing letter on Ellison, September 17, 2024]
He testified in his own defense. He maintained he had not intended to defraud. The jury deliberated and returned a verdict.
November 2, 2023 — one year to the day after the CoinDesk balance sheet article — the jury convicted Samuel Bankman-Fried on all seven counts.
On March 28, 2024, Judge Lewis A. Kaplan sentenced Samuel Bankman-Fried to 25 years in federal prison.
Prosecutors sought 40 to 50 years. The defense sought 5 to 6.5 years. Judge Kaplan sentenced him to 25 — below what the prosecution asked for, and roughly four times what the defense asked for. [SOURCE: SDNY sentencing; widely documented]
Bankman-Fried spoke at sentencing. He expressed remorse. He maintained, through lawyers and directly, that he had not acted with the intent the fraud statute requires — that he had genuinely believed the customers could be made whole.
The Second Circuit addressed this directly when it affirmed his conviction in June 2026. Circuit Judge Barrington Parker wrote for the three-judge panel: 'FTX customers were defrauded as soon as Bankman-Fried transferred their money to Alameda regardless of how strongly he believed he might later return the money.' [SOURCE: Bloomberg / Second Circuit, No. 24-961-cr, June 12, 2026]
Temporary misappropriation is still fraud. The intended repayment is not a defence.
Each case in this series has a thesis. A single thing it documents about how fraud works at scale.
: the persona was the marketing. : the speed. : the product was the lie. Madoff: duration was the disguise. Sam Bankman-Fried: the trust of the smart.
He was not just trusted. He was trusted by the people who were most careful about trust. The institutional investors who did due diligence on him. The magazine editors who wrote about him. The effective altruism community that held him up as proof of concept. The senators who invited him to testify about crypto regulation. These were not naive people who simply believed what they were told. They were people who thought about credibility seriously and concluded that his was real.
The fraud ran inside that credibility. It ran inside MIT and Jane Street and the giving pledges and the beanbag and the cargo shorts. It ran inside the persona of the person who was doing this for the right reasons.
And it was exposed not by a regulator, not by an auditor, not by a sophisticated institutional investor who looked past the persona. It was exposed by a balance sheet that a journalist obtained and published. And it was prosecuted successfully because the people closest to him — his co-founder, his engineering director, the woman who ran his trading firm and had been his girlfriend — chose to tell the truth.
She told the truth despite him leaking her diary to the press to stop her. That is the last detail of the case that belongs here.
He is in California, eligible for release in 2044, having applied for a presidential pardon that the White House has signalled it will not grant. The effective altruism community that celebrated him has had to reckon with what he represented and what the framework was actually being used for. The $8 billion in customer funds is the subject of ongoing bankruptcy proceedings. Some customers may recover some of their money.
He broke the trust of the people who were most certain he was the good one. That is the sentence the case leaves behind, beyond the 25 years.
$8B = customer funds misappropriated (loss figure, DOJ/trial record). Different from the $11B forfeiture ordered against Ellison. Bankman-Fried: convicted, sentenced 25 years, appeal denied June 2026, serving California, eligible 2044. Ellison: cooperated, sentenced 2 years, released. Both are in the record. The cooperation credit is 23 years.
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
HER ROLE IN THE FRAUD
WHAT ELLISON DID — AND WHAT SHE SAID AT TRIAL
JUDGE KAPLAN — SENTENCING SEPTEMBER 24 2024
FROM THE BENCH
CASE TIMELINE
WHAT THIS CASE ESTABLISHED
CROSS-REFERENCE
CONNECTED CASE
and Case 006 are the same fraud, two different roles, two different choices. maintained his innocence, testified, and was convicted on all 7 counts. Ellison pleaded guilty immediately, cooperated fully, testified against him for three days, and served 14 months. The outcomes — 25 years vs 14 months — are the clearest illustration in this series of what cooperation means inside the federal sentencing system.
BIOGRAPHY & FULL CONTEXT
BACKGROUND
THE COOPERATION — EVERY DETAIL
THE 23-YEAR MATH
THE FULL STORY — 9 CHAPTERS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — SHE TESTIFIED ANYWAY (2,700 WORDS)
She was the only person who could explain the why.
Not the what — the mechanics of how FTX customer funds moved to Alameda Research could eventually be reconstructed from the code, the financial records, the blockchain. Not the how — the documents and digital trail, even the ones had allegedly destroyed, could be recovered with forensic effort. The what and the how were things investigators could, in principle, piece together from evidence.
The why required her.
She had run his firm. She had been his girlfriend. She had sat in the rooms where the decisions were made and understood the reasoning — what he had believed, what he had decided not to believe, what he had said and done when the math started not adding up. She was, in the government's precise phrase, 'uniquely positioned to explain not only the what and how of 's crimes, but also the why.' [SOURCE: DOJ sentencing letter, September 17, 2024]
She pleaded guilty in December 2022 — immediately, before the year was out. She began cooperating before she was charged. She testified in open court in October 2023 and named him. She told the court everything she knew.
While she was preparing to testify, he leaked her private diary to a reporter.
She testified anyway.
Caroline Ellison was born in November 1994 in Boston, Massachusetts.
Her parents are Glenn Ellison and Sara Fisher Ellison — both professors of economics at MIT. [SOURCE: CNBC / Reuters / case brief] The family is not background detail. It is essential context. She grew up in a household where quantitative economic reasoning was the medium of daily intellectual life. Where the way you evaluated a claim was to ask what the evidence showed and how the mechanism worked. Where rigour was a household value before it was a professional one.
She attended Stanford University for her undergraduate degree. From Stanford she went directly to Jane Street Capital — the elite quantitative trading firm that has a specific kind of reputation in financial circles: selective, sophisticated, producing people who are exceptionally good at a particular kind of numerical reasoning under uncertainty. It is where had also worked. It is where the two of them met.
She was drawn to the effective altruism framework that and others in their circle subscribed to — the idea that the right way to do the most good in the world was to earn as much as possible and donate it as effectively as possible to causes that reduced the most suffering. As a fellow effective altruist, she was attracted to the prospect of earning money in order to give it to charity. [SOURCE: Yahoo News / Fortune]
He persuaded her to join Alameda Research, the quantitative cryptocurrency trading firm he had founded in 2017. She did. She rose through the organisation. She became co-CEO of Alameda in 2021. When her co-CEO Sam Trabucco stepped down in August 2022 — three months before the collapse — she became sole CEO.
She was 28 years old when FTX filed for bankruptcy. She was 28 when she pleaded guilty. She was 28 when she testified. She was 29 when she was sentenced. She is 31 now.
The relationship between Caroline Ellison and was not beside the operation. It was inside it.
They had met at Jane Street. He recruited her to Alameda. She ran the firm he had founded. He founded and ran the exchange, FTX, that the firm he had founded was secretly borrowing from. They lived together in the Bahamas — in the $30 million penthouse at the Albany compound on New Providence island where and ten FTX colleagues lived and worked. [SOURCE: Fortune / biography.com]
The romantic relationship was on and off across years — from approximately 2018 until mid-2022, in the period before the collapse. [SOURCE: biography.com; Yahoo News] It was, throughout, concurrent with the professional relationship: she ran his firm, he ran the empire, and the two companies they each led were secretly entangled in a way that would eventually consume both of them.
The DOJ's sentencing letter describes her as Alameda's 'nominal CEO' — the government's own language establishing that while she held the CEO title, the decision-making authority ran to . [SOURCE: DOJ sentencing letter, September 17, 2024] That distinction is part of her legal record, part of her cooperation, and part of the context of the relationship. She ran the firm. He controlled it.
She was, before the collapse, unhappy. The New York Times published an article in July 2022 — based on her personal writings — in which she described feeling 'unhappy and overwhelmed' at work and 'hurt/rejected' by a breakup with . [SOURCE: Yahoo News citing NYT]
Those writings would become the instrument he used against her.
Alameda Research was the vehicle through which FTX customer deposits were misappropriated. She ran Alameda Research.
Customer funds deposited on FTX — the exchange — were used by Alameda to cover the trading firm's losses, service its obligations, and fund an operation that included expensive real estate in the Bahamas, speculative investment positions, and political donations. The two entities were not kept separate as they were supposed to be. [SOURCE: DOJ trial record; Second Circuit opinion, June 2026]
She directed the use of customer funds to cover Alameda's losses and obligations. She knew the real balance sheet — the one that showed the true state of things — while the public-facing disclosures said something different. That gap between private knowledge and public statement is the core of the fraud she participated in.
The government's sentencing letter is precise about this: she was 'forthcoming about her own grave misconduct and the role she played in furthering 's scheme and its concealment.' [SOURCE: DOJ sentencing letter, September 17, 2024]
Grave misconduct. That is the government's language. She committed it. That is in the record and it belongs in this piece. So is the full context of what she did with that record when the operation ended.
When FTX collapsed in November 2022 and the federal investigation began, Caroline Ellison started talking to the government.
Not after her lawyer negotiated a deal. Not after she understood the full scope of what she was facing. Before she was charged. [SOURCE: DOJ sentencing letter, September 17, 2024 — stated directly in the filing]
She was charged in December 2022 with seven counts: wire fraud, securities fraud, money laundering conspiracy, and related charges. She pleaded guilty the same month. Immediately. She did not contest the charges. She did not seek to litigate the facts. She said she had done what the government said she had done and began helping them build the case.
Over the months that followed, she participated in what the government described as extensive document review — work that identified key corroborating evidence in an investigation that had been hamstrung by 's systematic destruction of evidence. He had tried to eliminate the record. She helped reconstruct it. [SOURCE: DOJ sentencing letter, September 17, 2024]
Her statements during the cooperation were, the government noted, 'notably consistent' with what she had said during the collapse of FTX — before she had any reason to believe she was being investigated. She had not changed her story to fit a plea deal. Her account of what had happened was the same before and after the federal investigation began. [SOURCE: DOJ sentencing letter]
While Caroline Ellison was cooperating with federal investigators and preparing to testify against , he leaked her private personal writings to a reporter.
The New York Times published an article in July 2022 — before the collapse — based on her personal writings in which she described feeling unhappy and overwhelmed at work. [SOURCE: Yahoo News citing NYT, July 2022] Those writings were personal. They were not intended for publication.
After the collapse, after the charges, after she had pleaded guilty and was cooperating with the government, allegedly shared her personal writings with a reporter — this time to try to damage her credibility as a witness. A federal judge found that this action 'likely amounted to witness tampering' and revoked his bail. He was held in pretrial detention for the remainder of the pre-trial period. [SOURCE: Yahoo News / Fortune, citing federal court record]
The government's sentencing letter to Judge Kaplan addresses this directly.
This piece does not quote her private writings. It will not. The government's own filing documents that those writings were weaponised against her. Quoting them would repeat that act. What this piece reports is that he did it, that a federal judge found it was likely witness tampering, that it was documented in a government filing, and that she testified anyway.
She was publicly humiliated with her own words. By the man she had loved. By the man she had worked for. By the man she was about to testify against in open federal court. He did it while facing the same charges she did.
She went to court and named him anyway.
On October 10, 2023, Caroline Ellison took the stand in the trial of in the Southern District of New York.
She testified about the mechanics of what had happened — how Alameda had used FTX customer funds, how the balance sheets had been constructed, how the gap between the private reality and the public statements had been maintained. She provided the kind of granular, first-hand account of decisions and conversations and reasoning that only someone who was there and paying attention could provide.
She also testified about the relationship. About the conversations between her and . About what he had known, what he had directed, what he had said when things were going wrong. The government had called her 'uniquely positioned' to explain the why — and that uniqueness rested on the fact that she had been both his closest professional partner and his romantic partner. She knew the public man and the private one. She knew what he said in the rooms that mattered.
She testified for multiple days. She was cross-examined by his defense lawyers. She held to her account.
The jury convicted on all seven counts on November 2, 2023 — one year to the day after the CoinDesk balance sheet article that had started the collapse.
On September 24, 2024, Caroline Ellison stood before Judge Lewis A. Kaplan in the Southern District of New York.
She was tearful. The AP's headline: 'Tearful Caroline Ellison gets 2 years in prison over her role in FTX fraud.' [SOURCE: AP News, September 24, 2024]
Her parents had written to the judge ahead of sentencing — Glenn Ellison and Sara Fisher Ellison, both MIT economics professors, writing on behalf of their daughter. The New York Times published the letter. [SOURCE: NYT — verify contents before quoting directly]
She spoke to the court. She expressed remorse. The government's letter had already described her as showing 'remarkable candor, remorse, and seriousness' throughout the cooperation period.
The government's sentencing letter to Judge Kaplan, dated September 17, 2024, is the primary document on her cooperation. It runs through every element of what she did and why it mattered. The direct quotes are the record. They belong here in full.
This series has a thesis for each case. A single thing the case documents about how fraud works at scale, and about the people inside it.
: the persona was the marketing. : the speed. : the product was the lie. Madoff: duration was the disguise. : the trust of the smart. Caroline Ellison: the one who knew, and told.
She is not the usual template for a case in this series. She is not primarily the fraudster, though she committed grave misconduct. She is not primarily the victim, though she was betrayed by the person she had worked for and loved. She is not primarily the hero, though the prosecution's most important witness is the closest the criminal justice system gets to one.
She is something more complicated: a person who made catastrophically wrong choices, who recognised them for what they were when she had the chance to do so, and who chose to tell the truth when telling the truth was both the legally optimal and the most costly personal choice available to her.
The legally optimal part: she understood that full cooperation was the fastest path to the shortest sentence. The most costly personal part: she was cooperating against the man she had loved, who was also weaponising her private writings to try to stop her. She did both things simultaneously. The cooperation track and the personal betrayal ran at the same time.
Her testimony is the reason the jury had what it needed to convict. Her document review is the reason the prosecution had evidence in a case where the defendant had systematically destroyed it. Her pre-investigation statements are the reason the government could establish that she had not changed her story to fit a deal.
She was the only person who could explain the why. And she did. In open court. On the record. Under cross-examination. While her former partner's lawyers tried to pick apart what she said.
She was sentenced to two years. She has been released. She is 31 years old. She has the rest of her life ahead of her, carrying the things she did and the things she chose when it ended.
Her private writings are not quoted in this piece. The DOJ filing documents that they were weaponised against her. Quoting them would repeat the act. What is reported: that it happened, that a judge found it was likely witness tampering, that it is in the government filing. She is a living person, released, who cooperated. Report per the court record only.
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
HOW THE FRAUD WORKED
THE CD FRAUD — LEGITIMACY AS ARCHITECTURE
THE LORD’S MOMENT — AUGUST 2008
THE $20M BOX AT LORD’S CRICKET GROUND
In August 2008, Allen Stanford landed a helicopter on the outfield at Lord’s — the most famous cricket venue in the world — carrying a Perspex box containing $20 million in cash. He announced the Stanford Super Series: West Indies XI vs England, $20M prize, the largest in cricket history. His West Indies team won. The prize was paid. Six months later, federal agents were chasing him through Houston streets. The $20M had come from investors who believed their money was in conservative CDs generating steady returns. [SOURCE: widely documented from collapse timeline]
CASE TIMELINE
WHAT THIS CASE ESTABLISHED
THE CRICKET, THE KNIGHTHOOD & THE COVER
CULTURAL INFRASTRUCTURE
THE SEC FAILURE & COLLAPSE
SERIES DISTINCTION — LEGITIMACY AS ARCHITECTURE
THE FULL STORY — 10 PARTS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE BOX AT LORD’S (3,500 WORDS)
In August 2008, Allen Stanford landed a helicopter on the outfield at Lord's Cricket Ground in London — the most famous cricket venue in the world, the spiritual home of the sport, a ground so steeped in tradition that its rules and conventions are maintained by an institution that has existed since 1787.
He stepped out carrying a Perspex box. Inside the box was $20 million in cash.
He was announcing a cricket tournament. The Stanford Super Series: a one-off match between his West Indies XI and England, for $20 million. The winning team would split the prize. Players on the winning side would receive approximately $1 million each. It was the largest prize in cricket history at the time. It was framed as a transformative gesture — a Texan billionaire who loved cricket so much he was willing to pay the biggest prize ever seen to celebrate it.
The Antiguan government had knighted him. The English cricket establishment welcomed him. The players were photographed laughing with him at the ground, some of them sitting in his helicopter. The image of the Perspex box and the $20 million was on the front pages.
Six months later, in February 2009, federal agents were chasing him through the streets of Houston. He was accused of running a $7.2 billion fraud. The $20 million prize was funded by the Stanford International Bank operation — money raised from CD investors whose principal was not invested as described, but used to fund the lifestyle and marketing of a man presenting himself as the Caribbean’s most significant financier.
Robert Allen Stanford was born on March 24, 1950, in Mexia, Texas — a small city in Limestone County, in the central part of the state, the kind of place that produces people who describe themselves, with pride, as being from somewhere real.
He described himself as a fifth-generation Texan. He was Baylor University educated — a degree in finance, 1974. He was large, physically imposing, gregarious, a man who occupied space with the specific confidence of someone who had decided early that the rooms he was in should know he was there.
He got into financial services in the early 1980s, starting with a gymnasium business in Waco, Texas, that eventually folded. He moved toward banking and investment. By the mid-1980s, he had established himself in Montserrat — a small Caribbean island — with a bank. The bank in Montserrat was later closed by regulators.
He moved to Antigua. He built Stanford International Bank there. He built a relationship with Antigua that would sustain his operation for decades, providing the offshore banking jurisdiction, the regulatory environment, and the political relationships that the scheme required to function.
He acquired Antiguan citizenship. He contributed millions to Antiguan politicians and to politicians in the United States and elsewhere. He sponsored cricket — building a stadium in Antigua, funding matches, positioning himself as the man who brought serious money to the sport that the Caribbean took most seriously.
In 2006, Antigua knighted him. He was Sir Allen thereafter.
The product was a certificate of deposit. A certificate of deposit — a CD — is among the most conservative financial instruments that exist. You deposit money with a bank. The bank holds it for a fixed term and pays you a fixed interest rate. At maturity, you get your principal back with interest. It is low-risk. It is simple. It is the savings instrument of choice for people who do not want complexity, do not want exposure, and do not want to think about it.
Stanford International Bank offered CDs. What made them attractive: the yields. In an environment where conventional CDs paid 3–4%, Stanford's CDs paid 10–15% or more. The pitch was that the bank's investment team was sophisticated enough to generate these returns through a diversified portfolio of liquid assets. [SOURCE: DOJ / SEC / widely documented from trial record]
Investors were told the CDs were safe, backed by a genuine investment portfolio, managed by a skilled team. The bank's financial statements were provided. The statements showed the returns being generated. The statements were fabricated.
What was actually happening: investor money was used to pay earlier investors — the classic Ponzi mechanism — and to fund Stanford's personal lifestyle. The personal lifestyle included private jets, yachts, a $20 million cricket tournament, real estate, political donations, and the comprehensive infrastructure of a man presenting himself as one of the richest and most significant figures in the Caribbean. [SOURCE: DOJ sentencing; SEC civil filings]
More than 20,000 investors across more than 100 countries put approximately $7.2 billion into Stanford International Bank CDs. [SOURCE: DOJ conviction release; Reuters] Many of them were from Latin America and the Caribbean — middle class investors who trusted the institution, trusted the returns, and trusted the man who was building cricket stadiums and getting knighted by island governments.
Antigua is a small island of about 80,000 people in the Eastern Caribbean. It is beautiful — coral beaches, warm water, the kind of landscape that makes people who visit wonder why they live where they do. It is also, as a financial jurisdiction, a place where a sophisticated operator with money and political connections could arrange matters to his advantage.
Stanford arranged matters to his advantage. He was one of the largest private employers on the island. He built Stanford International Bank there. He built a cricket stadium — the Stanford Cricket Ground — that could host international matches. He funded charitable works. He cultivated deep relationships with the Antiguan government, contributing millions to politicians and political causes.
The Antigua Financial Services Regulatory Commission was responsible for overseeing his bank. It did not detect the fraud. This is consistent with the pattern visible in both the Madoff and Stanford cases: the regulatory body responsible for oversight failed to identify what was happening until the scheme collapsed.
Stanford's Antiguan citizenship was practical as well as symbolic. His position as a major figure in Antiguan economic life gave him a form of protection and credibility that a straightforward foreign operator would not have had. He was not a visitor running a scheme from the island. He was part of the island's economic fabric — which made the scheme harder to question and harder to close.
He was knighted by the Antiguan government in 2006 — 'Sir Allen' was how he was addressed and how he introduced himself. The knighthood was later stripped following his conviction.
The Securities and Exchange Commission had looked at Allen Stanford before the fraud was exposed. More than once.
This is the second case in this series — after Madoff — where the regulatory body charged with protecting investors investigated the fraudster and failed to halt the scheme. In both cases, the scheme ran for years longer than it might have, in part because an investigation produced no action. In both cases, the eventual collapse came from market forces rather than regulatory action.
The SEC examined Stanford's operation and found that the above-market returns he was generating raised concerns similar to a Ponzi scheme. This examination occurred in the late 1990s and again in subsequent years. The SEC did not find the fraud. The scheme continued.
When the 2008 financial crisis triggered massive redemption requests that the scheme could not meet — the same mechanism that exposed Madoff — the SEC and other regulators moved in February 2009. By then, the fraud had been running for years with regulators having previously examined it without decisive action.
This is not a footnote. It is a structural failure that belongs in the case record alongside the fraud itself. The investors who put $7.2 billion into Stanford International Bank CDs did so in part because the institution had not been shut down despite examinations that had raised concerns. The regulatory failure is part of what the case documents.
The cricket connection was not incidental to the fraud. It was part of the same apparatus as the Antiguan knighthood, the charitable works, and the political donations: the infrastructure of a man who was spending money on things that made him look serious, embedded, and legitimate.
Cricket in the Caribbean is not just a sport. It is a cultural institution that carries specific weight — the game through which the Caribbean islands found a shared identity in the era of West Indies cricket dominance, when players from tiny island nations were the best in the world and the West Indies team was a source of collective pride for people who had otherwise been told they were peripheral.
Stanford understood this. He sponsored cricket matches in Antigua. He built a stadium. He funded development programs. He positioned himself as the man who was putting real money into the sport because he genuinely loved it — or at least into the appearance of a man who genuinely loved it.
The Lord's moment in August 2008 was the peak of the cricket chapter. He was at Lord's — the home of cricket — with a Perspex box containing $20 million, announcing the largest prize in the sport's history. The England cricket board had agreed to participate. Players from both teams were photographed with him. The image of the box circulated globally. He was, for a moment, the most famous cricket patron on earth.
He won the match — his West Indies XI beat England. The $20 million was paid. Then the financial crisis hit. The redemption requests came in at a scale the scheme could not meet. And the box that had appeared at Lord's, and the money it contained, turned out to have been funded by investors who had trusted their savings to a certificate of deposit in an Antiguan bank.
The 2008 financial crisis was the trigger here, as it was for Madoff. When markets collapsed in the autumn of 2008, investors across the world needed liquidity. The redemption requests that came into Stanford International Bank could not be met from the assets the bank claimed to hold, because those assets did not exist as described.
In February 2009, the SEC filed civil charges. Federal agents were dispatched. The news broke that day. Stanford, who had been trying to flee — running from federal agents in a car — eventually gave himself up. He was taken into federal custody on June 18, 2009 — surrendering to US Marshals in Fredericksburg, Virginia, after agents had been searching for him. [SOURCE: Wikipedia citing primary record]
The Stanford Financial Group — the US entity that had sold the offshore CDs to American and international investors — was seized. A receiver, Ralph Janvey, was appointed to recover assets for victims. The Antiguan bank was placed in receivership by Antiguan authorities.
What the receiver found: the investment portfolio that Stanford had described — the diversified, liquid, sophisticated assets supposedly generating the above-market returns — did not exist as represented. The bank's financial statements were fraudulent. The money was gone: spent on the lifestyle, on political donations, on cricket, on the other costs of maintaining the appearance of one of the Caribbean's most significant financial institutions.
A grand jury indicted Stanford on 21 counts in June 2009. He pleaded not guilty. His case then became complicated by a specific and unusual circumstance: while in pretrial detention, he became addicted to anti-anxiety medication prescribed in prison. A federal judge eventually declared him temporarily unfit for trial due to this addiction and related psychiatric issues, and he was sent to a federal hospital for evaluation. [SOURCE: Stabroek News / Reuters]
He was ultimately found fit for trial. The trial took place in early 2012 in Houston, Texas.
Stanford's trial opened in January 2012 in Houston before Judge David Hittner. Stanford had been in custody since 2009 — nearly three years — due to the fitness proceedings and related delays.
He maintained his innocence throughout. His defence argued that the government's case misrepresented how Stanford International Bank operated — that it was a real bank with real assets generating real returns, and that the prosecution's theory was wrong.
The prosecution presented evidence of the fabricated financial statements, the movement of investor funds to Stanford personally, the absence of the investment portfolio as described, and the classic mechanics of a Ponzi scheme operating across decades. Former Stanford insiders — including James Davis, his chief financial officer and former college roommate, who pleaded guilty and cooperated — testified against him. [SOURCE: widely documented from trial record]
James Davis, who had shared a dorm room with Stanford at Baylor University, became the government's most significant cooperating witness. He pleaded guilty in 2009 and testified about the mechanics of the fraud — how the financial statements were fabricated, how investor money was used, how the scheme was maintained across years of operation.
The jury convicted Stanford on 13 of 14 counts on March 6, 2012. [SOURCE: DOJ conviction release / Reuters] The counts included wire fraud, mail fraud, obstruction, and conspiracy to commit money laundering, among others.
On June 14, 2012, Judge David Hittner sentenced Robert Allen Stanford to 110 years in federal prison.
He was 62 years old at sentencing. He is 76 years old as of this writing. His scheduled release date is March 13, 2103. [SOURCE: Bureau of Prisons / Wikipedia citing BOP record]
He is serving his sentence at the United States Penitentiary, Coleman II, in Sumter County, Florida — a high-security penitentiary near Wildwood, about 50 miles northwest of Orlando. [SOURCE: Nation News Barbados / BOP]
He has not stopped claiming innocence. In a BBC interview in January 2016, he said he spends every day in prison working on his case. He refused to apologise to his victims and described the court-appointed receivership as 'a court-sanctioned theft of unimaginable proportions.' [SOURCE: Cayman News Service citing BBC 5Live, January 2016]
In 2023, he filed an application with the US Supreme Court seeking an extension of time to challenge the receivership — the legal proceeding through which Ralph Janvey manages the recovery and distribution of assets to victims. Justice Samuel Alito granted the extension to February 2024. [SOURCE: Supreme Court docket No. 23A401]
As of this writing, there is no indication that any appeal has succeeded. The 110-year sentence stands. The receivership continues its work. The victims have received some recovery — a fraction of what they put in.
The victims of Allen Stanford's fraud were not primarily hedge fund managers or institutional investors. They were people who had put their savings into something that looked safe.
More than 20,000 investors across more than 100 countries put money into Stanford International Bank certificates of deposit. [SOURCE: DOJ conviction release] A significant proportion were from Latin America and the Caribbean — Venezuela, Mexico, Panama, Ecuador, Colombia. Countries where the offshore CD in a respected Caribbean bank, with a credentialed American banker behind it and an Antiguan knighthood on the wall, looked like exactly the kind of solid, conservative, sensible investment that protects you from the instability of your own country's financial system.
Many of them were middle class or retired. They were not taking a speculative risk. They were doing what careful people do: putting their savings somewhere safe. The promised returns were higher than local rates, which was appealing, but not so high as to be obviously implausible. Stanford's operation was designed to be exactly plausible enough.
When the bank collapsed in February 2009, they could not access their money. The receivership began the long process of recovering and distributing what could be found. Years of litigation followed. Some victims received partial recovery. Many did not get back what they put in.
Stanford's BBC interview position — that the receivership was 'a court-sanctioned theft' — was the position of a man who had lost his case in court and had not changed his account of events. His victims had a different account.
The series thesis for is this: legitimacy was the architecture.
Every case in this series has a thesis — a single thing it documents about how fraud at scale works. Stanford's thesis is about the specific power of legitimate structures as fraud infrastructure.
He did not build a fake institution and pretend it was real. He built real institutions — a real bank with a real charter, real staff, real operations in a real country — and used the authentic structure as the container for a fraudulent core. Stanford International Bank was a functioning bank. It processed real transactions. It had real employees. It operated in a real regulatory environment. Inside that real structure, the investment portfolio was fabricated and investor money was being redirected.
The cricket sponsorship was real. The stadium was real. The knighthood was real. The political donations and the relationships with Antiguan and American politicians were real. All of it was real, and all of it served the same function: it made questioning the bank feel like questioning a person who had devoted themselves to the Caribbean, to cricket, to the community. Doubt became not a form of due diligence but a form of ingratitude.
Compare this to : there was no blockchain. The product had nothing beneath it. OneCoin was a number in a database and a brand. Stanford's fraud was the opposite in structure: a real institution with real operations and a fraudulent centre. The question 'how can this be a fraud — look at the stadium, the employees, the charter' was exactly the question the structure was designed to produce.
The SEC had looked. It had found similarities to a Ponzi scheme. It had not acted decisively. This is not a coincidence of the same form appearing twice in this series. It is the same dynamic: an institution with enough authentic complexity that the regulatory examination produced uncertainty rather than clarity, and the scheme ran.
He is at Coleman II. He is 76. His scheduled release is 2103. He is still working on his case, by his own account. The investors who put $7.2 billion into his certificates of deposit have received partial recovery from a receivership that has been working since 2009. The cricket ground in Antigua is still there.
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
THE BANK AND THE COURTS
LEESON (CASE 022) VS KERVIEL (CASE 030)
CASE TIMELINE
HOW IT WORKED
HOW THE BETS STAYED HIDDEN — DEFENSIVE LEVEL
WHAT THIS CASE ESTABLISHED
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE UNWINDING (1,500 WORDS)
() lost £827 million at Barings and the bank collapsed. Jérôme Kerviel built a position ten times larger and Société Générale survived. The difference is not a matter of audacity. It is a matter of which institution was on the other side.
Barings had been a distinguished private bank. It could not absorb the loss. ING bought it for £1.
Société Générale was — and remains — one of France's largest banks, a publicly listed institution with a market capitalisation that, in January 2008, was smaller than the position Kerviel had built. The position Kerviel had built — €49.9 billion in notional exposure to European equity index futures — was larger than the bank's entire market cap. When the bank unwound it in three days in January 2008, amid a falling market, the realized loss was approximately €4.9 billion. SocGen survived. It had to raise emergency capital, but it survived.
The mechanism is the same as Leeson: unauthorized trading, hidden through falsified records, in an institution where the compliance function failed to catch it in time. The scale is larger. The legal aftermath is dramatically different — because Kerviel raised a question Leeson never seriously contested: what if the bank knew?
Jérôme Kerviel was born on January 11, 1977, in Pont-l'Abbé, Finistère, in Brittany. He earned a finance degree at the Université de Nantes and a master's in financial market operations at the Université Lumière Lyon 2 in 2000 — a respectable but not elite French university trajectory in an industry where the highest desks tend to go to graduates of the grandes écoles.
He joined Société Générale in 2000, initially in the compliance and middle-office function — the back office that processed and recorded trades. This is the same critical detail as Leeson at Barings: he had direct knowledge of how trades were recorded, how reconciliations were done, and where the gaps in monitoring were. In 2005 he moved to the bank's Delta One trading desk — the proprietary trading operation that handled index futures and structured products.
Delta One traders take positions linked to market indices. Their trades are typically hedged — for every long position, there is a corresponding short. The hedge is what keeps the net exposure within limits and what allows risk managers to verify that the desk is doing what it says it is doing.
Kerviel's positions were not hedged. The hedges were fictitious. He created fake counterparty entries in the bank's systems — entries that appeared to offset his real trades but pointed to accounts that did not exist or to transactions that were never executed. The result: on paper, the desk looked properly hedged. In reality, Kerviel held an enormous naked long position on European equity indices.
By early January 2008, Kerviel's unauthorized positions had grown to approximately €49.9 billion in notional value — primarily futures on the DAX, EUROSTOXX, and FTSE indices. This was larger than Société Générale's entire market capitalisation at the time.
The position had been profitable through 2007. Kerviel later said, and has always maintained, that his trading had produced gains for the bank — gains the bank accepted without asking where they came from. In 2007 he had generated profits of approximately €1.4 billion from his unauthorized positions. No one from the bank's risk or compliance function asked how those profits had been made.
He falsified the offsetting entries to stay below the bank's risk limits. He created fictitious forward transactions with existing SocGen counterparties — transactions large enough to appear to hedge his real positions but that never settled because they were never real. When Eurex, the German derivatives exchange, sent an inquiry about one of these positions in late 2007, Kerviel created a forged email response. The inquiry was absorbed without escalation.
In the second week of January 2008, the bank's back office identified an irregular transaction and raised it with compliance. On January 18, 2008, a junior employee flagged an anomaly. The investigation that followed revealed the full scale of the position in the days that followed.
On January 19, 2008, Société Générale's senior management understood what they had. Over the weekend of January 19-20, they made the decision to unwind the position — to close every one of Kerviel's unauthorized trades as quickly as possible.
The unwinding ran from January 21 to January 23, 2008. These were not quiet days in the market. Global equities were falling sharply — European markets plunged on January 21 while US markets were closed for a holiday, and on January 22 the Fed made an emergency 75 basis point rate cut. Into this falling market, Société Générale was selling approximately €50 billion in equity index futures — an operation of such scale that some market participants later speculated that the selling itself contributed to the week's market movements.
The realized loss: approximately €4.9 billion. This was the market impact of selling an enormous long position into a falling market over three days. If the positions had been unwound more slowly, or if the market had been rising, the loss would have been different. Kerviel has argued since his conviction that the bank's decision to unwind quickly — and secretly, before informing the regulator — maximized the loss. The bank disputes this.
SocGen disclosed the fraud and the loss on January 24, 2008. The bank's share price fell approximately 4 percent on the day of disclosure. Kerviel was arrested that week. He has spent the years since disputing the attribution of the loss.
The conviction in October 2010: 5 years in prison (2 suspended, 3 to serve), and €4.9 billion in damages — the full amount of the unwinding loss. The damages figure was controversial from the start.
The 2016 damages ruling is the most distinctive element of this case in the series. French courts found that SocGen had received warning signals — internal alerts from exchanges and compliance processes — that, if properly investigated, could have halted Kerviel's trading earlier. The bank's own incentive structure, which rewarded the profits Kerviel was generating without asking hard questions, was found to constitute contributory fault.
Kerviel's defense from the beginning was that he was not a rogue element but a product of the institution — that the bank knew enough to ask questions and chose not to, because the money was coming in. The 2016 ruling gave that argument legal weight in the civil damages context, without reversing the criminal finding that he had forged documents and concealed positions.
Leeson (): one person, no oversight, bank died. The lesson was unambiguous.
Kerviel: one person, apparently no oversight — but the oversight question turned out to be more complicated. The bank received signals that, in retrospect, should have been investigated. The profits were accepted. The losses were called fraud. The French judiciary, eventually, found the causal chain messier than a simple bad-actor story.
This is not a defense of Kerviel's conduct. He forged documents. He created fictitious hedges. He lied to compliance when confronted. The criminal conviction reflects that conduct accurately. But the series' interest in this case is the institutional question, because it is the question that the series' entire compliance section is built around: what does a working compliance function actually require?
The Kerviel case answers it in reverse. A bank that paid out €1.4 billion in profits generated by positions it could not fully explain, without asking where those profits came from, built a compliance gap large enough to hide €50 billion. The warning signals were there. The culture that produces them also has to produce the investigation.
SOURCES
KEY FACTS
FULL PROFILE
WHO THEY ARE
CASE RECORD
MEMBERS — CHARGED, NOT CONVICTED
THE BIGGEST HEISTS (AS ATTRIBUTED)
WHY IT MATTERS
CASE TIMELINE
HOW IT WORKED
HOW THE HEISTS WORK (PER THE FBI) — DEFENSIVE LEVEL
WHAT THIS CASE ESTABLISHED
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE GOVERNMENT THAT DECIDED THEFT WAS CHEAPER THAN TRADE (2,100 WORDS)
Every other case in this series ends.
Not tidily, not always justly — but it ends. There is an arrest, a plea, a verdict, a sentence. A person is moved from one side of a courtroom to the other. The legal system does the thing legal systems do, and we record the outcome.
ends on December 11, 2025, in a federal courtroom in New York, when a judge says 'You chose to lie. You chose poorly,' and a 34-year-old man who destroyed $40 billion in market value is led from the courtroom. ends in a house in Gainesville, Georgia, with federal agents lifting a popcorn tin from a bathroom closet.
Case 027 does not end. Four North Korean men are charged. They are in Pyongyang. They will not be extradited. They are employees of a state that does not extradite its employees. The unit they work for continues to operate. The operations continue to run. The proceeds continue to flow — into a state, into a nuclear programme, into the budget line that pays for the next operation.
You cannot arrest a government. You can only describe it accurately — and say, every time, that the description is an assessment.
Lazarus Group is the name used by researchers, governments, and intelligence agencies to describe cyber units attributed to the Reconnaissance General Bureau — the RGB — North Korea's primary foreign intelligence apparatus.
It is a label applied from outside — not a name they chose for themselves.
The name 'Lazarus' is an umbrella. It covers Bureau 121 and its sub-units under different analytical frameworks used by different researchers and governments. The FBI uses TraderTraitor for the crypto-specific sub-unit; Kaspersky Labs coined BlueNoroff; Symantec and others use APT38 for the financial theft arm. The inconsistency in naming reflects the fact that the attribution assessments come from competing sources working with different intelligence.
Every individual listed below is a LEGAL STATUS NOTE. The three DPRK nationals are indicted — not convicted. Ghaleb Alaumary pleaded guilty and his status is documented separately. North Korea denies the existence of Park Jin Hyok. All conduct attributed to DPRK nationals is alleged in the indictment and assessed by intelligence agencies — it has not been proven at trial.
KEY FACTS: First charged September 6, 2018 in criminal complaint (CDCA). First North Korean national publicly indicted for financial cybercrime. North Korea issued an official denial of his existence. Travelled to China and conducted legitimate IT work under Chosun Expo cover — the dual-use front company model the DPRK uses across multiple operatives. On FBI Cyber Most Wanted list. [SOURCE: DOJ; FBI; OpenSanctions; US Treasury OFAC]
KEY FACTS: Charged in the February 17, 2021 unsealing of the expanded indictment. The Marine Chain Token is a specific and documented example of the Lazarus Group creating financial fraud products — a blockchain-based token designed to appear legitimate while secretly funding the DPRK state. This represents a distinct capability: not just theft, but fraud product development. [SOURCE: DOJ Feb 2021 indictment]
KEY FACTS: The alias pattern (Julien Kim, Tony Walker) reflects a specific operational technique: constructing Western-friendly identities for marketing fraudulent financial products. This distinguishes Kim Il's documented role — the outward-facing, investor-targeting component — from the technical infrastructure roles attributed to the other indicted members. His aliases suggest he engaged with Western targets directly as part of the fraud product marketing. [SOURCE: DOJ 2021 indictment; Infosecurity-Magazine citing DOJ]
KEY FACTS: Alaumary is the series connection point. He bridges (/) and Case 027 (Lazarus Group). His role was to organise teams of money laundering co-conspirators in the US and Canada to process proceeds attributed to North Korean cyber theft. He is the only individual in this case file who is NOT a North Korean national and who has entered a guilty plea in US proceedings. He was sentenced on 8 September 2021 to 140 months (11 years 8 months) and ordered to pay more than $30 million in restitution (DOJ). [SOURCE: DOJ plea agreement; DOJ Feb 2021 press release]
The Lazarus Group does not operate from a building labelled 'DPRK Cyberattack Centre.' It operates through front companies that provide legitimate IT services as cover for RGB operations — a dual-use model the DPRK uses systematically to generate both revenue and operational cover.
Attribution discipline mandatory throughout. Each operation is labelled with its attributing body. No operation has been proven in court. Dollar figures labelled with what they measure and their source. 'Stolen' means 'attributed as stolen by' — the attribution is an intelligence assessment.
Aggregated figures for Lazarus-attributed theft circulate widely and vary significantly. The variations are not errors; they reflect different methodologies, time periods, and attribution decisions. Every figure below carries its source.
of this series is — . His co-conspirator Ghaleb Alaumary — now Member 04 of this case file — laundered proceeds from North Korean-linked cyber operations including the Bank of Valletta SWIFT heist. The Instagram influencer's laundering network was downstream of this state programme.
is and Binance. Binance admitted to failing to run an effective anti-money-laundering programme; exchanges with weak controls are the kind of channel launderers of stolen crypto rely on. (The DOJ's Binance findings name sanctioned-country users and terrorist-linked transactions; this file does not claim they name North Korea.)
The series' foundational category on BEC includes the case (): the principle that the attack surface in financial fraud is human verification applies equally to SWIFT social engineering and invoice fraud.
Lazarus Group is not a separate thread in the series. It is the thread that was already running through 's network and 's compliance failures. The individual fraudsters commit their crimes. The exchange failures create the channels. The state-sponsored unit uses all of it.
Beyond direct heists, US government agencies and private security firms have documented a parallel Lazarus-adjacent operation: the systematic placement of North Korean IT workers at technology companies globally, generating income assessed to flow back to the DPRK state.
The operation, documented in joint advisories from the US Departments of Justice, State, and Treasury, involves DPRK nationals securing remote employment at technology companies — cryptocurrency-adjacent firms in particular — under false identities and with falsified credentials. [SOURCE: US Departments of Justice, State, Treasury joint advisory — verify exact dates and title]
The technique: a North Korean national secures remote work as a software developer, graphic designer, or IT contractor. They perform genuine work. The salary is paid to accounts that route back to the DPRK state. The cover is plausible, the work is real, and the revenue is generated without any intrusion or heist.
This operation connects to the front company model documented in Part Three. Chosun Expo Joint Venture was Park Jin Hyok's cover for legitimate IT work — the IT-worker operation scales that model to thousands of individuals operating globally through diverse cover identities.
The dollar amounts generated through this channel are not established with the same precision as the direct heists. The programme is documented as existing and ongoing; its aggregate scale is assessed rather than audited.
The individual cases in this series have psychological explanations. Madoff ran his scheme because he could not face the moment it ended. built a framework of self-justification. Holmes told the story long enough that she started to believe it.
The Lazarus Group does not have a psychology. It has a budget line.
North Korea operates under comprehensive international sanctions — the response to its nuclear weapons programme. The sanctions have not ended the programme. What they have produced is an intensification of the need for hard currency through channels sanctions cannot reach. The Lazarus clusters are the assessed solution.
The operations follow the hardening of targets. Banks hardened their SWIFT infrastructure after 2016. The group moved to exchanges. Centralised exchanges hardened direct custody. The group moved to bridges. Bridges hardened. The group moved to supply-chain attacks on the software those bridges depended on — as in Bybit, where the entry point was a developer's compromised machine.
The technical escalation is not the story. The story is structural: every time a target hardens, the unit adapts, because the state still needs the money and the capability exists to find the next soft point. This will continue until either the sanctions regime changes, the nuclear programme concludes, or the capability is degraded by means outside the scope of this case file.
What can be said: the US government has charged four North Koreans as members of the unit — Park Jin Hyok, Jon Chang Hyok, Kim Il and, in July 2024, Rim Jong Hyok (reward up to $10 million). Ghaleb Alaumary pleaded guilty to laundering for the operation and was sentenced to 11 years 8 months. The unit is attributed by the US, UK, and other governments to have conducted operations assessed to have generated billions of dollars in proceeds. Those proceeds fund the North Korean state.
What cannot be said: that any of this has been proven in a court of law through an adversarial proceeding. Attribution is an intelligence judgment. The indictments are criminal charges, not convictions. The figures are assessments, not audited accounts. Park Jin Hyok's existence is denied by the North Korean government.
Every other case in this series ends with a person in a cell or a person on the run. This one ends with four charged men beyond reach, an operational unit still working, a UN Panel of Experts writing its next annual report, and a fresh FBI attribution for a fresh $1.5 billion theft.
You cannot indict a government. You can charge four of its employees, and imprison its money launderer, and watch them stay exactly where they are.
SOURCES
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
THE TAKEDOWN AND THE COURT
SILK ROAD (CASE 013) VS HYDRA (CASE 035)
CASE TIMELINE
HOW IT WORKED
HOW HYDRA WORKED — DEFENSIVE LEVEL
KNOWN NETWORK & CONNECTED CASES
WHAT THIS CASE ESTABLISHED
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE STORE (1,300 WORDS)
Silk Road () launched in 2011, was shut down in 2013, and its operator received two consecutive life sentences — then was pardoned by President Trump in January 2025. The prosecution of Silk Road established the legal framework for darknet-market enforcement in the United States. The platform itself had processed approximately $200 million in revenue before it was taken down.
Hydra processed more than $5.2 billion. [SOURCE: US DOJ]
Silk Road was the original. Hydra was what the model became after a decade of iteration — larger, better organised, more deeply embedded in the Russian-language market, and in operation for seven years before it was taken down. By the time German authorities seized its servers on April 5, 2022, Hydra had some 17 million customer accounts and had handled an estimated 80 percent of all darknet-related cryptocurrency transactions worldwide in 2021. [SOURCE: US DOJ, April 2022; Chainalysis]
Stanislav Moiseyev, identified as the founder and organiser of the operation, was convicted by the Moscow Regional Court on December 2, 2024 and sentenced to life imprisonment. Fifteen accomplices received sentences ranging from 8 to 23 years. [SOURCE: TASS / Interfax as reported by Cointelegraph / BankInfoSecurity]
Two governments came for Hydra: Germany seized the infrastructure; Russia convicted the operator. The marketplace was treated as a serious crime on both sides of the jurisdictional divide.
Hydra Market founded approximately 2015, was a Russian-language darknet marketplace. The core business was illegal drugs — its vendors supplied narcotics to buyers across Russia and Belarus using a dead-drop model, where purchased items were left at predetermined locations rather than mailed. [SOURCE: Moscow Regional Court per TASS; BankInfoSecurity]
What made Hydra distinctive was not the business model — which was the same escrow-and-rating structure that Silk Road had established — but the scale of its integration into the Russian-speaking market and the sophistication of its financial services layer. Beyond drug sales, Hydra offered ransomware-as-a-service, hacking tools, stolen payment card data, counterfeit currency, and fake identity documents. It also operated as a cryptocurrency mixer — a service to obscure the origin of cryptocurrency transactions. [SOURCE: DOJ; BankInfoSecurity; Wikipedia]
The cryptocurrency volume reflects both the marketplace's size and its mixing function: much of the $5.2 billion figure represents money flowing through Hydra for obscuring purposes, not only for direct purchases on the market. This distinction matters: $5.2 billion is the total assessed flow, not the total value of goods sold.
Hydra's drug-supply chain operated through a network of vendors, clandestine production facilities, and storage sites hidden in vehicles, garages, and homes with secret compartments — per the Russian prosecution's account. The scale of the physical operation was documented when authorities seized approximately one tonne of illegal narcotics during raids. [SOURCE: Moscow Regional Court per TASS; BankInfoSecurity]
On April 5, 2022, the German Federal Criminal Police Office (BKA), working with US Department of Justice and Treasury counterparts, announced the seizure of Hydra's Germany-based servers and the confiscation of cryptocurrency. The US Treasury's OFAC simultaneously sanctioned Hydra, cutting it off from the US financial system and any institutions with US connections. [SOURCE: DOJ announcement April 5, 2022; US Treasury]
The cryptocurrency seized in the operation amounted to approximately $25 million — the assets directly accessible on the seized infrastructure. This is the seizure figure. It is separate from the $5.2 billion in revenue the marketplace had processed over its lifetime; the vast majority of that revenue had long since been distributed or moved.
The servers were located in Germany — which explains the German-led jurisdiction. The choice of Germany for hosting was presumably not accidental; Hydra's operators sought hosting infrastructure with limited visibility to Russian authorities, though the eventual Russian prosecution of Moiseyev suggests that calculation did not hold.
The DOJ's parallel action designated Hydra as a significant transnational criminal organisation and charged Dmitry Olegovich Pavlov, a Russian national, with conspiring to run Hydra's servers through his hosting company, Promservice. [SOURCE: DOJ April 5, 2022]
The Moscow Regional Court convicted Stanislav Moiseyev and 15 co-defendants on December 2, 2024. The charges: organising a criminal community and the illegal production and distribution of psychotropic substances and drugs — the Russian criminal code's framing of what the marketplace had enabled. [SOURCE: TASS / Interfax as reported; Cointelegraph; BankInfoSecurity]
The life sentence was imposed by a judge, with a fine of 4 million rubles (approximately $38,000). His accomplices received sentences of 8 to 23 years and collective fines of 16 million rubles. Moiseyev's life term is served in a special-regime colony, the strictest in the Russian system; his accomplices were sent to special- and strict-regime colonies. It was the first life sentence in Russia for a crime of this kind, according to Russian media.
The Russian conviction is independent of and parallel to the US and German actions. The Russian state prosecuted Moiseyev not under US law but under Russian criminal code, for harm done to Russia — the narcotics supplied within Russia and Belarus. The international dimension (the German server seizure, the US sanctions) provided the backdrop, but the prosecution was a domestic Russian action.
During the investigation, Moiseyev refused to disclose the password to his confiscated cryptocurrency wallet. [SOURCE: Forklog citing Interfax] The value of that wallet is not established in public reporting — it represents an unknown quantity of digital assets beyond the reach of the court's confiscation orders.
The conviction is being appealed by the defence. [SOURCE: Bitdefender citing reports] The life sentence stands pending appeal.
The Silk Road case is often framed as the founding and closing of the darknet marketplace model. The Hydra case is why that framing is wrong.
The model did not close when Ulbricht was convicted in 2015. It migrated — to other platforms, other jurisdictions, other languages. Hydra was not a successor that respected the boundaries of the original; it operated at a completely different scale in a completely different market. The Russian-language darknet economy that Hydra dominated was largely invisible to Western coverage until the April 2022 takedown made it visible.
Since Hydra's closure, per Chainalysis reporting, new Russian-language darknet markets have emerged and grown. Darknet markets generated $1.7 billion in revenue in 2023, surpassing 2022 levels even in Hydra's absence. The closure of the dominant platform created a fragmented market of successor operations, and a 'Russian darknet market conflict' among those successors. [SOURCE: Chainalysis / cryptometer.io citing Chainalysis]
The marketplace was never the crime scene. It was the infrastructure — the store, not the supply chain, not the cash-out. Moiseyev built the store and ran the community. The vendors, the producers, the customers, the money mixers: a much wider ecosystem fed through the same platform. A life sentence for the infrastructure operator does not close the supply chain.
SOURCES
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
THE PEOPLE AND THE MONEY
SBF (CASE 005) VS MASHINSKY (CASE 028)
CASE TIMELINE
HOW IT WORKED
HOW CELSIUS WORKED — DEFENSIVE LEVEL
WHAT THIS CASE ESTABLISHED
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — UNBANK YOURSELF (1,300 WORDS)
The slogan was 'Unbank Yourself.'
Celsius Network, the cryptocurrency yield platform founded and led by Alex Mashinsky, built its brand on the proposition that it was better than a traditional bank. It paid higher interest — 5 to 20 percent annually on deposited crypto, depending on the asset and the tier. It did not require credit checks. It was available globally. And it was, according to Mashinsky in his weekly 'Ask Mashinsky Anything' livestreams, safe.
'Celsius does not do non-collateralized loans,' he told customers in those livestreams. 'That would be taking too much risk on your behalf.' [SOURCE: Reuters / guilty plea record]
It was false. Celsius did make non-collateralized loans. It made risky, undisclosed bets in decentralized finance protocols. When those bets turned against it in the crypto market collapse of 2022, the hole in the balance sheet was approximately $1.2 billion. The company froze customer withdrawals on June 12, 2022 — trapping approximately $4.7 billion in customer assets. It filed for bankruptcy on July 13, 2022.
Mashinsky was arrested on July 13, 2023, exactly one year after the bankruptcy filing. He pleaded guilty on December 3, 2024, to two counts: commodities fraud and a scheme to manipulate the price of Celsius's native CEL token. He was sentenced to 12 years in federal prison on May 8, 2025, by US District Judge John G. Koeltl in Manhattan's Southern District of New York. [SOURCE: NBC Washington; Yahoo Finance; DOJ]
Alexander Mashinsky was born in October 1965 in the Soviet Union (the Ukrainian SSR); his family emigrated in the 1970s and he grew up in Israel. He is a serial entrepreneur who moved to the United States and built a career in technology. He claims to have invented Voice over Internet Protocol (VoIP) — a claim that is disputed but that he deployed as a credential for the Celsius brand.
Celsius Network was founded in 2017. The model was crypto lending: customers deposited Bitcoin, Ethereum, stablecoins, and other digital assets with Celsius. Celsius paid them interest — returns substantially higher than any conventional bank was offering. The interest was funded by Celsius lending those assets out to institutional borrowers and deploying them in DeFi protocols.
At its peak in late 2021, Celsius purportedly held approximately $25 billion in assets, according to the DOJ and was one of the largest crypto yield platforms in the world. It had approximately 1.7 million customers. The customer base was heavily retail — ordinary individuals who had deposited life savings, retirement funds, and emergency reserves in what Mashinsky had repeatedly told them was a safe, conservative, regulated alternative to traditional banking.
The reality, per the DOJ's charges and Mashinsky's own guilty plea: Celsius was taking risks it never disclosed. It made uncollateralized loans — which Mashinsky had specifically denied on livestream. It deployed customer assets into highly volatile DeFi protocols. The risks were not disclosed to customers in a way that would have allowed them to make informed decisions.
The CEL token was Celsius's native cryptocurrency — its own coin, with a specific function within the platform: customers could receive higher interest rates if they held CEL, and Celsius used it as part of its yield payment structure. CEL's price mattered to Celsius's business model and to its appearance of solvency.
Mashinsky's specific plea covers what he admitted doing to the CEL token: he directed Celsius to purchase CEL in the open market to prop up its price — using customer funds to create artificial demand for a token that was also a significant part of his personal wealth. While doing this, he was personally selling his own CEL holdings. [SOURCE: DOJ; guilty plea record]
At sentencing, the court heard that Mashinsky made more than $48 million from selling CEL at inflated prices he had helped create. [SOURCE: Fortune / Yahoo Finance / NBC Washington] While he was telling customers on livestreams that he was not selling his CEL tokens, he was selling his CEL tokens.
In court in December 2024, Mashinsky stated: 'I said that Celsius had approval from regulators. It was false. I falsely said I was not selling my CEL tokens. I accept full responsibility for my actions. I did not know which law it was violating, but I knew it was wrong — and illegal.' [SOURCE: Inner City Press / Reuters, December 2024]
The crypto market began its major decline in May 2022. The collapse of TerraLUNA ( in this series) triggered a liquidity crisis across the sector. Celsius's positions — heavily concentrated in illiquid DeFi protocols that were themselves collapsing — created a hole in the balance sheet that the company could not cover.
On June 12, 2022, Celsius halted all withdrawals, swaps, and transfers. The platform froze. Approximately 1.7 million customers could not access their funds. The announcement cited 'extreme market conditions' — language that revealed nothing about the underlying insolvency.
The bankruptcy filing came on July 13, 2022. The $1.2 billion gap in the balance sheet became public. Customers who had deposited in good faith — retirees, families, individuals who had moved their life savings onto the platform — were now unsecured creditors in a bankruptcy proceeding.
More than 200 victim impact statements were submitted at sentencing. The judge acknowledged reports of suicides connected to the collapse. [SOURCE: Fortune; DOJ press statement at sentencing] These are the human consequences of the gap between 'safer than a bank' and the reality of what the platform was doing with deposited assets.
DOJ sought 20 years. His lawyers sought 1 year and 1 day. Probation recommended 15 years. Judge Koeltl imposed 12. [SOURCE: The Block; NBC Washington; Yahoo Finance]
Judge Koeltl described the crimes as 'extremely serious' and said a substantial sentence was needed because some customers lost everything and suffered severe psychological harm (as reported by AP). The 12-year sentence for Mashinsky sits between Ellison's 2 years (full cooperation, no personal theft) and 's 25 years (direct misappropriation of $8B, zero cooperation). The DOJ characterized the $4.7B FTC settlement with Celsius as one of the largest in the FTC's history.
The co-defendant Roni Cohen-Pavon, Celsius's former Chief Revenue Officer, pleaded guilty in September 2023 and cooperated. On 14 May 2026 Judge Koeltl sentenced him to time served, a $40,000 fine and forfeiture of over $1 million.
The Mashinsky case closes the crypto yield platform category. Every major platform of this type that was prominent in 2021 has now produced a criminal case: FTX (), Celsius (Case 028), Binance/ (). The model was the same — take depositor funds, promise yield, deploy in risky strategies — and the regulation that would have required disclosure of those risks was what each platform had spent years trying to avoid.
SOURCES
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD [ALLEGED / DOCUMENTED]
THE WOLF OF WALL STREET LOOP
FROM MALAYSIA’S SOVEREIGN FUND TO DICAPRIO’S OSCAR PLATFORM [ALLEGED]
Red Granite Pictures — the production company that made The Wolf of Wall Street — was co-founded by Riza Aziz, the stepson of Malaysian PM Najib Razak. The US government alleged Red Granite was funded in part with money looted from 1MDB. Red Granite settled a DOJ forfeiture action for approximately $60 million without admitting wrongdoing in 2017. The settlement is documented. The source of the funds is alleged.
The film that made a $200M boiler-room operator into a global icon was allegedly funded with a sovereign fund’s money. [SOURCE: DOJ forfeiture filings — allegation]
CASE TIMELINE
HOW THE FRAUD WORKED
THE STORY ON BOTH SIDES — FROM THE CASE BRIEF
WHAT THIS CASE ESTABLISHED
BACKGROUND & BIOGRAPHY
EARLY LIFE & EDUCATION
THE LIFESTYLE (ALLEGED)
1MDB — THE FUND & THE ALLEGED FRAUD
1MDB OVERVIEW
NAJIB RAZAK — THE CONVICTION SIDE
THE FUGITIVE STATUS — WHERE IS HE NOW
THE FULL STORY — 8 PARTS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE FUND (3,000 WORDS)
In of this series, : the fraud cost $200 million, the film made him immortal, and the legend outlasted the crime by every measure.
The film was The Wolf of Wall Street. Martin Scorsese directed it. Leonardo DiCaprio played Belfort. It grossed over $390 million worldwide. Five Academy Award nominations.
The production company was Red Granite Pictures. Red Granite was co-founded by Riza Aziz — the stepson of Malaysian Prime Minister Najib Razak.
The United States government alleged that Red Granite was funded, in part, with money looted from 1Malaysia Development Berhad — a Malaysian state investment fund known as 1MDB. In 2017, Red Granite settled a US forfeiture action for approximately $60 million without admitting wrongdoing. [SOURCE: DOJ forfeiture settlement — verify exact figure before publication]
The alleged architect of the 1MDB fraud — the man the US Department of Justice called the 'mastermind' — was Taek Jho Low. A Malaysian financier, born in Penang, educated at the University of Pennsylvania, who built relationships with royalty and politicians across multiple continents and who, the US government alleged, siphoned over $4.5 billion from a fund that belonged to the Malaysian people. [SOURCE: DOJ civil forfeiture complaints — allegation, not adjudication; Low has never been convicted]
He was last reportedly seen on December 24, 2019, at Shanghai Disneyland. He has not been found since.
Taek Jho Low was born on November 4, 1981, in George Town, Penang, Malaysia. He came from a wealthy family — his father was a businessman — and his early trajectory was the trajectory of a certain kind of ambitious, globally mobile young man from Southeast Asia: elite secondary school in England (Harrow), then the United States for university.
He attended the University of Pennsylvania's Wharton School and graduated in 2005. Wharton is one of the most selective business schools in the world. The network it produces — the classmates, the professors, the alumni, the events — was part of what Low leveraged in the years that followed. He was good at building relationships. He was good at inserting himself into rooms where the people with power were, and presenting himself as someone who also had power.
While in London and later internationally, he developed a close relationship with Riza Aziz — whose mother, Rosmah Mansor, would later marry Najib Razak, the man who became Prime Minister of Malaysia. These relationships — the British school, the American university, the political connections through Riza — were the infrastructure Low built before 1MDB existed.
By his late twenties he was moving between Kuala Lumpur, Abu Dhabi, Singapore, London, and New York, attending events that mixed finance, politics, and entertainment with a specific kind of aspiration. He was present at parties with celebrities. He was present in rooms with sovereign wealth fund officials. He was present at the kind of gathering where a young man who presents himself as having access to serious money is treated as someone who has access to serious money.
He had not yet committed any crime. He was building the access that would, according to US prosecutors, later be used to commit one.
1Malaysia Development Berhad was established in 2009 as a Malaysian state strategic development company — a sovereign fund intended to attract foreign investment, develop infrastructure, and generate long-term returns for the Malaysian people. It was a government vehicle, wholly owned by the Malaysian Ministry of Finance. The money it raised was public money. The people it was supposed to serve were Malaysian citizens.
Sovereign wealth funds of this kind are not inherently unusual. Countries around the world — Norway, Singapore, Abu Dhabi, Kuwait — manage large state funds that invest nationally and internationally, generating returns that benefit the country's citizens. The model is legitimate and well-established. 1MDB was established in that tradition.
What allegedly happened to it was not in that tradition. According to the United States Department of Justice's civil forfeiture complaints and criminal charges, approximately $4.5 billion was siphoned from 1MDB through a complex network of transactions, shell companies, and international banking relationships. [SOURCE: DOJ civil forfeiture complaints — these are allegations; Low has not been convicted]
The mechanism, at its most basic: 1MDB raised money through bond issuances and joint ventures. The money raised was supposed to be invested. Instead, the DOJ alleged, a substantial portion was diverted — moved through intermediary accounts, converted into assets, and spent on things that had nothing to do with Malaysian infrastructure or development. [SOURCE: DOJ civil forfeiture filings — alleged]
The money had an owner from the beginning. That is what makes 1MDB distinct in this series. Madoff's victims were investors who had chosen to trust him. Holmes's investors were sophisticated funds and wealthy individuals. Ignatova's victims were millions of people who had opted into OneCoin. The money in 1MDB had a different character: it was the Malaysian people's money, administered by a government vehicle, and the Malaysian people had not chosen anything. It was simply taken — allegedly.
The United States government filed civil forfeiture actions beginning in 2016, seeking the recovery of assets it alleged were purchased with money stolen from 1MDB. The complaints describe, in considerable detail, what the money allegedly bought. [SOURCE: DOJ civil forfeiture complaints — all figures below are allegations]
Real estate. Multiple high-end properties in New York, Los Angeles, London, and elsewhere were among the assets the DOJ alleged were purchased with 1MDB proceeds. The New York properties included luxury apartments in buildings that represent the most expensive residential real estate in the United States.
Art. The DOJ alleged that works by Monet, Picasso, Basquiat, and others — a collection valued at hundreds of millions of dollars — were purchased with proceeds. These were not financial investments in the conventional sense. They were physical assets that could be held, displayed, lent, and sold.
The Equanimity. A 300-foot superyacht, valued at approximately $250 million, was alleged to have been purchased with 1MDB funds. The yacht was eventually seized by Indonesian authorities at the request of the US government and transferred to Malaysia. [SOURCE: WSJ reporting; DOJ filings — allegation]
Jewellery. The DOJ alleged that jewellery purchased for Rosmah Mansor — the wife of Prime Minister Najib Razak — was paid for with 1MDB money. This allegation intersects with the Najib case.
The film. Red Granite Pictures — the production company that made The Wolf of Wall Street — was alleged to have been funded with 1MDB proceeds. Red Granite settled a US forfeiture action for approximately $60 million without admitting wrongdoing. The settlement is documented. The source of the funds is alleged. [SOURCE: DOJ forfeiture settlement — verify exact $60M figure before publication]
Parties. Celebrity events. The kinds of gatherings that generate photographs and social media footage — people with extraordinary wealth in rooms where that wealth is displayed — were allegedly funded with this money. The optics were the point. The presence at these events was itself a form of credential.
This is the loop the case closes. State it plainly.
Red Granite Pictures was a Hollywood production company co-founded by Riza Aziz, the stepson of Malaysian Prime Minister Najib Razak. Low had developed a close relationship with Riza in London, in the years before 1MDB became the dominant fact of both their lives.
Red Granite produced The Wolf of Wall Street in 2013. The film that made — in this series, a man who defrauded 1,513 clients of approximately $200 million — into a global cultural icon was produced by a company that the US government alleged was funded with money stolen from Malaysia's people.
The United States Department of Justice filed a civil forfeiture action targeting, among other assets, money that had flowed through Red Granite. In 2017, Red Granite settled the action for approximately $60 million without admitting wrongdoing. [SOURCE: DOJ forfeiture settlement — exact figure needs primary verification]
Riza Aziz was separately charged in Malaysia. His case proceeded through Malaysian courts.
The Wolf of Wall Street, the film, received no formal sanction. It continues to exist as a film. It continues to be watched. It continues to make Belfort famous. The money that allegedly funded its production has been the subject of a settled forfeiture action. The relationship between the production and the alleged fraud is documented in the DOJ filings. What the audience sees when they watch the film — DiCaprio screaming on a yacht, Belfort living a life of extraordinary excess — was made possible by financing that the US government alleged came from an extraordinary theft.
Najib Abdul Razak was the sixth Prime Minister of Malaysia. He served from 2009 to 2018. 1MDB was established under his government in 2009. He sat on its advisory board. His stepson was connected to the production company the DOJ alleged was funded with 1MDB money. His wife was alleged to have received jewellery purchased with 1MDB proceeds.
These are allegations about the 1MDB case. What is not an allegation is the verdict.
In 2018, after the ruling coalition he had led for decades lost a general election — the first time in Malaysian history that the coalition had lost power since independence — Najib was arrested and charged. The case against him proceeded through the Malaysian court system.
He was convicted on seven counts: criminal breach of trust, money laundering, and abuse of power. [SOURCE: Malaysian court record] These are convictions. They are facts in the same sense that Madoff's guilty plea is a fact or that 's jury verdict is a fact. Najib Razak was convicted on seven counts by a Malaysian court. His appeal processes have proceeded.
The precedent is historical. Malaysia had never before convicted a sitting or former prime minister. The conviction was, in the context of Malaysian political history, an event without equivalent.
This is the specific dual structure that makes Case 014 unusual in the series. () is also a fugitive — but her co-defendants were convicted, not her government. Here the alleged architect remains free, the alleged political enabler was convicted, and the country itself was the victim.
On December 24, 2019, Taek Jho Low was reportedly seen at Shanghai Disneyland.
It is Christmas Eve. He is reportedly at a theme park in China. By this point he has been a named subject of DOJ investigation since 2016, has had an Interpol notice issued against him, has had his St Kitts and Nevis citizenship revoked, and is a global fugitive by any reasonable characterisation of the word.
He has not been publicly confirmed as located anywhere since.
This is the second case in this series — after Ignatova — where a central subject has vanished. But where Ignatova's disappearance has a possible murder hypothesis attached to it, Low's disappearance has a different character: he is almost certainly alive, likely in a jurisdiction with limited extradition arrangements with the countries seeking him, and almost certainly in contact with lawyers and advisors. He is not gone in the way Ignatova might be gone. He is hidden.
China has been consistently suggested as his location of refuge, given the Shanghai Disneyland sighting and the complexity of extradition arrangements. [SOURCE: widely reported — secondary sources; not confirmed by any official body] China has not extradited him. He has not surfaced in any court.
His St Kitts and Nevis citizenship, acquired in 2011 to provide an additional travel document, was revoked in 2019. His Cyprus citizenship, acquired in 2015, was revoked in 2024. The citizenship revocations represent the systematic removal of the travel infrastructure he had built — passport by passport.
He remains on Interpol's wanted list. He remains subject to US criminal charges. He remains, as of this writing, at large.
Jho Low maintains his innocence.
Through statements issued by his representatives — typically through lawyers and press agents rather than in-person appearances — he has consistently denied the allegations against him. His position, stated publicly and consistently: the charges are part of a 'campaign of harassment and political persecution' connected to his prior association with and support of Najib Razak and the political faction that Najib represented.
He contends that the 1MDB investigation, as conducted by the Malaysian authorities who came to power after Najib's coalition lost the 2018 election, is politically motivated — an attempt by a new government to use the legal system against figures associated with the old government.
He has never been tried. He has never had the opportunity to present a full defense in court, because he has not been present in any court to present one. The allegations the DOJ has made against him are, in the strict legal sense, unproven — not because evidence does not exist but because no trial has occurred.
This defense must be included and stated clearly. It is part of the record. He is a living person who has not been convicted of anything. The discipline of alleged/convicted that runs through this entire document requires that his denial be given the same weight as the allegation.
The series thesis for Case 014 is this: the fund.
Every other case in this series is a private fraud. defrauded individuals and institutions who had chosen to trust him. Madoff defrauded investors who had opted in. Holmes defrauded investors who had written checks. Ignatova defrauded 3.5 million people who had bought a product. Even Stanford's fraud — the case this most closely resembles in scale and geography — targeted individual investors who had purchased certificates of deposit.
1MDB was different. The money was never offered to investors in the ordinary sense. It was raised in the name of a country — by a government fund, through bond issuances that committed the Malaysian state — and then allegedly diverted. The 30 million people of Malaysia had not chosen anything. They had not purchased anything. They did not know the fund existed in any meaningful sense. The money was theirs by virtue of being citizens of a country whose government controlled it.
That is the specific character of this case that distinguishes it. And the consequence was proportionate: not just financial losses to identifiable investors, but a political catastrophe — the fall of a government, the conviction of a prime minister, the exposure of state-level corruption at a scale that Malaysia had not seen before.
The 1MDB scandal is one of the reasons Najib Razak's coalition lost the 2018 election. It is one of the reasons he was subsequently arrested and convicted. The fraud — if proven in Low's case, which it has not been — had an electoral consequence. It changed a country's government.
And it allegedly funded a movie. The Wolf of Wall Street. The film that took a fraud that cost $200 million and made it into a legend. The money that was supposed to develop Malaysia built DiCaprio's award platform.
That loop — from Malaysian infrastructure fund to Hollywood production to global celebrity for a convicted boiler-room operator — is one of the more vertiginous connections in the history of financial fraud. It is documented in DOJ filings. It is alleged in the sense that Low has not been convicted. The settlement is real. The film exists.
The central discipline: Low is alleged. Najib is convicted. Every dollar figure attached to Low is from DOJ civil forfeiture complaints — allegations, not adjudication. Najib's seven-count conviction is Malaysian court record — documented fact. Low maintains innocence throughout.
VERIFY BEFORE PUBLICATION Red Granite settlement exact figure ($60M) · Najib's current sentence/appeal status · Shanghai Disneyland sighting — confirm sourcing (widely reported, secondary only) · Interpol notice type · Exact citizenship revocation dates for St Kitts (2019) and Cyprus (2024)
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
SBF VS CZ — THE SAME ERA, THE DIFFERENT CRIME
NOT THE SAME CASE
Judge Richard A. Jones · Seattle · April 30, 2024 [SOURCE: CNBC / AP]
THE PARDON — OCTOBER 23 2025
FULL AND UNCONDITIONAL — PRESIDENT TRUMP
CZ via X · October 23, 2025 [SOURCE: Axios / AP]
The pardon erases his conviction and restores his civil rights. It does NOT affect the $4.3B Binance company penalty — the corporate settlement stands. The DOJ’s findings about what Binance allowed to happen are part of the historical record. The pardon removes the personal criminal conviction. It does not change what the exchange did. White House: “no allegations of fraud or identifiable victims” — a framing contested by the DOJ’s own filings. [SOURCE: AP / Reuters / Axios, Oct 23 2025]
Part of a broader pattern: Trump also pardoned () and three BitMEX founders who had also pleaded guilty to BSA violations. [SOURCE: Fortune, May 2025]
CASE TIMELINE
HOW THE FRAUD WORKED
THE POINT OF THIS CASE — FROM THE CASE BRIEF
KNOWN NETWORK & CONNECTED CASES
WHAT THIS CASE ESTABLISHED
BIOGRAPHY & BINANCE BACKGROUND
EARLY LIFE & CAREER
THE COMPLIANCE FAILURE — WHAT BINANCE DID WRONG
THE PARDON & THE RATIO
THE UNPRECEDENTED SENTENCE
THE PARDON — OCTOBER 23, 2025
THE $4.3B vs $50M RATIO
THE FULL STORY — 7 PARTS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE DOOR (2,600 WORDS)
In November 2022, FTX collapsed. had taken $8 billion in customer funds and used them to cover losses at his trading firm. He was convicted on all seven counts. He is serving 25 years in federal prison in California.
The man whose tweet — announcing Binance would sell its FTT holdings — triggered the bank run that ended FTX was Changpeng Zhao. CZ. The founder and CEO of Binance, the largest cryptocurrency exchange in the world by trading volume.
One year after FTX collapsed, on November 21, 2023, CZ pleaded guilty in federal court in Seattle. His charge: one count of failing to maintain an effective anti-money-laundering program, in violation of the Bank Secrecy Act. Binance simultaneously agreed to a resolution with the US Department of Justice totalling $4.3 billion — one of the largest corporate penalty settlements in American history.
He was sentenced to four months in federal prison. He served them. He was released in September 2024.
On October 23, 2025, President Donald Trump granted him a full and unconditional presidential pardon. [SOURCE: AP / Reuters / Axios / White House, October 23, 2025]
These two men — and CZ — are the two dominant figures in the crypto exchange story of this era. Their cases are not the same case. The series treats them as separate because they are separate. committed fraud. CZ failed at compliance. The distinction is not a technicality. It is the entire moral and legal difference between the two outcomes.
Changpeng Zhao was born on September 10, 1977, in Jiangsu province, China. He emigrated to Canada with his family in the late 1980s and grew up in Vancouver. He attended McGill University in Montreal, where he studied computer science.
His career before crypto was in finance and technology: he worked at the Tokyo Stock Exchange, at Bloomberg Tradebook on their futures-trading systems, and eventually at firms with cryptocurrency exposure including OKCoin. By 2017 he had enough understanding of both the technology and the trading mechanics to found his own exchange.
He founded Binance in 2017 with an initial coin offering, originally based in Hong Kong. The timing was exceptional: the 2017 crypto bull market was accelerating, retail interest in cryptocurrency was exploding globally, and there was genuine demand for an exchange that offered more tokens with lower fees than the existing platforms. Binance grew with extraordinary speed.
By the early 2020s, Binance was the largest cryptocurrency exchange in the world by trading volume. Not one of the largest — the largest. It processed more trades, in more currencies, with more users, than any other platform. CZ was one of the wealthiest people in the world, with a net worth estimated in the tens of billions at peak, though most of that wealth was tied to the value of BNB, Binance's own token. He was, by any reasonable measure, one of the most powerful individuals in cryptocurrency.
The Bank Secrecy Act requires US financial institutions to know who their customers are, to monitor their transactions, and to file reports of suspicious activity. This is the foundational anti-money-laundering framework for American finance — the infrastructure that makes the financial system harder to use for drug trafficking, terrorism financing, sanctions evasion, and other illicit purposes.
Binance violated it. That is the plea. That is the conviction — or rather, the conviction before the pardon. What the DOJ found:
First: Binance failed to register as a money services business as required under US law, even while serving US customers. The company claimed, including through geolocation restrictions and IP blocking measures, that it did not serve US customers. The DOJ found this claim was not implemented effectively — US customers continued to transact on the platform. [SOURCE: DOJ press release, November 2023]
Second: Binance failed to implement an adequate Know Your Customer programme. For years, users could open accounts and trade without providing meaningful identifying information. The 'know your customer' requirement exists specifically to prevent the exchange from becoming a conduit for illicit finance. Binance's implementation of this requirement was, per the DOJ, inadequate.
Third: As a consequence of these failures, Binance processed transactions connected to entities and activities that US sanctions law prohibited. The DOJ stated that Binance processed transactions for users with connections to Hamas, al-Qaeda, ISIS, and darknet markets. [SOURCE: DOJ plea agreement; AP coverage of sentencing] These are not allegations in the uncertain sense — they are part of a guilty plea. They happened.
The scale of these failures — across the world's largest exchange, over years of operation, while the company actively sought to avoid US regulatory oversight — is what made this the largest corporate settlement the DOJ had reached with a cryptocurrency business at the time. [SOURCE: DOJ November 2023]
He was not charged with fraud. He was not charged with misappropriation. He was not charged with stealing customer deposits. He was not accused of taking money that belonged to his customers and using it for anything.
This distinction matters because the public narrative around CZ — particularly in the period after FTX's collapse, when he was the most prominent remaining figure in major crypto exchanges — sometimes carried the implication that he was the same kind of actor as . He was not.
Binance's customers, as of this writing, can access and withdraw their funds. The exchange did not collapse. There was no bankruptcy. There was no $8 billion hole in the balance sheet. The compliance failures were real and serious — the transactions that moved through Binance included proceeds of crimes that harmed real people — but the mechanism of the harm was different from the mechanism in the FTX case.
The FTX harm: customers deposited money expecting it to be held safely, and it was taken. The customers were the direct victims.
The Binance harm: criminals used the exchange to move proceeds of their crimes because the exchange did not implement adequate controls to stop them. The exchange's customers were not the victims. The victims of the underlying crimes were the victims — and the exchange's failure made it easier for those crimes to continue profiting.
Both harms are real. They are not the same harm. The legal system recognised this, and the sentence reflects it: 25 years for , 4 months for CZ. The White House, when announcing the pardon, stated that CZ's prosecution involved 'no allegations of fraud or identifiable victims.' [SOURCE: White House / Axios, October 23, 2025] That framing is contested by the DOJ's own filing, which identifies specific categories of crime enabled. But the structural difference between the two cases is accurately stated.
The penalty structure is where this case is most unusual in the series. The gap between the company's payment and the individual's fine is the story.
Binance agreed to pay $4.3 billion to resolve the DOJ, Treasury/FinCEN, and CFTC actions. This is one of the largest corporate penalty resolutions in the history of financial enforcement. It included fines and forfeiture across multiple agencies. [SOURCE: DOJ November 2023; Bloomberg analysis]
CZ's personal fine: $50 million. [SOURCE: DOJ plea agreement]
The ratio: the company paid 86 times what CZ paid personally. This structure — massive corporate penalty, relatively modest personal fine, short prison term — reflects the DOJ's assessment of the case as a compliance failure by a business that had grown faster than its regulatory infrastructure, rather than a personal fraud committed by an individual who set out to steal.
The $4.3 billion is a company number. It belongs to Binance. It represents the value the DOJ assessed for years of inadequate controls at the world's largest crypto exchange. It must not be attributed to CZ as a personal liability or a personal theft figure. He personally paid $50 million. These are different numbers measuring different things.
He also stepped down as CEO of Binance as part of the plea. Richard Teng has run the exchange since. CZ retained his equity stake.
When Judge Richard A. Jones sentenced Changpeng Zhao to four months in federal prison in April 2024, he was sentencing the first person in American history to receive a prison term for a single violation of the Bank Secrecy Act.
This is not a minor historical footnote. The Bank Secrecy Act has been in existence since 1970. It is the foundational anti-money-laundering law of the United States. Violations of it have resulted in corporate fines, regulatory actions, and civil penalties across the entire history of the modern financial system. Nobody had ever gone to prison for a single count of BSA violation before CZ.
The DOJ sought 36 months. CZ's lawyers sought no prison time. Judge Jones imposed 4 months — below the DOJ's request, above zero, and historically unprecedented for the specific charge. [SOURCE: AP / Reuters sentencing coverage, April 2024]
The unprecedented nature of the prison sentence is itself a data point about the scale of the failure. The DOJ had determined that the world's largest crypto exchange had operated in violation of anti-money-laundering law for years, at a scale and with consequences — the Hamas, al-Qaeda, ISIS, darknet market transactions — that justified a penalty that had never been applied to this charge before.
He reported to FCI Lompoc in California in June 2024. He was released in September 2024 after serving approximately four months. The prison was minimum security.
On October 23, 2025, President Donald Trump granted Changpeng Zhao a full and unconditional presidential pardon.
CZ had applied for the pardon in 2025, after serving his sentence. He acknowledged the application publicly, noting that he was 'the only one in US history who was ever sentenced to prison for a single BSA charge.' [SOURCE: Fortune, May 2025; CZ via X]
White House Press Secretary Karoline Leavitt announced the pardon and characterised Zhao's prosecution as part of the Biden administration's 'war on cryptocurrency.' She stated there had been 'no allegations of fraud or identifiable victims' in the case. [SOURCE: Axios / AP, October 23, 2025]
The pardon erases his conviction and restores his civil rights. He posted on social media: 'Deeply grateful for today's pardon and to President Trump for upholding America's commitment to fairness, innovation, and justice.' [SOURCE: CZ via X, October 23, 2025]
What the pardon does not erase: the $4.3 billion Binance penalty. The company's settlement stands. The DOJ's findings about what Binance allowed to happen — the sanctioned-entity transactions, the BSA violations, the inadequate AML programme — are part of the historical record. The pardon removes CZ's personal criminal conviction. It does not change what the exchange did.
The pardon also fits a broader pattern. In his second term, Trump pardoned multiple crypto industry figures including (whose life sentence for the Silk Road dark web marketplace was terminated), and three founders and an executive of BitMEX — who had also pleaded guilty to BSA violations. [SOURCE: Fortune, May 2025] CZ's pardon was the highest-profile of these, given Binance's scale.
The thesis for Case 015 is the door.
He built Binance — the world's largest cryptocurrency exchange — without building the controls that the law requires to prevent that exchange from being used for money laundering, sanctions evasion, and the financing of organisations designated as terrorist by the United States government. The controls were inadequate. The door, in the relevant sense, was not guarded.
The series argument: every other case in this collection is about people who took money, or built a fake product, or ran a scheme. CZ's case is about what happens when you build something real and powerful and don't build the compliance infrastructure around it.
Binance processed genuine transactions for genuine users. It was a real exchange running real trades in real currencies for real people who wanted to trade cryptocurrency. The compliance failures were failures of an institution that was growing faster than its regulatory framework — not a fraud designed to steal from customers.
That is not an excuse. The transactions that moved through Binance because the controls were inadequate — the Hamas-connected transactions, the ISIS-connected transactions, the darknet market transactions — had real-world consequences. The people whose crimes were made easier by a non-compliant exchange were doing things that harmed people. The exchange's compliance failure was a material contribution to that harm, even though CZ was not the person doing the harm.
He built the door. He did not guard it. The company paid $4.3 billion. He served 4 months. Then a president pardoned him, framing the prosecution as the prior administration's 'war on cryptocurrency' and characterizing the BSA violation — a compliance failure without direct victims in the FTX sense — as regulatory overreach.
The ratio is the story: $4.3 billion from the company, $50 million from the individual, 4 months in a minimum-security prison, then a full pardon. That is the structure of accountability for the world's largest crypto exchange running an inadequate anti-money-laundering programme for years. Whether that ratio reflects proportionate justice is a question this series leaves for the reader — but the numbers are the record and they speak plainly.
$4.3B = Binance company penalty. $50M = CZ personal fine. Never combine. NOT charged with fraud, theft, or misappropriation. Conviction erased by pardon October 23, 2025 — $4.3B company penalty not affected. He was the first person ever sentenced to prison for a single BSA violation.
VERIFY BEFORE PUBLICATION Exact BOP entry and release dates · $1.8B forfeiture vs fine breakdown within the $4.3B · Exact sanctioned entity names in the DOJ plea agreement · Exact Binance user count cited in DOJ filings
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD [ALLEGED]
CO-DEFENDANTS — CONVICTED
THE MURDER HYPOTHESIS — REPORTED AS HYPOTHESIS ONLY
WHAT THE JOURNALISM SAYS — AND WHAT IT DOESN’T
In February 2023, Bulgarian investigative outlet BIRD published a police document found in the safe of a dead police officer. The document described an informant account from a yacht trip in Cuba, in which a Bulgarian crime figure’s brother-in-law claimed a hit had been ordered on Ignatova.
The FBI has not confirmed her death. She remains on the Ten Most Wanted list. The reward is active. The FBI’s official position: she is a living fugitive. This case file reports the hypothesis as exactly that: a hypothesis sourced to named investigative journalism, not confirmed fact.
WHAT THIS CASE ESTABLISHED
BACKGROUND & RISE
EARLY LIFE & EDUCATION
ONECOIN — THE OPERATION
THE DISAPPEARANCE & OPEN STATUS
THE VANISHING
CO-DEFENDANTS — THE ONES WHO WERE CAUGHT
CASE TIMELINE
HOW IT WORKED
HOW ONECOIN WORKED — AS PROSECUTORS DESCRIBE IT
THE FULL STORY — 10 PARTS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE ONE WHO VANISHED (4,200 WORDS)
On October 25, 2017, Ruja Ignatova boarded a flight in Sofia, Bulgaria, bound for Athens, Greece.
She was 37 years old. She had, according to the US government's indictment, spent the preceding three years building one of the largest financial fraud schemes in modern history — a fake cryptocurrency called OneCoin, marketed to millions of people in dozens of countries as the investment that would make them rich the way Bitcoin had made others rich, if only they had been early enough.
She had not been early enough. She had been smarter. She had skipped the part where you actually need a blockchain and gone directly to the part where you collect the money.
The sealed US indictment against her had been filed on October 12, 2017 — thirteen days before she left. She had, authorities believe, been tipped off. [SOURCE: FBI / SDNY]
She landed in Athens. She has not been seen publicly since.
When the FBI added her to its Ten Most Wanted Fugitives list in 2022, she was the only woman on it. The reward for information leading to her arrest, first set at $100,000, now stands at up to $5 million. [SOURCE: FBI, June 30, 2022; US State Department, June 26, 2024] Her co-founder is in prison for 20 years. Her brother was released after 34 months. The lawyer who laundered OneCoin money is serving 10 years. Her other partners are in custody, convicted, or cooperating.
Ruja Ignatova is the only person at the centre of this case who has not been found.
Almost every other case in this series ends. is in prison. pleaded guilty. is sentenced. Madoff died in custody. is in California. Holmes is in Texas. Case 008 has no ending yet. She left on a flight and has not come back.
Ruja Ignatova was born in 1980 in Ruse, Bulgaria — a city on the Danube, on the border with Romania, the kind of mid-sized Eastern European provincial capital that produced people who were either very good at finding their way out of it or very determined to stay.
She was very good at finding her way out. When she was ten years old, her family emigrated to Germany — to Schramberg, a small manufacturing town in Baden-Württemberg in the south of the country. She learned the language. She integrated. She was, by all accounts, academically exceptional.
She studied law. She obtained a doctorate in European private law from the University of Konstanz in Germany — a research university with a strong reputation in European law. She is sometimes described as having studied at Oxford; what can be confirmed is a period of study there as part of her European legal education. [SOURCE: widely reported — verify exact Oxford credential against primary before publication]
She worked for McKinsey and Company — the management consulting firm — and for a Bulgarian company called Walch Management, which ended in legal controversy and fraud allegations that preceded OneCoin. [SOURCE: widely reported from public record] She had, before OneCoin, already had a confrontation with questions about her business conduct.
She was intelligent, credentialed, multilingual, and comfortable in rooms where serious people talked about serious money. She was also, by the time she created OneCoin, someone who understood how to use the appearance of legitimacy to open doors that would otherwise remain closed.
In 2014, she and Karl Sebastian Greenwood co-founded OneCoin.
Bitcoin had already made some people very rich. Not most people. The people who had been early enough, who had believed in the thing before belief was the obvious position, who had held through the years when nobody treated it seriously — those people were now sitting on returns that made any conventional investment look embarrassing.
The people who had missed that window were looking for the next one. They were looking for someone who could tell them, credibly, that the next window was open and that they were not too late.
Ruja Ignatova told them she was that person. OneCoin, she said, was better than Bitcoin. It was faster, more scalable, more practical, more suitable for real-world commercial use. It would not just match Bitcoin — it would replace it. It was the Bitcoin killer. [SOURCE: CNN citing US Attorney Williams / SDNY sentencing statement]
To invest in OneCoin was to be early to the thing that would dwarf the thing you had already missed. The pitch addressed the specific regret of the people who had watched Bitcoin's rise from the outside. You were not too late. You had found it.
OneCoin did not have a blockchain. This is not a technical critique of its design. It is the fact that defines the fraud: a cryptocurrency — by definition — is a digital asset recorded on a distributed public ledger called a blockchain. Every transaction is verified by the network and recorded permanently. This is what makes cryptocurrency cryptocurrency rather than a number in a database.
OneCoin had no blockchain. The 'coins' that investors received were numbers entered into an internal company database. There was no public ledger. There was no mining. There was no verification network. There was no cryptocurrency. There was a number in a spreadsheet with a name next to it, and the name next to the number belonged to someone who had paid real money for it. [SOURCE: SDNY / DOJ / widely documented from case record]
She knew this. According to the US government's case, Greenwood knew it too. 'The pair knew it was a scam from the start,' US prosecutors said at sentencing. [SOURCE: CNN citing DOJ, September 2023]
There was no blockchain. The product that was going to beat Bitcoin did not share the one property that makes Bitcoin what it is. The investment opportunity of a lifetime was a number in a database with no external verification, no public ledger, and no value beyond the belief that the next person would also believe.
She called herself the CryptoQueen. And she performed the role with the kind of commitment that distinguishes a fraud that runs for three years from one that is detected in three months.
She held events — large, staged events in conference centres and arenas, where she appeared in designer clothes, with a polished presentation, explaining why OneCoin was the future of finance. The events were productions: the graphics, the rhetoric, the crowd energy, the sense of being present at something historic.
She spoke about her credentials: the education, the McKinsey background, the legal expertise. She positioned herself as someone who understood finance and technology at a level that most investors did not, and who was therefore in a position to see what they could not see: that the next wave was already forming, and that the people in this room were about to ride it.
The multi-level marketing structure compounded the effect. OneCoin was sold through a network in which investors were also sellers — they were incentivised to bring in new investors, who in turn were incentivised to bring in more. The structure turned believers into salespeople. The more people you recruited, the more you earned. Your returns depended not just on the coin's value but on the performance of the people you had brought in below you.
This is the classic pyramid structure. The FBI, in its formal description of the scheme, used the phrase 'multi-level marketing strategy that urged OneCoin investors to sell additional packages to friends and family.' [SOURCE: FBI press release, June 30, 2022] The people who were being defrauded were also, structurally, the people doing the defrauding of the next level down. Everyone was simultaneously victim and recruiter.
Special Agent Ronald Shimko of the FBI described Ignatova as targeting people 'who may not have fully understood the ins and outs of cryptocurrencies but were moved by Ignatova's impressive resume and the marketing strategies used by OneCoin.' [SOURCE: FBI press release, June 30, 2022] The credential and the pitch were designed for each other.
Karl Sebastian Greenwood was the other architect of OneCoin. A citizen of Sweden and the United Kingdom, 46 years old at sentencing, a salesman whose 'mastery as a salesman' federal prosecutors credited with helping build OneCoin's initial success. [SOURCE: CNN citing DOJ, September 2023]
He worked alongside Ignatova from the beginning. Together they pitched OneCoin as the Bitcoin killer — 'promising a financial revolution' and selling the story of a coin that would replace the one that everyone had already heard about. The investors who had missed Bitcoin were the audience. Greenwood was part of the delivery mechanism for the message.
When Ignatova disappeared in October 2017, Greenwood continued. He ran the operation with what remained of the leadership. Nine months after Ignatova vanished, he was arrested in Thailand in July 2018. [SOURCE: CNN / KTVZ]
He pleaded guilty to wire fraud and money laundering. The government presented evidence that he had personally misappropriated more than $300 million — to five-star resorts, villas, a private jet, and a yacht. [SOURCE: DOJ/Forklog, citing sentencing statement, September 2023]
On September 12, 2023, Judge Edgardo Ramos sentenced Karl Sebastian Greenwood to 20 years in federal prison and fined him $300 million. US Attorney Damian Williams: 'Greenwood and his co-conspirators, including fugitive Ruja Ignatova, conned unsuspecting victims out of billions of dollars with promises of a financial revolution... In fact, OneCoins were entirely worthless, and investors were left with nothing.' [SOURCE: CNN citing DOJ, September 2023]
Ruja Ignatova recruited her brother to work as her personal assistant. Konstantin Ignatov had been working as a forklift driver in Germany. She offered him a job. He took it.
After she disappeared in October 2017, Konstantin became the de facto leader of the OneCoin operation — the face who appeared at events, the person who managed the remaining structure, the one who kept the machine running for the two years between her disappearance and his arrest. [SOURCE: Bloomberg, March 2024]
He was arrested in March 2019 at Los Angeles International Airport. He pleaded guilty to conspiracy to commit wire fraud and money laundering, and began cooperating with prosecutors. His cooperation included testimony in the case against Mark Scott, the lawyer who laundered hundreds of millions of dollars for the OneCoin operation.
His sentencing was delayed for years as prosecutors worked their way through related cases. On March 5, 2024, Judge Edgardo Ramos sentenced Konstantin Ignatov to time served — the 34 months he had already spent in custody. He was also ordered to forfeit $118,000. [SOURCE: Bloomberg, March 5, 2024; The Informer Post]
At sentencing, he took full responsibility: 'I have only myself to blame. The last five years have been a very painful period in my life, but I am grateful for the lessons I have learned.' [SOURCE: ForkLog citing Law360, sentencing hearing]
He was ordered to spend two years under court supervision. He was a forklift driver before his sister called him. He cooperated against her operation and walked out of the courtroom.
Mark Scott was a lawyer. He handled the laundering.
Scott was a former partner at the law firm Locke Lord — a real, established American law firm. He agreed to launder nearly $400 million in OneCoin proceeds, moving the money through a network of investment funds he controlled, disguising its origin through layers of transactions across jurisdictions. [SOURCE: Forklog; Bloomberg citing DOJ]
He was convicted in November 2019 after a jury trial in New York — testimony at his trial came from Konstantin Ignatov, among others. He was sentenced on January 25, 2024 to 10 years in federal prison. [SOURCE: Forklog]
The $400 million he laundered is not the total scale of the fraud. It is the amount that passed through his specific operation. The broader OneCoin fraud is characterised by the DOJ as exceeding $4 billion. Scott handled one piece of the money movement.
The sealed indictment against Ruja Ignatova was filed on October 12, 2017, by the US Attorney's Office for the Southern District of New York. [SOURCE: SDNY / FBI] It was sealed — meaning it was not publicly disclosed. Someone told her it existed.
Thirteen days later, on October 25, 2017, she boarded a Ryanair flight from Sofia, Bulgaria to Athens, Greece. This is the last confirmed sighting — the last time her location is known with certainty from any public record.
She landed in Athens. She has not been seen publicly since.
What happened next is, in the strictest sense, unknown. The FBI believes she may travel on a German passport to the United Arab Emirates, Bulgaria, Germany, Russia, Greece, and/or Eastern Europe. [SOURCE: FBI official listing] This is not a confirmed location — it is an assessment of where she might go based on her known connections and travel history.
A superseding indictment was issued in 2018, adding charges. The charges now include: conspiracy to commit wire fraud, wire fraud, conspiracy to commit money laundering, conspiracy to commit securities fraud, and securities fraud. [SOURCE: FBI; SDNY]
In June 2022, the FBI added her to its Ten Most Wanted Fugitives list. She became the only woman on the list. A $100,000 reward was announced; the US State Department raised it to up to $5 million in June 2024. [SOURCE: FBI press release, June 30, 2022; US State Department, June 26, 2024]
She has been on that list for over four years as of this writing. She has not been found.
THE DEPARTURE — CONFIRMED FACTS ONLY: October 12, 2017: Sealed US indictment filed against Ignatova. [SDNY]
October 25, 2017: Ignatova boards Ryanair flight from Sofia to Athens. [FBI]
After Athens: location unknown. FBI believes she may travel on German passport to UAE, Bulgaria, Germany, Russia, Greece, Eastern Europe.
What is NOT confirmed: why she left, who tipped her off, where she went after Athens, whether she is still alive.
She has not been arrested, extradited, or found. The FBI has not confirmed her death.
In February 2023, the Bulgarian investigative outlet BIRD — the Bureau for Investigative Reporting and Data — published a police document.
The document had been found in a safe in the apartment of a Bulgarian police officer who had been shot dead in March 2022. Inside the safe was a one-page report describing an exchange during a yacht trip in Cuba. An informant had reported that the brother-in-law of Christophoros Amanatidis — known as 'Taki,' described as a Bulgarian crime boss — had been drinking and had told the informant that Taki had ordered a successful hit on Ruja Ignatova. According to this account, she was killed on another yacht.
Atanas Tchobanov — a journalist at BIRD who has worked with the International Consortium of Investigative Journalists — told Fortune Magazine directly: it is 'a hypothesis.' 'It's not conclusive.' [SOURCE: Fortune, February 24, 2023, citing BIRD / Tchobanov]
The FBI has not confirmed that Ruja Ignatova is dead. She remains on the Ten Most Wanted list. The reward remains active. The FBI's official position is that she is a fugitive at large.
This piece reports the hypothesis as a hypothesis. It is documented. It is sourced to named journalism. It is also — in the word of the journalist who reported it — not conclusive.
EDITORIAL STANDARD ON THIS SECTION: The murder hypothesis is sourced to BIRD (Bulgarian investigative outlet) and confirmed by a named journalist (Tchobanov) to Fortune as 'not conclusive' and 'a hypothesis.'
The FBI has NOT confirmed Ignatova's death. She remains an active fugitive on the Ten Most Wanted list.
This piece states: the hypothesis exists, the source is credible investigative journalism, the FBI's position is that she remains at large.
We do not state she is dead. We do not state she is alive. The record does not allow either conclusion.
The numbers in this case require the same labelling discipline applied to every case in this series.
$4 billion: this is the FBI's and DOJ's characterisation of the total amount defrauded across the OneCoin scheme. [SOURCE: FBI press release; DOJ/Williams statement] It represents money that investors around the world paid into the OneCoin system in exchange for coins that were, in the government's characterisation, worthless.
$300 million: the amount Greenwood personally misappropriated, per the DOJ, spent on five-star resorts, villas, private jet, and a yacht. [SOURCE: DOJ, September 2023]
$400 million: the amount Mark Scott laundered — one piece of the money movement, not the total fraud.
3.5 million: the number of people who invested in OneCoin, per the DOJ at Greenwood's sentencing. [SOURCE: DOJ/Williams; CNN] These were people in dozens of countries — in Europe, in Asia, in Africa, in the Americas. Many of them were not sophisticated investors. Many of them were people who had heard about Bitcoin and believed they had found the next version of it, backed by a credentialed professional who spoke to them at events and told them the future of finance was here.
They were left with nothing. The coins they had were numbers in a database with no external value and no market. When the operation collapsed, there was nothing to redeem them against.
FIGURE
WHAT IT MEASURES / SOURCE
$4B+
Total alleged investor losses — DOJ/FBI characterisation of the OneCoin fraud [SDNY; FBI June 2022]
$300M
Greenwood's personal misappropriation (resorts, jets, yacht) — DOJ sentencing statement [SDNY, Sept 2023]
$400M
Amount laundered by lawyer Mark Scott — his case specifically [SDNY; Forklog]
$118K
Konstantin Ignatov forfeiture ordered — time-served sentence [Bloomberg, March 2024]
3.5 million
Number of OneCoin investors worldwide — DOJ at Greenwood sentencing [CNN / SDNY]
$100,000
Original FBI reward for information leading to Ignatova's arrest [FBI, June 30, 2022] — raised to up to $5 million by the US State Department, June 26, 2024
Almost every case in this series has a resolution. Someone was convicted. Someone was sentenced. The machine stopped.
Case 008 has no resolution. The architect of the fraud is gone. The co-founder is serving 20 years. The brother is out. The lawyer who laundered the money is in. The head of compliance was prosecuted too. And the person who built the thing, who called herself the CryptoQueen, who persuaded 3.5 million people across dozens of countries to invest in a cryptocurrency that was not a cryptocurrency — she left on a flight in October 2017 and has not come back.
The series thesis for this case: the brand was the blockchain. Every other case in this series had, at some level, a real product — had a real Instagram, had a real heist, had a real (if flawed) algorithm, Madoff had a real investment firm, had a real exchange, Holmes had a real laboratory. In each case the fraud ran inside something that existed.
Ruja Ignatova's fraud had nothing inside it. No blockchain. No mining. No verification. No market. An internal database and a name: OneCoin. The name, the events, the credential, the rhetoric — these were the product. The coin itself was a number in a spreadsheet. The only thing that gave it value was the belief that the next person would also believe.
That is the purest form of the scam this series documents: not fraud layered over something real, but the appearance of something real with nothing beneath it at all. The Bitcoin killer had no Bitcoin. The CryptoQueen had no crypto.
She is still, as of this writing, wherever she is. The FBI has a reward out. Europol has a listing. The question of whether she is in a villa somewhere with money she moved before the collapse, or whether she is dead on a yacht in a story that Bulgarian investigative journalists cannot confirm, is unanswered.
The case has a $4 billion price tag, per the DOJ, 3.5 million victims, and no defendant in the dock for the original crime. It is one of only two cases in this series — with , — where the central question, where are they, is still open.
The brand was the blockchain. The CryptoQueen had no crypto. And she is one of only two people in this series who left before anyone could stop them.
FULL TIMELINE
DATE
EVENT
1980
Born in Ruse, Bulgaria
c.1990
Family emigrates to Schramberg, Germany. She grows up in Germany, learns the language, integrates.
2000s
Obtains law doctorate from University of Konstanz. Studies period at Oxford. Works for McKinsey. Bulgarian company ends in fraud allegations (pre-OneCoin).
2014
Co-founds OneCoin with Karl Sebastian Greenwood. Begins selling to investors. No blockchain. Multi-level marketing structure.
2014–2017
Builds the CryptoQueen brand. Holds events globally. Attracts 3.5 million investors. $4B+ collected. She and Greenwood knew it was fraudulent, per DOJ.
Oct 12, 2017
Sealed US indictment filed against Ignatova. SDNY. She is allegedly tipped off. [FBI / SDNY]
Oct 25, 2017
LAST KNOWN LOCATION: boards Ryanair flight, Sofia to Athens. Not seen publicly since. [FBI]
2018
Superseding indictment adds charges. Konstantin Ignatov takes over OneCoin operations. Greenwood arrested in Thailand, July 2018.
Mar 2019
Konstantin Ignatov arrested at LAX. Pleads guilty. Cooperates.
Nov 2019
Mark Scott convicted by jury — laundering ~$400M in OneCoin proceeds.
Jun 30, 2022
FBI adds Ignatova to Ten Most Wanted Fugitives list. Only woman on the list. $100,000 reward (raised to up to $5 million by the US State Department, June 2024). [FBI press release; State Department]
Feb 2023
BIRD (Bulgarian investigative outlet) publishes police document suggesting Ignatova was killed on a yacht, 2018 — ordered by crime boss 'Taki.' Journalist: 'a hypothesis... not conclusive.' FBI has not confirmed her death. [Fortune, Feb 24, 2023]
Sep 12, 2023
Greenwood sentenced: 20 years federal prison + $300M fine. Judge Ramos. SDNY. [CNN / DOJ]
Jan 25, 2024
Mark Scott sentenced: 10 years federal prison. [Forklog / DOJ]
Mar 5, 2024
Konstantin Ignatov sentenced: time served (34 months). Released. Forfeits $118,000. [Bloomberg]
Now
Ruja Ignatova: whereabouts unknown. FBI Ten Most Wanted. Reward up to $5 million. Europol listing. No arrest. No confirmation of death. The case remains open.
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
THE REAL BUSINESSES — WHAT INVESTORS COULD SEE
KNOWN NETWORK & CO-CONSPIRATORS
CASE TIMELINE
HOW THE FRAUD WORKED
THE SUPPLY CHAIN THAT WASN’T — FIVE STEPS
MADOFF (CASE 004) VS PETTERS (CASE 018)
IN THEIR WORDS
WHAT THIS CASE ESTABLISHED
THE FULL STORY — 5 PARTS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE INVISIBLE (2,000 WORDS)
Tom Petters owned Polaroid. He owned a stake in Sun Country Airlines. He had previously owned Fingerhut, the consumer credit catalogue company. He sat on charity boards in Minnesota. He employed thousands of people in real businesses that made real products.
Behind all of it — running simultaneously for approximately fourteen years, from 1994 to 2008 — was a $3.65 billion Ponzi scheme. Investors were told their money was being used to buy consumer electronics from suppliers and resell them to big-box retailers at guaranteed profit margins. The purchase orders they were shown were largely fabricated. The supplier relationships were largely fictitious. The money from new investors was paying old investors and funding the acquisition of real companies — Polaroid, Sun Country, Fingerhut. [SOURCE: DOJ; Minneapolis Star Tribune]
The businesses were real. The employees were real. The stores were open. The planes were flying. The paychecks cleared. Tom Petters was convicted on 20 counts of wire fraud, mail fraud, money laundering, and conspiracy in December 2009 and sentenced to 50 years in federal prison on April 8, 2010.
He was 52 years old at sentencing. Judge Richard Kyle: 'Mr. Petters was captain of the ship.' [SOURCE: AP sentencing coverage] His projected release date is April 25, 2052. He would be 95.
Madoff fabricated returns. Petters fabricated a supply chain. Both showed investors a business that was never there. The difference: Petters used the fraud proceeds to buy real companies with actual employees. The legitimacy was operational. The fraud was the thing you could not see.
Thomas Joseph Petters was born in 1957 and built his career in Minnesota's consumer products and retail sector. By standard measures he was a success: connected, charitable, prominent in the Twin Cities, associated with significant consumer brands.
Petters Group Worldwide was his holding company, based in Minnetonka, Minnesota. Through it he acquired real businesses with real operations:
Fingerhut — a consumer credit catalogue company acquired in the early 2000s. Genuine business, hundreds of thousands of customers, merchandise sold on credit terms. Real employees. Real products. Real inventory.
Polaroid — the iconic photography brand, acquired in 2005. Global recognition. A history of genuine technological innovation. When Petters owned Polaroid, Polaroid cameras existed and were sold and worked.
Sun Country Airlines — a Minnesota-based discount carrier. Real planes. Real flights. Real passengers travelling between real destinations. When Petters was associated with Sun Country, Sun Country flew. [SOURCE: Reuters; Star Tribune]
All of this is relevant to how the fraud ran for fourteen years. The visible, functioning businesses were the evidence that the man behind them was serious and solvent. Investors who wanted to verify found Polaroid and Sun Country — things they could confirm. The fraud was the piece of the operation they could not see: the supply chain.
Petters Company Inc., known as PCI, was the investment vehicle. It was the fraud.
PCI told investors it was purchasing consumer electronics — televisions, DVD players, the kind of household goods that big-box retailers stocked — from a supplier and reselling them at guaranteed profit margins. Investors funded the purchases. When the goods sold, they received principal plus returns, sometimes as high as approximately 35%. [SOURCE: DOJ; MPR News]
The purchase orders backing these transactions were, per the trial record, largely fabricated. Associates who posed as the suppliers and brokers generated bogus documentation for transactions that either did not occur or did not occur as described; several were separately prosecuted in the District of Minnesota. [SOURCE: DOJ; Star Tribune]
New investor money paid earlier investors — the fundamental Ponzi mechanic — and funded Petters' other businesses and personal expenses. The acquisitions of Fingerhut, Polaroid, and Sun Country were funded, at least in part, with investor capital. The money did not vanish into private accounts; it purchased operating companies. That is what made the fraud durable. The companies it bought kept the operation looking legitimate.
MADOFF () vs PETTERS (Case 018)
Claimed activity
Madoff: options trading strategy · Petters: buying and reselling consumer electronics
Was any of it real?
Madoff: No — no trades, fabricated statements · Petters: Partly — real companies, real brands, bogus supply chain
Duration
Madoff: ~17 years active Ponzi · Petters: ~14 years (1994–2008)
Scale
Madoff: $64.8B fabricated / ~$17B principal · Petters: ~$3.65B scheme size [DOJ] — not net investor loss
Sentence
Madoff: 150 years · Petters: 50 years
Recovery
Madoff: Picard trustee ongoing · Petters: limited — spent on acquisitions and operations
The collapse came from inside. A long-time Petters associate named Deanna Coleman agreed to cooperate with the FBI in 2008. She recorded conversations. She gathered evidence.
The FBI raided Petters Group Worldwide headquarters in Minnetonka in September 2008. Petters was arrested. His businesses entered bankruptcy proceedings. [SOURCE: MPR News; Star Tribune]
Co-conspirators who built the scheme with him — including James Fry, Frank Vennes, and Larry Reynolds — each faced separate proceedings in the District of Minnesota. Each played a role in the documentation infrastructure: the bogus purchase orders, the fake invoices, the appearance of a functioning supply chain that sustained the fraud through fourteen years and investor rounds.
Petters was convicted by a jury on 20 counts — wire fraud, mail fraud, money laundering, conspiracy — on December 2, 2009. He initially maintained his innocence, claiming he had been betrayed by trusted associates who had turned a legitimate business into a Ponzi scheme without his knowledge. This defense was rejected by the jury and by Judge Kyle at sentencing.
Years later, in a 2013 hearing seeking a shorter sentence, Petters finally admitted guilt: 'This is my only chance to clear my conscience and soul. I made a horrible mess of things.' [SOURCE: ABI Journal citing WSJ; MPR News] Judge Kyle dismissed his request, writing that Petters had 'tried to pull off one final con.' [SOURCE: MPR News / KROC News]
On April 8, 2010, Judge Richard H. Kyle sentenced Thomas Joseph Petters to 50 years in federal prison before a packed courtroom in St. Paul, Minnesota.
Prosecutors had sought the statutory maximum of 335 years. The defense argued four years would be sufficient. Kyle chose 50. He recommended the Bureau of Prisons house Petters in Minnesota, to allow him to remain close to his family including two young sons. [SOURCE: AP sentencing; MPR News]
US Attorney B. Todd Jones at sentencing: 'Tom Petters was a fraud. Tom Petters built his life on deceit and lies, and today the check came due.' [SOURCE: AP sentencing coverage, April 8, 2010]
Judge Kyle: 'Mr. Petters was captain of the ship.' [SOURCE: AP] The phrase is precise. Petters did not claim he was absent while associates committed the fraud. He was there. The judge found he knew. The jury had found the same.
His victims included hedge funds — institutional money from sophisticated investors — and pastors, missionaries, and retirees. The range reflects both the scale and the structure of the scheme: PCI targeted a wide network through multiple channels, including religious community networks where trust was built on shared belief rather than financial diligence. [SOURCE: AP sentencing]
His projected release date: April 25, 2052. He would be 95 years old. Even with maximum good-conduct credit, he would spend approximately 41 more years in prison from the date of sentencing. US Attorney Jones called the 50-year term 'fair and just' and described it as 'tantamount to a life sentence.' [SOURCE: AP]
COMMUTATION — STATUS: The brief for this case noted a potential commutation in 2025 and flagged it for verification.
No confirmed commutation of Tom Petters' sentence has been found in primary sources as of September 2026.
This piece does not state a commutation occurred.
If a commutation is confirmed by primary source (DOJ / BOP / White House), update this section with specific date, authority, and scope of the commutation before publication.
Current documented status: serving 50-year sentence, federal prison.
The series thesis for Case 018 is built into the prologue: the stores were open and the planes were flying. The specific thing Petters did differently from Madoff was use the fraud proceeds to buy operating companies.
Madoff's fraud ran inside the credibility of Wall Street's institutional establishment. Stanford's ran inside Antigua's political relationships and cricket culture. Holmes's ran inside the California tech mythology of the Stanford dropout visionary. Petters' ran inside working businesses with real employees, recognisable brand names, and operating revenue.
The investors who wanted to verify were shown things they could verify. Polaroid was real. Sun Country flew. The chairman was charitable and prominent in a community that knew him. The documentation looked like documentation. The fraud was specifically what was not there: the supply chain, the purchase orders, the consumer electronics changing hands between PCI and the retailers.
This is why it lasted fourteen years. And this is why recovery has been limited for victims: unlike Madoff, where money was invested but never deployed and could theoretically be clawed back as uninvested principal, Petters' money was spent. It bought Polaroid. It kept Sun Country flying. It paid Fingerhut's employees. The money was in the businesses.
His is often ranked as the third-largest Ponzi scheme in US history, after Madoff's and Stanford's. You have likely not heard his name before this series. That is the precise thesis: the invisible. He ran a fraud behind real companies in a state that does not think of itself as a fraud capital, and when it collapsed the businesses collapsed with it, and the name did not stick the way Madoff's did.
The stores were open. The planes were flying. And then they were not.
Tom Petters built a warehouse. invented a trade. Both showed investors a supply chain that was never there — and Petters used the proceeds to build something real enough that nobody needed to look at the supply chain for fourteen years.
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
THE PATIENCE — 9 YEARS OF NOTHING
WHAT HE DID AND DIDN’T DO
Every other case in this series is about people who could not stop spending. posted every purchase. bought 31 cars in a month. lived in a $30M penthouse. James Zhong spent almost nothing. The patience was the strategy. The patience was not enough — because the blockchain does not forget, and nine years is only a long time for a person. For a ledger, it is nothing.
THE ZHONG–ULBRICHT LOOP
+ CASE 016 — THE SAME STORY, TWO POSITIONS
CASE TIMELINE
HOW THE FRAUD WORKED
THE CONNECTION TO — FROM THE CASE BRIEF
WHAT THIS CASE ESTABLISHED
THE FULL STORY — 8 PARTS + EPILOGUE — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE POPCORN TIN (3,000 WORDS)
In November 2021, federal agents executed a search warrant at a residence in Gainesville, Georgia.
They found a gaming computer. Inside it, on a single-board computer and various storage devices: approximately 50,676 Bitcoin. [SOURCE: DOJ forfeiture filings]
They found $661,900 in cash. [SOURCE: DOJ]
They found gold and silver bars. Hidden in a popcorn tin. Buried under blankets in a bathroom closet. [SOURCE: DOJ / reporting]
The Bitcoin, at the time of seizure in November 2021, was worth approximately $3.4 billion. [SOURCE: DOJ — value at Nov 2021 prices]
50,676 Bitcoin — $3.4 billion at November 2021 prices. In a house in Georgia. On a computer. Next to a popcorn tin full of gold bars in a bathroom.
The man who lived in the house was James Zhong. He had stolen the Bitcoin nine years earlier — from a website the FBI had already shut down, from an operator the federal government had already sentenced to die in prison, from a marketplace that was itself a crime scene.
He stole from the criminals. Then he sat on it. For nine years. And then the government came and took it all.
Before the world knew his name, the blockchain knew his wallet.
In the years after Silk Road was shut down — after was arrested in a San Francisco library in October 2013, after the FBI seized the marketplace's servers, after the federal government catalogued what it had taken — a question persisted in the forensic record. The Bitcoin did not add up.
Silk Road had processed an enormous volume of transactions during its two and a half years of operation. When the government seized the servers, it expected to find the Bitcoin that had flowed through the marketplace's escrow system. It found some. It did not find all of it. A substantial amount was missing — not misplaced in the accounting but absent from the wallets the government now controlled.
Somebody had taken it before they got there.
The wallet that held the missing Bitcoin became known in blockchain forensics circles as the "Individual X" wallet. It was one of the largest single holdings of Bitcoin linked to an identifiable — if unnamed — person. Chainalysis and other blockchain analysis firms tracked its existence. The coins sat. They did not move. Year after year, the wallet held still while Bitcoin's price climbed from hundreds of dollars to thousands to tens of thousands, and the value of the coins inside it grew from a curiosity into a fortune into something that could only be described with a B.
For eight years, Individual X was a ghost in the ledger. A wallet with no face. A theft with no suspect. The largest known haul from the most famous darknet marketplace in history, sitting in a single address, untouched, while the man who built Silk Road sat in a federal prison cell and the man who robbed it sat in a house in Georgia.
The theft happened in September 2012. Silk Road was still operational. Ulbricht was still free, still running the marketplace under the name , still a year away from the library and the handcuffs.
What James Zhong found was a flaw in the withdrawal system.
Silk Road operated on a deposit-then-withdraw model — users deposited Bitcoin into internal accounts, transacted on the marketplace, and withdrew their balances. The system was designed so that a user could not withdraw more than they had deposited. That was the assumption. It was also wrong.
Zhong discovered that the withdrawal-processing logic could be exploited — that by structuring his transactions in a specific way, he could withdraw far more Bitcoin than he had put in. [SOURCE: DOJ plea agreement / press release]
He exploited the flaw. He took approximately 51,680 Bitcoin. [SOURCE: DOJ]
51,680 Bitcoin. In September 2012, that was worth a fraction of what it would later become — Bitcoin was trading in single digits to low double digits for much of 2012. The dollar value at the time of theft was modest by the standards of this series. The value of the same coins nine years later, when the government seized them, was approximately $3.4 billion. [SOURCE: DOJ — Nov 2021 valuation]
The gap between those two numbers — the value at theft and the value at seizure — is the specific financial phenomenon that makes this case unusual. He did not steal $3.4 billion (Nov 2021 value). He stole 51,680 Bitcoin, which became worth $3.4 billion (Nov 2021 value) while he held it. The distinction matters because precision matters, and because the raw number — 51,680 BTC — is the fact, and the dollar amount depends entirely on which date you attach to it.
This is the part that makes the case.
He had 51,680 Bitcoin. He had taken it from a marketplace that, at the time of the theft, was still the most actively monitored criminal enterprise on the internet. Every law enforcement agency with a cyber mandate was watching Silk Road. The FBI was building the case that would shut it down a year later. The blockchain was public — every transaction visible to anyone with the tools to read it.
And James Zhong did nothing.
He moved the Bitcoin into a consolidated holding. He sat on it. He did not spend it. He did not convert it. He did not buy houses or cars or watches or Birkin bags. He did not throw a $75,000 birthday party or rent a mansion for $68,000 a month or stream himself on Discord celebrating the moment the coins arrived.
He lived in Gainesville, Georgia. He held the Bitcoin. He waited.
One year. The FBI shut down Silk Road. Ulbricht was arrested. The government seized servers and wallets. Zhong's coins were not among what they found.
Two years. Bitcoin climbed. The coins sat.
Five years. Bitcoin entered the mainstream. Futures were listed on the CME. The price passed $19,000 in December 2017. Zhong's 50,000-plus coins were worth, briefly, nearly a billion dollars. He did not sell.
Seven years. Bitcoin crashed, recovered, crashed again. The coins sat.
Nine years. November 2021. Bitcoin reached its all-time high near $69,000. Zhong's holding was worth approximately $3.4 billion (Nov 2021 value). [SOURCE: DOJ — Nov 2021 valuation]
And then the government knocked on his door.
Every other case in this series is about people who could not stop spending. posted every purchase. bought 31 cars in a month. Madoff maintained the lifestyle for decades. lived in a penthouse in the Bahamas. The spending is always the evidence, and the evidence is always the spending.
James Zhong spent almost nothing. He held the largest stolen Bitcoin fortune in history and he waited, quietly, in a house in Georgia, while the value grew from thousands to millions to billions. The patience was the strategy. The patience was also, in the end, not enough — because the blockchain does not forget, and nine years is only a long time for a person. For a ledger, it is nothing.
The United States government seized approximately 50,676 Bitcoin from James Zhong's residence in November 2021. [SOURCE: DOJ forfeiture filings]
The seizure was not announced immediately. The government held the information for a year — conducting its investigation, building its case, confirming the chain of evidence that connected the Individual X wallet to the man in the house in Georgia.
The specifics of the seizure, as described in DOJ filings: the Bitcoin was stored on devices in his home. A gaming computer. Storage devices. The $661,900 in cash and the gold and silver bars in the popcorn tin were also seized. [SOURCE: DOJ]
The popcorn tin is not a footnote. It is the image the case produces — a man with 50,676 BTC — $3.4 billion at November 2021 prices — on a computer, with gold bars hidden in a tin that once held caramel corn, under blankets in a bathroom closet. The juxtaposition between the scale of the digital fortune and the smallness of the physical hiding place tells you something about the man's relationship to the money. He did not live like a man who had billions in Bitcoin. He lived like a man who had a secret.
A note on the numbers: he stole approximately 51,680 BTC. The government seized approximately 50,676 BTC. The difference — roughly 1,004 BTC — is itself a detail. Per DOJ, those coins were not spent: Zhong voluntarily surrendered them to the government (1,004.15 BTC in total, beginning in March 2022). By his sentencing in April 2023, the government held final forfeiture orders for 51,680.32 BTC. [SOURCE: US Attorney SDNY, April 14, 2023, US v. Zhong, 22 Cr. 606 (PGG)]
On November 7, 2022, the Department of Justice announced that "Individual X" — the ghost in the Silk Road ledger, the wallet that blockchain forensic firms had tracked for nearly a decade — was James Zhong. [SOURCE: DOJ / SDNY press release, 7 Nov 2022]
He had pleaded guilty three days earlier, on November 4, 2022, to one count of wire fraud. [SOURCE: DOJ plea agreement]
One count. Wire fraud. For the theft of 51,680 Bitcoin from the most famous darknet marketplace in history — a theft that, measured by the value of the assets at seizure, was the largest individual cryptocurrency recovery the US government had ever executed.
The charge was not computer fraud, not money laundering, not conspiracy. Wire fraud. A single count that carried the entire weight of a $3.4 billion (Nov 2021 value) seizure.
James Zhong was sentenced to one year and one day in federal prison. [SOURCE: SDNY sentencing, 2023]
One year and one day.
In a series where Madoff received 150 years, where Stanford received 110, where Ulbricht received two life sentences, where received 25 years, where Gonzalez received 20 and was released in 2023 — Zhong received one year and one day for the largest Bitcoin seizure in American history.
The sentence requires explanation, because the number on its face appears absurd relative to the dollar figure. The explanation has three parts.
First, cooperation. Zhong cooperated with the government. He did not flee. He did not destroy evidence — no phone tossed into Biscayne Bay, as did when the FBI came for him in . When the agents arrived at Zhong's door, the Bitcoin was there, the cash was there, and the gold was in the popcorn tin. He pleaded guilty. He assisted the government in recovering assets. Cooperation, in the federal system, is the single most powerful mitigating factor at sentencing.
Second, the victim. Silk Road was not a legitimate business. It was a criminal marketplace whose founder was convicted on five federal counts including running a continuing criminal enterprise. The "victim" of Zhong's theft was a crime scene. The moral weight that a judge assigns to a theft is influenced by the character of the thing stolen from — and stealing from a drug marketplace does not carry the same weight as stealing from pensioners or a sovereign fund.
Third, recovery. The government got the money back. Nearly all of it. 50,676 of 51,680 Bitcoin. The forfeiture was almost complete. In cases where restitution is the goal and the restitution is achieved, the punitive element of the sentence is reduced. The government did not need to punish Zhong into returning the money. He had already returned it — or, more precisely, the government had already taken it.
One year and one day. The "and one day" is a technical feature of federal sentencing: a sentence of exactly one year is served in full, but a sentence of one year and one day qualifies the defendant for good-time credit, which can reduce the actual time served. The extra day is, paradoxically, a benefit.
and Case 016 are the same story told from two positions.
built Silk Road. He created the anonymous marketplace, the Bitcoin escrow, the Tor hidden service. He ran it for two and a half years under the name . He was arrested in October 2013, convicted on five counts, and sentenced to two life sentences plus forty years. In January 2025, he was pardoned by President Trump. [SOURCE: Executive pardon, 21 January 2025]
James Zhong found the flaw in what Ulbricht built. He exploited the withdrawal system, took 51,680 Bitcoin, and held it for nine years while the government shut down the marketplace, arrested its founder, and spent nearly a decade trying to account for where the money had gone.
Ulbricht received two life sentences. Zhong received one year and one day.
Ulbricht built the infrastructure for anonymous criminal commerce and was sentenced to die in prison. Zhong exploited a bug in that infrastructure, stole from it, returned the money when caught, and served twelve months.
The contrast is not a commentary on justice — it is a fact of how the federal system weighs different kinds of conduct. Building the machine that enables the crime is punished more severely than exploiting a flaw in the machine. The architect receives a harsher sentence than the burglar. The system that processed millions of illegal transactions was judged more dangerous than the man who found the one transaction the system got wrong.
Ulbricht was pardoned. Zhong served his time. The Bitcoin went to the US government, which sold portions of it at public auction. The marketplace is gone. The money is accounted for. The two men who defined its history — the builder and the thief — are both free.
The largest single seizure of cryptocurrency by the US government at the time of announcement — approximately 50,676 Bitcoin, valued at approximately $3.4 billion (Nov 2021 prices). [SOURCE: DOJ]
The "Individual X" investigation demonstrated that blockchain forensics can identify wallet holders years or decades after a transaction, even when the coins are not moved. The ledger does not forget. Time is not a defence against a public blockchain.
A sentence of one year and one day for a theft valued in the billions — the lightest sentence-to-dollar ratio in this entire series — established that cooperation, victim character, and asset recovery weigh more heavily in federal sentencing than the raw dollar figure.
The case recovered the Bitcoin the FBI could not find when it shut down the marketplace in 2013 — accounted for nine years later, in a house in Georgia, in a popcorn tin and a gaming computer. Zhong voluntarily surrendered an additional ~1,004 BTC beyond what agents seized, bringing the total under final forfeiture orders to ~51,680.3 BTC.
He stole 51,680 Bitcoin from a darknet marketplace in September 2012.
He put it on a computer. He put gold bars in a popcorn tin. He put the tin under blankets in a bathroom closet. He lived in Gainesville, Georgia.
He waited nine years. The Bitcoin went from being worth thousands to being worth $3.4 billion (Nov 2021 value). He did not spend it. He did not post it. He did not celebrate it. He did not tell anyone — as far as the record shows — what was sitting on the hard drive in his house.
The blockchain did not care about his patience. The ledger recorded the theft in 2012 and held the record until 2021, when the government matched the wallet to the man and drove to Georgia with a warrant.
He cooperated. He pleaded guilty. He served one year and one day.
stole $200 million and served 22 months. stole 4,100 BTC from a single victim and faces decades. stole 170 million card numbers and received a twenty-year sentence. James Zhong stole 51,680 BTC — valued at $3.4 billion (Nov 2021 value) — and served a year.
The difference is not the amount. The difference is who you steal from and whether the government gets it back.
He robbed the robbers. The state took the loot. The popcorn tin is in an evidence locker somewhere, and the Bitcoin is in the US Treasury's account.
Every Bitcoin valuation carries a date. The theft total (51,680 BTC) and the initial seizure (50,676 BTC) are distinguished throughout — the additional ~1,004 BTC was voluntarily surrendered by Zhong, bringing total forfeiture to ~51,680.3 BTC. This involves a living person who has been convicted, sentenced, and has served his sentence.
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
THE FAMILY AND THE FIRM
CASE TIMELINE
HOW IT WORKED
HOW THE DEBT WAS HIDDEN — DEFENSIVE LEVEL
WHAT THIS CASE ESTABLISHED
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE FAMILY BANK (600 WORDS)
The debt was real. It was just not on the books.
Adelphia Communications, founded by John Rigas in 1952 in Coudersport, Pennsylvania, grew over five decades into one of the largest cable operators in the United States. By the late 1990s, it was a publicly traded company with millions of subscribers, thousands of employees, and a balance sheet that — as it turned out — showed approximately $2.3 billion less in obligations than the company actually had.
The concealment mechanism: the Rigas family used co-borrowing arrangements — credit facilities that they drew on for personal and family purposes but that were structured to appear as Adelphia corporate obligations or were not reported on Adelphia's books at all. When the SEC began investigating in 2002 and the disclosures followed, the gap was visible and the company was not survivable.
Adelphia filed for bankruptcy in June 2002 — one of the largest corporate bankruptcies in US history at the time. John Rigas and his son Timothy Rigas were convicted at trial on July 8, 2004, on 18 counts of securities fraud, bank fraud, and conspiracy. John Rigas was sentenced in June 2005 to 15 years in federal prison. He was released in 2016 on compassionate grounds at age 91. He died on September 30, 2021, aged 96. [SOURCE: DOJ; Reuters; Wikipedia]
Adelphia's founding family held executive positions across the company. John Rigas was founder and CEO; Timothy Rigas was CFO; other family members held senior roles. The family also had substantial personal ownership.
The fraud operated on two tracks. The first: the Rigas family used Adelphia's credit to borrow money for personal purposes — real estate, investment losses, and other family expenses — without disclosing the borrowing on Adelphia's public financial statements. The off-balance-sheet obligations grew to approximately $2.3 billion. Investors who read Adelphia's financial statements could not see these obligations; the company appeared substantially healthier than it was.
The second track: direct personal benefit. The prosecution documented specific instances of company resources flowing to family purposes — personal expenses paid, assets used, money moving from the public company into family accounts. The personal benefit figure was smaller than the off-balance-sheet debt figure; they are different numbers measuring different things.
The concealment was the offence. Spending company money can be a breach of fiduciary duty and a civil matter; concealing it in the books is securities fraud and bank fraud, because investors and lenders made decisions based on financial statements that were materially false.
Three companies. Three CEOs. Three different places they put the lie.
In all three cases, the company's financial statements did not reflect reality. In all three cases, the fraud required falsification — not just misconduct, but concealment. In all three cases, the victims were shareholders and employees who made decisions based on statements that had been altered to hide the truth.
John Rigas was 79 years old when he was convicted. He was 91 when he was released. He died at 96. Timothy Rigas, his son and co-defendant, received 20 years, later reduced to 17; he was released in 2019. The case is closed by death. The record is as above.
SOURCES
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
THE BANK, THE BUYER & THE WATCHDOGS
LEESON (CASE 022) VS MADOFF (CASE 004)
CASE TIMELINE
HOW IT WORKED
HOW ONE TRADER BROKE A BANK
WHAT THIS CASE ESTABLISHED
THE FULL STORY — 4 PARTS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE 88888 ACCOUNT (1,900 WORDS)
Barings Bank was founded in 1762. It financed the Louisiana Purchase. It helped the British government fund the Napoleonic Wars. By the time Nick Leeson arrived in Singapore in the early 1990s, Barings had been operating for 232 years — longer than the United States had existed.
It lasted three more.
On February 26, 1995, Barings Bank was declared insolvent. The cause: £827 million in losses accumulated by a single trader in a hidden account called 88888 — a number considered lucky in Chinese culture, chosen by Leeson originally to book a small accounting error he wanted to make disappear. [SOURCE: Singapore court record; Board of Banking Supervision inquiry, July 1995]
The losses did not disappear. They grew. For approximately three years, Leeson took increasingly large positions on Japanese interest-rate futures and options, booked his losses into account 88888, and reported profits to London. London paid him a bonus for his reported performance. The bonus was based on profits that did not exist.
When the Kobe earthquake struck Japan on January 17, 1995, the Nikkei fell sharply and kept falling. The positions in account 88888 — which Leeson had been building larger, trying to trade his way back to even — became unrecoverable. The losses were terminal before London even understood the scale. [SOURCE: FT; Wikipedia citing sources]
On February 23, 1995, Leeson left Singapore. Three days later, Barings was insolvent. ING, the Dutch bank, acquired it for £1. [SOURCE: widely reported; ING acquisition record]
Barings had survived empires and financed wars. It was destroyed in three years by one trader — because the person taking the risk was the person recording it. The fraud was not clever. It was a missing control, exploited by a man who did not stop.
Nicholas William Leeson was born on February 25, 1967, in Watford, England. He left school at 18 and took a job as a clerk in a bank. He was good with numbers, ambitious, and — in the specific culture of 1980s London banking — the kind of person who could rise fast if given the chance.
He joined Barings in 1989. Within a few years he was posted to Indonesia, then to Singapore, where Barings had a futures trading operation. In Singapore, Leeson was given an unusual degree of responsibility: he was both the head of the trading operation and the head of the back office — the settlement and record-keeping function. These two roles should never sit with the same person. The person who makes a trade should not be the person who records it. That separation is one of the foundational controls in regulated financial institutions.
At Barings Singapore, the control was absent. Leeson was, in effect, marking his own homework. When he made a mistake in 1992 — a junior trader on his team made an error that cost roughly £20,000 — he did not report it. He opened a new account to park the loss and told himself he would recover it. The account was numbered 88888. [SOURCE: Singapore court record; Wikipedia citing Board of Banking Supervision inquiry]
That decision — to hide a small error rather than report it — is the moment the fraud began. Everything that followed was the arithmetic consequence of that choice: conceal, trade to recover, lose more, conceal more, trade larger, lose larger.
From 1992 to 1995, account 88888 accumulated what Leeson could not recover. He was trading Nikkei futures and options — derivatives contracts linked to the performance of the Japanese stock market. His strategy: bet on stability. Buy contracts when the market fell, expecting it to recover. When it fell further, buy more.
The strategy is called 'doubling down' and it is the mechanism by which a recoverable mistake becomes an unrecoverable one. The position grows larger with each losing trade, because each new trade is sized to win back all the previous losses in a single recovery. If the market never recovers enough, the position grows until the institution cannot absorb it.
The Nikkei did not recover enough. By late 1994, the losses in account 88888 were in the hundreds of millions of pounds. Leeson was reporting profits. London was posting record results. His bonus for 1994 was approximately £130,000. [SOURCE: Wikipedia citing sources — verify figure] The profits were fabricated. The bonus was paid on fiction.
The control that should have caught this — an independent back office that reconciled trading positions against external records — did not exist in the form that would have been required. Internal auditors reviewed Barings Singapore's books. External auditors signed off on accounts. Neither caught the discrepancy between the positions in account 88888 and the external clearing house records, despite the fact that, by 1994, Barings was posting enormous margin calls to cover 88888's positions — margin calls that London was funding without fully understanding why. [SOURCE: Board of Banking Supervision inquiry, July 1995]
The Kobe earthquake of January 17, 1995 was not the cause of the fraud. It was the event that made the consequences irreversible. The quake sent the Nikkei down sharply in the days following. Leeson's existing positions — already billions of yen underwater — became terminal. He bought more contracts, trying to move the market. The market did not move. The losses became £827 million. [SOURCE: FT; Wikipedia; Singapore court record]
LEESON (Case 022) vs MADOFF ()
Control failure
Leeson: no separation between trading and back office. Madoff: no independent audit of returns. Both: the check did not exist.
Duration
Leeson: ~3 years (1992–1995). Madoff: ~17 years active Ponzi phase. Both: nobody looked.
Institution destroyed
Leeson: Barings — 232 years, one of Britain's most respected banks. Madoff: his own firm.
Discovery mechanism
Leeson: market moved against him until losses were terminal. Madoff: financial crisis forced redemption requests he could not meet. Both: not caught by auditors.
Sentence
Leeson: 6.5 years (Singapore). Madoff: 150 years (SDNY).
On February 23, 1995, Nick Leeson left Singapore with his wife. He left a note: 'I'm sorry.' He flew to Kuala Lumpur, then to Brunei, then to Frankfurt, where German authorities arrested him on March 2, 1995. [SOURCE: widely reported; Singapore court record]
In Singapore, the scale of the losses became clear to Barings in the days after he left. The margin calls — the cash required to maintain the positions in account 88888 — exceeded anything the bank could fund. Barings Bank went to the Bank of England and asked for emergency support. The Bank of England declined to organize a rescue. On February 26, 1995, Barings was placed into administration. [SOURCE: FT; Wikipedia citing sources]
ING, the Dutch financial group, acquired Barings and its approximately 1,200 employees for £1. [SOURCE: widely reported] The employees retained their jobs, largely. The shareholders — the people who owned Barings, including some long-serving employees with equity stakes — lost everything. Some pensioners lost portions of their retirement savings. A 232-year-old institution transferred ownership for one pound.
Leeson was extradited to Singapore. He pleaded guilty in December 1995 and was sentenced to six years and six months in prison. He served approximately three years and five months before being released in July 1999 for good behaviour. During his imprisonment, he was diagnosed with colon cancer and treated in prison. [SOURCE: Wikipedia citing sources — verify exact release basis and date]
After release, he wrote a memoir, became a speaker and commentator on risk management, and later became CEO of Galway United Football Club in Ireland. He is 59 years old. He is a living private individual and public commentator. This piece reports the record of the fraud and the sentence; it does not speculate about his current circumstances.
The Board of Banking Supervision — the UK regulatory body that investigated the Barings collapse — published its inquiry in July 1995. Its findings documented specifically what controls had been absent and how those absences allowed the losses to accumulate undetected for three years. [SOURCE: Board of Banking Supervision inquiry, July 1995 — verify title]
The primary failure: separation of duties. Leeson combined the roles of trader and head of back office. The back office settles trades and records positions — it is supposed to be independent of the trading desk so that errors and fraud can be detected before they compound. At Barings Singapore, the same person did both. The check did not exist.
The secondary failures compounded the primary one. Internal audits did not catch the discrepancy. External auditors did not catch it. London management noticed that Barings Singapore was requiring unusually large margin calls — funding requests to cover positions — but did not investigate why with sufficient rigour to discover account 88888. The signals were present. The investigation was not.
This is the lesson the brief asks to be stated plainly, because it applies directly to every case in this series that involves an institution that failed to check: the compliance function is not a formality. It is the institution's only protection against the person inside it who decides not to stop. When the compliance function does not function, the only remaining check is the market — and the market checks through collapse.
Barings was 232 years old. It had never lost a war. It lost one employee.
It took one man, one account, and three years. Barings had outlived empires and financed wars. It did not survive a trader who booked his own losses and kept trading to hide them. Nobody separated the risk from the record. The bank was older than America. The control was missing the whole time.
SOURCES
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
THE HEALTHCARE TRIO
CASE TIMELINE
HOW IT WORKED
HOW THE REFERRAL MACHINE WORKED — DEFENSIVE LEVEL
WHAT THIS CASE ESTABLISHED
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE REFERRAL MACHINE (700 WORDS)
Perez (043) faked the patients. Patel (044) faked the need. Esformes faked the reason they came.
Philip Esformes owned and operated a network of approximately 30 nursing homes and assisted-living facilities in Florida — a real network providing real care to real residents. The fraud was in the pipeline that brought those residents into the facilities: Esformes paid physicians, hospital discharge workers, and others to refer patients into his network, in violation of the anti-kickback provisions that govern Medicare referrals. Once the patients were in his facilities, the network billed Medicare for services — including services that were unnecessary or not provided as billed.
The total fraudulent claims figure: approximately $1.3 billion — described by the DOJ at the time of charging in 2016 as one of the largest individual healthcare fraud cases ever brought. [SOURCE: DOJ / US Attorney S.D. Fla., 2016]
Esformes was convicted at trial on April 5, 2019 and sentenced to 20 years in federal prison on September 12, 2019. In December 2020, President Trump commuted his sentence. The commutation shortened the sentence. It did not erase the conviction. He was convicted. He still is. [SOURCE: DOJ; White House clemency record December 2020]
The anti-kickback statute exists because referrals must be made in the patient's interest, not in the financial interest of the person making the referral. A physician who refers a patient to a facility because the facility has paid them is making a financial decision, not a clinical one. The patient may not receive care that is appropriate for them; the facility bills Medicare regardless.
Esformes's network operated this way at scale. Physicians received payments for sending patients to his facilities. Discharge workers at hospitals were paid to direct patients into the network when they were ready to leave acute care. The patients — elderly, often vulnerable, in transition from hospital care — were the inventory that moved through the referral chain and generated the billing claims.
Approximately 30 facilities processed those patients and billed Medicare for their care — including, per the DOJ, services that were unnecessary or not provided as documented. The residents were real. The care was at least partially real. The fraud was in the kickbacks that determined which facility they went to and in the billing for services beyond what was genuinely provided.
The human cost is the most delicate aspect of this case: nursing-home and assisted-living residents are among the most vulnerable people in the healthcare system. They rely on the facilities that care for them. When those facilities are selected through a kickback arrangement rather than on clinical merit, the residents' welfare is secondary to the financial transaction. State this with care, without sensationalism.
The commutation was issued by President Trump on December 22, 2020. A commutation reduces or eliminates a sentence; it does not reverse the conviction or constitute a finding of innocence.
This is the precise legal distinction the brief for this case flags: Esformes was convicted. His sentence was commuted. The conviction stands. He is not 'pardoned' (which would erase the conviction record); he is convicted with a commuted sentence.
Esformes's commutation is legally distinct from every pardon in the series: Milton (041), pardoned in March 2025 (a full pardon affects his conviction record differently); Milken (034), pardoned in February 2020; Ulbricht (013), pardoned in January 2025; (015), pardoned in October 2025. State the instrument precisely.
The healthcare trio is now complete. Perez (043): fabricated claims. Patel (044): manufactured demand through kickbacks. Esformes (045): purchased referral pipeline. Together they document every major engine of large-scale healthcare fraud: the billing licence, the kickback network, and the referral chain.
SOURCES
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
SENTENCING NOTE — MURDER-FOR-HIRE
EVIDENCE AT SENTENCING — NOT A CHARGE, NOT A CONVICTION
Evidence presented at Ulbricht’s sentencing hearing indicated he had commissioned murder-for-hire deals targeting individuals. This evidence was considered by the judge and influenced the severity of the sentence. He was not charged with murder-for-hire. It was not a count at trial. It is not a conviction. Sentencing courts may consider conduct not independently charged; the standard of proof is different from trial. To state it as a conviction is inaccurate. To omit it is incomplete — it shaped the sentence. The framing above is the correct one.
THE PARDON — JANUARY 21 2025
THE ENDING THAT CHANGED
A pardon is not an acquittal. It does not reverse the conviction. It does not say the courts were wrong. It is executive clemency — the president’s constitutional authority to release a person from the consequences of a federal conviction. The legal system spoke at trial, appeal, and Supreme Court. All three times: you will die in federal prison. A signature undid it. He is the only person in this series whose ending changed.
CASE TIMELINE
HOW THE FRAUD WORKED
THE CONVICTIONS — FROM THE CASE BRIEF
KNOWN NETWORK & CONNECTED CASES
WHAT THIS CASE ESTABLISHED
BACKGROUND & BIOGRAPHY
EARLY LIFE & IDEOLOGY
SILK ROAD — THE MARKETPLACE
THE ARREST, TRIAL & AFTERMATH
TRIAL & SENTENCING
THE PARDON — 2025
WHAT SILK ROAD ESTABLISHED
THE FULL STORY — 10 PARTS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE PARDONED (3,100 WORDS)
Two life sentences plus forty years, to run concurrently. No possibility of parole.
That was the sentence handed down in 2015 by a federal judge in the Southern District of New York. It was the harshest sentence in this entire series — harsher than Madoff's 150 years, which at least contained a number that could be spoken as something other than forever. Two life sentences is not a number. It is a period at the end of a life.
He appealed to the Second Circuit in 2017. He lost. [SOURCE: Second Circuit decision, 2017]
He appealed to the Supreme Court in 2018. They declined to hear the case. [SOURCE: Supreme Court cert denial, 2018]
The legal system had spoken three times. Trial. Appeal. Final appeal. The answer was the same each time: you will die in federal prison.
On January 21, 2025, President Trump signed a full and unconditional pardon. [SOURCE: Executive pardon, 21 January 2025]
Ross Ulbricht walked out.
He is the only person in this series whose ending changed.
He was born on March 27, 1984, in Austin, Texas. [SOURCE: Court record]
The family was comfortable, educated, the kind of household that produced children who went to good universities and joined organisations that valued self-reliance and service. Ross Ulbricht became an Eagle Scout — the highest rank in the Boy Scouts of America, earned by fewer than four percent of scouts who enter the program. It requires years of sustained commitment, community service projects, and the specific discipline of completing a long series of requirements that most teenagers abandon.
He completed it. He was, by every metric his community offered, the kind of young man the system was designed to produce.
He went to the University of Texas at Dallas. Bachelor of Science. Then Penn State — a master's degree, graduated 2009. [SOURCE: Court record / reporting] Two degrees, two institutions, the credentials of a person building something conventional.
He returned to Austin after graduation. He was twenty-five years old, educated, credentialed, and looking for something to build.
He tried day trading. It did not work.
He started a video game company. It did not work either. [SOURCE: Reporting]
Two failures. Two attempts at the entrepreneurial path that Austin, with its tech scene and its startup culture, seemed to promise to anyone with the right education and the right ambition. He had both. The ventures failed anyway. The market was not interested in what he was selling through legitimate channels.
The detail matters because it is the same arc that appears in and . Holmes tried a legitimate medical device before Theranos became a fraud. Stanford ran real businesses before the Ponzi consumed everything. The legitimate attempt comes first. The failure of the legitimate attempt is not the cause of the crime — but it is always in the room.
What Silk Road was, stated plainly: an online marketplace, accessible only through the Tor network, where buyers and sellers could transact using Bitcoin, without revealing their identities to each other, to the platform, or to law enforcement.
What it sold, also stated plainly: primarily illegal drugs. Also fraudulent identity documents. Also other goods and services that could not be sold through conventional channels.
What made it different from every illegal marketplace that had existed before it: it worked. [SOURCE: DOJ / court record]
The Tor network — originally developed by the US Naval Research Laboratory — routes internet traffic through layers of encryption and relay nodes, making it extremely difficult to determine who is communicating with whom or where a particular service is hosted. A Tor hidden service has no physical address, no IP address visible to the public internet, no location that can be raided without first being discovered through other means.
Bitcoin — which in 2011 was still a niche technology understood by a small number of people — provided the payment layer. No bank accounts. No wire transfers. No payment processor that could be subpoenaed. Buyer sends Bitcoin to escrow. Seller ships product. Buyer confirms receipt. Escrow releases payment. The entire transaction occurs between pseudonymous parties through encrypted channels.
Ulbricht built both layers into a functioning marketplace. He did not invent Tor. He did not invent Bitcoin. What he invented was the combination — the realisation that these two technologies, designed for privacy and decentralisation, could be assembled into a commercial platform that operated beyond the reach of the systems that regulated every other marketplace on earth.
He ran it under the name Dread Pirate Roberts — taken from *The Princess Bride*, the 1987 film in which the name is passed from one pirate to another, so that the identity persists even as the person behind it changes. The name was a statement of intent: the market is not the man. The man can be replaced. The market endures.
He also used, at various points, the handles Frosty and Altoid. [SOURCE: Court record / FBI investigation]
Silk Road launched in 2011. [SOURCE: Court record]
It operated for approximately two and a half years. In the context of this series, that is a short run. Madoff operated for decades. Stanford ran his Ponzi for years. built his Instagram over nine years. Silk Road existed for roughly the same amount of time it takes to complete an associate's degree.
In those two and a half years, it changed the world.
Not because of the drugs sold through it — illegal drug markets existed long before the internet and will exist long after. But because it proved a concept that had been theoretical: a marketplace could function with no physical infrastructure, no banking relationship, no identity verification, and no geographic jurisdiction. A market could exist in the space between encrypted networks, accessible to anyone who knew how to find it, invisible to anyone who did not.
Every darknet market that followed — and there have been dozens, some lasting months, some lasting years, each one taken down and replaced by another — is a copy of the architecture Ulbricht built. He did not steal money. He built infrastructure. The infrastructure outlived him, outlived Silk Road, and continues to operate in evolved forms across the Tor network today.
That is what the sentence was for. Not for the drugs — any drug dealer can be sentenced for drugs. For building the machine that made the drugs untraceable, the sellers anonymous, and the buyers invisible. For proving it could be done.
The FBI arrested Ross Ulbricht in October 2013. Silk Road was taken offline simultaneously. [SOURCE: FBI / DOJ]
The investigation that led to the arrest was a multi-agency operation that had been building for months. The specific details of how agents identified Ulbricht and connected him to the Dread Pirate Roberts pseudonym involve operational security failures — moments where the wall between his real identity and his pseudonymous one became thin enough for investigators to see through.
He was arrested in a public library in San Francisco. The agents needed him to be logged in — to have his laptop open and the Silk Road administrative interface active on screen — so that the evidence of his control over the platform would be captured in real time, not reconstructed from forensic analysis of an encrypted device after the fact.
They got what they needed. He was logged in. The laptop was open. The Dread Pirate Roberts was sitting in a library, running a market, when the FBI introduced themselves.
The trial took place in the Southern District of New York. He was convicted in 2015 on five counts. [SOURCE: SDNY / court record]
The counts, stated precisely:
One. Engaging in a continuing criminal enterprise. This is the most serious charge — the federal "kingpin" statute, reserved for leaders of large-scale criminal operations. It carries a mandatory minimum of twenty years and a maximum of life.
Two. Distributing narcotics by means of the internet.
Three. Conspiracy to commit money laundering.
Four. Conspiracy to traffic fraudulent identity documents.
Five. Conspiracy to commit computer hacking.
Five counts. One trial. One verdict: guilty on all counts.
The sentence: two life terms plus forty years, to run concurrently. No parole. [SOURCE: SDNY sentencing]
The judge, at sentencing, spoke to the scale of what Silk Road had enabled. Not the individual transactions — each one a drug sale, each one a crime, but none of them individually the kind of crime that produces a life sentence. The scale. The infrastructure. The marketplace itself as the criminal act. The judge sentenced the architect, not the dealers.
This section must be handled with precision, because it is the most misunderstood element of the case.
Evidence was presented at Ulbricht's sentencing hearing indicating that he had commissioned murder-for-hire deals targeting at least five individuals. [SOURCE: Sentencing hearing / court record]
This evidence was considered by the judge as part of the sentencing determination. It influenced the severity of the sentence.
The distinction is not technical — it is fundamental. Evidence considered at sentencing is not the same as a crime proven at trial. Sentencing courts may consider a broader range of conduct than trial courts, including conduct that has not been independently charged or tried. The standard of proof is different. The procedural protections are different.
To state it as a conviction would be inaccurate. To omit it entirely would be incomplete — it shaped the sentence, and the sentence is a central fact of the case. The correct framing is the one just given: evidence presented at sentencing, considered by the judge, never charged as a separate crime.
That framing holds for any discussion of this case. It is the framing the record supports.
In 2017, Ulbricht appealed to the United States Court of Appeals for the Second Circuit. The appeal raised multiple issues, including the severity of the sentence and the conduct of the investigation. The Second Circuit upheld the conviction and sentence. [SOURCE: Second Circuit, 2017]
In 2018, his attorneys petitioned the Supreme Court of the United States for a writ of certiorari — a request for the Court to hear the case. The Supreme Court declined. [SOURCE: Supreme Court, 2018]
The legal system had now spoken at every level available to it. Trial court. Appellate court. The highest court in the country. Each time, the answer was the same.
Ross Ulbricht was going to die in federal prison. That was not speculation or editorialising — it was the mathematical consequence of two life sentences with no possibility of parole, upheld through every avenue of appeal the American legal system provides.
A movement formed. The Free Ross campaign argued that the sentence was disproportionate — that two life terms for a non-violent first offence, by a man with no prior criminal record and an Eagle Scout badge, exceeded what the crime warranted. Libertarian and cryptocurrency communities adopted him as a cause. Petitions circulated. His mother became a public advocate. The campaign ran for years, through multiple administrations, building a constituency that believed the sentence was unjust regardless of the crime.
The movement did not change the legal outcome. The courts had ruled. The sentence stood.
What changed it was something the courts could not provide.
On January 21, 2025 — his first full day in office — President Trump signed a full and unconditional pardon for Ross William Ulbricht. [SOURCE: Executive pardon, 21 January 2025]
A pardon is not an acquittal. It does not reverse the conviction. It does not say the courts were wrong. It does not address the evidence, the trial, or the legal reasoning that produced the sentence. It is an act of executive clemency — the president's constitutional authority to release a person from the consequences of a federal conviction, for any reason or no stated reason at all.
Ulbricht was released. He had served approximately ten years of a sentence that was designed to last the rest of his life.
He walked out of federal custody and into a country where the technology he had pioneered — anonymous marketplaces, cryptocurrency payments, encrypted communication — had become orders of magnitude larger, more sophisticated, and more consequential than anything Silk Road had been.
The market he built in 2011 with Tor and Bitcoin was a prototype. By the time he walked out in 2025, the darknet marketplace ecosystem had evolved through dozens of successors — each one learning from the last, each one refining the model, each one demonstrating that the concept Ulbricht proved could not be un-proved by taking down its creator.
The name deserves its own section because it was not arbitrary.
In *The Princess Bride*, the Dread Pirate Roberts is not a person. It is a title. The original Roberts retired years ago, passing the name and the ship to his first mate, who passed it to the next, who passed it to the next. The reputation — the fear, the legend, the brand — persists because it was never attached to a single human being. The pirate is immortal because the pirate is an idea.
Ulbricht chose this name for Silk Road's administrator. The choice was a declaration: this market is not me. If I am taken, the market continues. The name passes to the next. The pirate endures.
He was half right. He was taken. The market did not endure — Silk Road specifically was seized and shut down. But the model endured. The idea endured. Every darknet marketplace that launched after Silk Road's closure was the next person picking up the name and the ship.
The Dread Pirate Roberts was arrested in a library. The pirate's descendants are still operating.
Silk Road was the first modern darknet marketplace to achieve scale, demonstrating that a commercial platform could operate outside the jurisdiction of any nation-state by combining the Tor network with cryptocurrency payments. [SOURCE: DOJ / court record]
The "continuing criminal enterprise" charge — the kingpin statute — was applied to a marketplace operator, not a drug trafficker. The legal precedent established that building and operating the infrastructure for illegal commerce is itself the crime, separate from any individual transaction conducted on the platform.
The sentence — two life terms plus forty years — was the most severe in this series, applied to a first-time offender with no prior criminal record. It reflected a judicial determination that the scale of the infrastructure, not the violence of the conduct, warranted the maximum penalty.
The pardon — signed January 21, 2025 — is the only instance in this series of an executive action reversing a final federal sentence. It demonstrated that the separation between the judicial and executive branches extends to the most severe sentences the system produces.
The technology Ulbricht combined — Tor for anonymity, Bitcoin for payment, escrow for trust between anonymous parties — became the standard architecture for every darknet marketplace that followed. The model survived his arrest, his conviction, his sentence, and his pardon. It is operational today.
Every case in this series ends with a sentence that holds. Madoff died in prison. is serving twenty-five years. is serving eleven. Gonzalez served thirteen of twenty. Stanford is serving a hundred and ten. Greenwood is serving twenty. Holmes reported to prison. Ignatova may be dead.
Ross Ulbricht was sentenced to die in federal prison. He appealed twice and lost twice. The legal system closed every door it had.
A president opened a different one.
He is forty-two years old. He is free. He built a marketplace that operated for two and a half years, was convicted on five federal counts, served ten years of a life sentence, and walked out of a federal facility on the strength of a signature.
The market he built is gone. The model he proved is everywhere.
He was an Eagle Scout from Austin, Texas, who earned a master's degree, failed at day trading, failed at a video game company, built the most consequential illegal marketplace in the history of the internet, named himself after a fictional pirate whose identity could never be captured because it was never a person — and then discovered that the identity could be captured, and the person sentenced, and the sentence reversed by a power the courts could not override.
He built a market nobody could find, ran it as a pirate, and was sentenced to die in prison — until a signature undid it.
All figures labelled by what they measure. There is no headline dollar figure in this case — Silk Road was a marketplace, not a direct theft. Murder-for-hire evidence was considered at sentencing but never charged. This involves a living person who has been pardoned and released.
*The only case in the series whose ending changed.*
*What would prove it wrong?*
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
CO-DEFENDANT
HOW THE FRAUD WORKED
THE MECHANISM — THE STORY AS PRODUCT
THE JURY SPLIT — THE MORAL PUZZLE
WHAT TWO JURIES DECIDED
The split is the case’s moral puzzle. The jury decided she defrauded the people who gave her money. It could not say, beyond a reasonable doubt, that she defrauded the people who got blood tests. Balwani’s jury reached the opposite conclusion on that question. The patients who received inaccurate tests from a technology that did not work as described — whether they suffered a wrong is a question neither verdict resolves. It sits in the gap between them. [SOURCE: trial records · NBC News verdict coverage]
THE INVESTORS — WHO BELIEVED, WHAT THEY LOST
KNOWN INVESTOR FIGURES — FROM UNSEALED COURT DOCUMENTS
THE NINTH CIRCUIT — FEBRUARY 24 2025
CONVICTION AFFIRMED — APPEAL DENIED
54-page opinion by Judge Jacqueline Nguyen for the unanimous three-judge panel. Two appeal grounds received most attention: improper fact-witness testimony by Dr. Kenneth Das (Theranos’s final lab director); and improper admission of a government regulatory report. Both were found harmless given the weight of other evidence. En banc rehearing denied May 8, 2025 — no judge requested a vote. Certiorari to the Supreme Court is the only remaining option (granted in fewer than 1% of criminal cases). [SOURCE: Bloomberg Law · Courthouse News · Fox4/KTVU]
CASE TIMELINE
WHAT THIS CASE ESTABLISHED
THE FULL STORY — 10 CHAPTERS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE MIRAGE (3,500 WORDS)
The promise of Theranos was this: one drop of blood from a finger prick, placed on a small proprietary device called the Edison, could run hundreds of medical tests. Quickly, cheaply, accurately. Without a needle, without a lab, without the friction of traditional diagnostics.
The promise was beautiful in the way that the best Silicon Valley pitches are beautiful — it identified a real problem (blood draws are unpleasant and expensive), proposed an elegant solution (a device that did more with less), and positioned the person making it as the visionary who had seen what others had missed.
The promise was also, a federal jury in San Jose decided in January 2022, a fraud.
The Ninth Circuit Court of Appeals, affirming the conviction in February 2025, called the promise of Theranos's technology a 'mirage.' It described Elizabeth Holmes's statements and those of her partner Ramesh Balwani as 'half-truths and outright lies.' [SOURCE: Bay City News / Fox4, citing Ninth Circuit opinion, February 24, 2025]
She built a company on a story. The story was the product. And when the story was told to investors who wrote checks, she was convicted. When it was told to patients who got blood tests, the jury acquitted. That distinction — the jury's split — is the moral puzzle at the centre of Case 007, and it belongs at the beginning.
Elizabeth Anne Holmes was born on February 3, 1984, in Washington D.C.
Her family background was comfortable and connected — her father worked for government and later in business, her mother for Congress. She attended St. John's School in Houston, where by her own account she decided as a teenager that she would be a billionaire. [SOURCE: widely documented in press coverage] She told her father that she wanted to give him a birthday present he couldn't afford to buy himself, which he interpreted as affection and she may have meant literally.
She enrolled at Stanford University in 2002 to study chemical engineering. She was 18. By the following year, at 19, she had dropped out to found Theranos.
The Stanford credential — present even in its absence, perhaps especially in its absence — would carry forward in the Theranos story. She had been accepted to Stanford. She had studied there. She had left because she had something better to do. In Silicon Valley, dropping out to start a company is not failure. It is the specific sequence of actions that produced Gates, Dell, Zuckerberg. It is a credential of its own.
She was 19 years old when she founded Theranos. She was 37 when she was convicted.
The black turtleneck was Steve Jobs's. It was his uniform — the same garment, worn every day, a statement that the mind had better things to occupy itself with than deciding what to wear. Elizabeth Holmes adopted it.
She also adopted — or developed, or cultivated — a voice. Her natural speaking voice, by those who knew her before Theranos became famous, was described as higher and more ordinary. The voice that appeared on magazine covers and TED stages and in board meetings with Henry Kissinger and George Shultz was deep, deliberate, and authoritative. Whether this was a performance or had become simply how she spoke is something that only she knows.
The Jobs comparison was not incidental. Magazines applied it. Interviewers applied it. The comparison served a function: it placed her in a lineage, attached her story to a known narrative of visionary founders who saw differently from everyone else and were proven right. If she was the next Jobs, then the people who doubted the technology were the equivalent of the people who doubted the first Mac. Doubt became a risk of being wrong rather than a form of due diligence.
She appeared on the cover of Fortune in 2014 under the headline 'This CEO Is Out For Blood.' She appeared in Forbes, Time, Inc. By 2015, at 31, she was on the Forbes 400 with an estimated net worth of $4.5 billion — all of it on paper, all of it contingent on the company's valuation being real. She was, the magazine said, the youngest self-made female billionaire in history.
The board of Theranos included Henry Kissinger, George Shultz, James Mattis, and William Perry. Not scientists. Not medical diagnostics professionals. Statesmen, generals, men of institutional authority whose presence on a board implied that the enterprise had been examined and found worthy. The board was, in its composition, a form of the argument: serious people are involved, serious people have looked at this.
The persona and the board were parts of the same machine. The story was being told in every dimension simultaneously — the appearance, the voice, the lineage, the backers, the magazine profiles. The technology didn't need to be proven if everything else about the frame said it already was.
Ramesh Balwani, known as Sunny, was President and Chief Operating Officer of Theranos. He and Elizabeth Holmes were in a romantic relationship for years during the period the fraud occurred.
Balwani was 19 years older than Holmes. He had made money in software during the dot-com era and joined Theranos in 2009. At the company, he managed the laboratory operations and the customer-facing testing business — the part of the operation where patients actually received blood tests and results.
The court severed their cases — a procedural decision that meant they were tried separately, before different juries, at different times. [SOURCE: case record, 5:18-cr-00258-EJD] The consequence of severance was significant: their accounts could not be cross-examined against each other in the same proceeding. What Holmes said about Balwani's role, and what Balwani said about Holmes's, were not tested against each other in real time.
Holmes was tried first. She was convicted in January 2022 on four counts: three counts of wire fraud against investors and one count of conspiracy with Balwani to defraud investors. She was acquitted on the counts relating to patients.
Balwani was tried separately and convicted in July 2022 on all twelve counts he faced — including the patient-related counts that Holmes had been acquitted on. [SOURCE: DOJ / N.D. Cal.] The jury that evaluated his conduct regarding patients reached a different conclusion than the jury that evaluated Holmes's. He was sentenced in December 2022 to 13 years in federal prison. [SOURCE: Fox4/KTVU confirming 13 years]
The Edison was the name of the Theranos device — a proprietary blood-testing machine that was supposed to do what the company claimed: run a comprehensive menu of tests from a single drop of blood obtained by finger prick.
What the company told investors, per the court record: the Edison could perform this analysis accurately and reliably across hundreds of tests. The technology was working. The results were trustworthy. The product was ready.
What was actually happening, per the evidence at trial: the Edison could not reliably run the full claimed menu of tests. Many tests were being run on commercial third-party laboratory machines — the kind made by Siemens and other established manufacturers — rather than on the proprietary Edison device. [SOURCE: trial record / DOJ] Theranos had publicly disparaged such machines as inferior to its own technology. It was using them instead.
Some patient test results were inaccurate. The lab's final director, Dr. Kenneth Das, ultimately ordered all tests run on the Edison machines to be voided — a decision that was later cited in the appeals proceedings. [SOURCE: Courthouse News / Bay City News, citing Ninth Circuit opinion]
Investors were shown demonstrations and financial projections that did not reflect the operational reality. The technology was described as finished and proven when, by the evidence presented at trial, it was neither.
The core lie, stated plainly as the court record allows: the product that investors were paying for did not work the way they were told it worked. The promise was what they were buying. The promise was the mirage.
In October 2015, John Carreyrou of the Wall Street Journal published a story.
The headline: 'Hot Startup Theranos Has Struggled With Its Blood-Test Technology.' The story was based on interviews with former Theranos employees — people who had left the company and were willing, with some protection, to describe what they had seen inside.
What they described: that the Edison device was not performing as Theranos claimed. That many tests were being run on conventional laboratory equipment. That the results had accuracy problems. That the reality inside the company was considerably different from the story being told outside it.
Theranos and Holmes fought the story aggressively. Her lawyers sent cease-and-desist letters. The company held a press conference. Holmes went on television and called the reporting 'factually inaccurate' and 'misleading.' She told journalists that the story had been written by someone who did not understand the technology.
The story was accurate. Carreyrou continued reporting. He eventually published the book Bad Blood: Secrets and Lies in a Silicon Valley Startup, which became the definitive account of what had happened inside the company. The book came out in 2018 — the same year Holmes and Balwani were indicted.
The WSJ exposé is the origin point of the legal proceedings. Without Carreyrou's reporting, the fraud might have continued until it collapsed on its own. With it, the regulatory scrutiny that followed led to the evidence that led to the indictments. Journalism is in the chain of causation for this case in a way it usually is not.
The Theranos investor list was not a list of naive people who had been tricked by a slick presentation. It was a list of some of the wealthiest and most connected individuals and families in the United States.
Rupert Murdoch invested approximately $125 million in Theranos — later writing it down to zero. [SOURCE: widely reported; verify exact figure against primary before publication] The DeVos family, the Walton family, the Cox family — among the investors who collectively put in what the government characterised as approximately $945 million. [SOURCE: DOJ — verify against primary before final publication]
These were not people who failed to do due diligence because they lacked access to experts. They were people who had been told, by a founder with a Stanford pedigree and a board of statesmen, a compelling story about a transformative technology — and who chose to believe it. Some of them may not have asked the questions that would have revealed the problem, in part because the frame Holmes had constructed made asking those questions feel like missing the point.
This is a pattern visible across the series. Madoff's victims were sophisticated investors who could have investigated the returns and chose not to, partly because the returns looked like exactly what a Madoff investment should look like. 's backers were institutional funds that did due diligence and concluded the effective altruism framing made the risk worth taking. Holmes's investors had a board of Kissinger and Shultz and Mattis telling them, implicitly, that serious people had looked at this.
The company was valued at approximately $9 billion at its peak. That valuation — the figure that made Holmes a billionaire on paper — is not the amount investors lost. The lost figure is the actual capital invested, approximately $945 million per the government's case. The gap between those two numbers is the gap between valuation and reality, and it is the same gap that appears in every case in this series.
Holmes's trial ran for four months in San Jose, California, before Judge Edward J. Davila. It was one of the most closely watched corporate fraud trials in recent memory.
The prosecution presented evidence that the Edison device could not reliably run the tests Theranos claimed it could, that many results had been generated on conventional laboratory equipment rather than the proprietary machine, that investor presentations had contained projections and representations that did not match the company's actual capabilities.
Holmes testified in her own defense over eight days. She told the jury that she had genuinely believed in the technology. She said she had been the victim of Balwani's abuse — domestic abuse claims that her legal team presented as part of the defense, arguing that his control over her limited her awareness of what was actually happening inside the company. [SOURCE: widely documented; trial record]
The jury deliberated and returned its verdict on January 3, 2022.
On three counts of wire fraud against investors and one count of conspiracy to defraud investors: GUILTY.
On the counts related to patients: NOT GUILTY.
The split is the most important legal fact in the case and the most important moral fact. The jury decided that she had defrauded the people who gave her money. It decided it could not say, beyond a reasonable doubt, that she had defrauded the people who got blood tests. Whether that distinction reflects the evidence, the difficulty of proving patient harm in a case this complex, or something else — that is a question the verdict leaves open.
Balwani's jury, evaluating his conduct separately eight months later, came to a different conclusion about the patient counts and convicted him on all twelve charges.
On November 18, 2022, Judge Edward J. Davila sentenced Elizabeth Holmes to 135 months in federal prison — 11 years and 3 months.
The sentence was below what prosecutors had sought and above what her lawyers had argued for. Davila acknowledged the genuine belief Holmes may have had in the technology, but found that the evidence of fraud was sufficient to warrant a substantial sentence. [SOURCE: Reuters / CNN Business, November 18, 2022]
Holmes was ordered to surrender to prison in April 2023. Her lawyers sought to delay while the appeal was pending. The Ninth Circuit denied the stay in May 2023, finding she had not raised a 'substantial question' that her conviction would be overturned. [SOURCE: UPI, May 2023] Judge Davila ruled she must report by May 30, 2023.
She reported to the Federal Prison Camp in Bryan, Texas — a minimum security facility. In a People Magazine interview, she described prison as 'hell and torture.' [SOURCE: Fox4 citing People Magazine] She is currently serving her sentence there.
Balwani was sentenced in December 2022 to 13 years — a longer sentence than Holmes, reflecting his additional convictions on the patient-related counts. [SOURCE: Fox4/KTVU confirming 13 years]
On February 24, 2025, a three-judge panel of the Ninth Circuit Court of Appeals unanimously affirmed Holmes's conviction and sentence.
The 54-page opinion, written by Judge Jacqueline Nguyen, rejected every argument Holmes's lawyers had raised. Two grounds of appeal had received the most attention: that the trial judge had improperly allowed Theranos's final lab director, Dr. Kenneth Das, to testify as a fact witness on matters that required him to be qualified as an expert; and that a government regulatory report had been improperly admitted and may have misled the jury. [SOURCE: Fox4/KTVU; Courthouse News; Bloomberg Law]
The Ninth Circuit found that even if the trial judge had committed procedural errors in these rulings, those errors were harmless — the other evidence against Holmes was so substantial that no different result would have been likely. [SOURCE: Bloomberg Law citing opinion, February 2025]
The court's characterisation of the fraud was the most significant element of the opinion for the series record: the promise of Theranos's technology was a 'mirage,' and Holmes's statements were 'half-truths and outright lies.' [SOURCE: Bay City News / Fox4, citing Ninth Circuit panel opinion]
Holmes requested a rehearing in April 2025, arguing that the harmless error analysis was wrong and that the panel had made factual mistakes in its opinion. On May 8, 2025, the Ninth Circuit denied the rehearing — both the panel rehearing and the en banc hearing request — unanimously. No judge of the court requested a vote on whether to rehear the matter. [SOURCE: Bloomberg Law, May 8, 2025; Courthouse News, May 2025]
The only remaining legal option is a petition to the United States Supreme Court for certiorari. The court grants fewer than 1% of such petitions in criminal cases. Holmes's conviction is, for all practical purposes, final.
The series thesis for Case 007 is this: she built a company on a story, and the story was the product.
The other cases in this series document specific kinds of deception. deceived about the source of his money. deceived about his right to the Bitcoin he had stolen. deceived about what an algorithm had done. Madoff deceived about whether investments had occurred. deceived about the separation between his exchange and his trading firm.
Holmes deceived about what a machine could do. But more specifically, more relevantly: she deceived about whether the story she was telling about the machine was true. The story — revolutionary technology, democratised diagnostics, the next Jobs building the next Apple — was so compelling, so coherent, so well-constructed and so well-delivered that it substituted for the evidence that would have tested it.
Silicon Valley has a specific vulnerability to this kind of fraud. The culture privileges the founder's vision over conventional verification. Due diligence can feel like you are the person who told Jobs that a graphical interface was unnecessary. The board of statesmen was not assembled because they understood medical diagnostics. It was assembled because their presence implied that serious people had examined the claim and found it credible.
They had not. Or not sufficiently. Or the story was simply better than the questions it generated.
John Carreyrou did what the board had not done: he talked to people who had actually worked inside the company and reported what they said. The story he published in 2015 was not the product of technical expertise. It was the product of the journalist's oldest tool — talking to people who were there. The technology that could run hundreds of tests from a single drop of blood could not withstand that.
The jury decided she defrauded investors. It could not agree she defrauded patients. Balwani's jury convicted him on the patient counts. The moral question — did the patients who received inaccurate tests from a technology that did not work as described suffer a wrong? — is not resolved by either verdict. It sits in the gap between them, as it will continue to sit.
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
THE REACH
CASE TIMELINE
HOW IT WORKED
HOW THE BRIBERY DEPARTMENT WORKED — DEFENSIVE LEVEL
WHAT THIS CASE ESTABLISHED
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE DEPARTMENT (1,100 WORDS)
Most companies have a legal department, a finance department, a human resources department. Odebrecht — Marcelo Odebrecht's construction conglomerate, the largest in Latin America — had one more: the Division of Structured Operations.
The Division of Structured Operations (Divisão de Operações Estruturadas) was, per the US DOJ's description in its 2016 charging documents, a bribery unit — a department with its own off-book accounting system, dedicated to routing payments to government officials across the region in exchange for public infrastructure contracts. It was staffed, budgeted, and audited. Its output was corruption, paid in cash and tracked in records.
The records are why the case is continental. When the Brazilian investigation Operation Car Wash (Lava Jato) reached Odebrecht's cooperation agreement in 2016, the Division's records provided evidence against officials in approximately 12 countries: Brazil, Peru, Ecuador, Mexico, Panama, Venezuela, Argentina, Colombia, the Dominican Republic, Guatemala, Mozambique, Angola, and others. Presidents, ministers, and party treasurers across the hemisphere were implicated by a single company's expense account.
Marcelo Odebrecht, born in 1968, was CEO of the company from 2008 to 2015. He was arrested in Brazil in 2015. He was convicted in 2016 and sentenced to 19 years and 4 months. He cooperated with investigators under a leniency agreement. And in May 2024, Brazil's Supreme Federal Court annulled the criminal proceedings — while leaving the cooperation agreement intact.
The bribe was the input. The contract was the output.
Odebrecht built its Latin American dominance through public infrastructure contracts — roads, dams, oil facilities, ports. The contracts were awarded by governments. The governments were controlled by officials. The officials could be paid.
The Division of Structured Operations managed those payments through a dedicated off-book accounting system — a shadow ledger that tracked bribes by official, by project, and by country. The amounts were substantial. The records were meticulous. The process was routine.
The DOJ's 2016 leniency agreement with Odebrecht and its petrochemical subsidiary Braskem documented approximately $788 million in bribes paid across the scheme's operational period — from approximately 2001 through 2016. This is the bribe total: the amount paid to officials to obtain contracts. It is not the contract value (which was far larger) and it is not a loss figure in the conventional sense. The bribes were an input cost, and the contracts were the return on investment.
The scale made Operation Car Wash, the Brazilian anti-corruption investigation that ultimately reached Odebrecht, one of the largest corruption investigations in history. The cooperation agreement Odebrecht signed with Brazilian, US, and Swiss authorities was, at the time, one of the largest corporate corruption settlements ever — with total penalties reported at approximately $3.5 billion across jurisdictions. [SOURCE: DOJ 2016; verify exact total]
On May 21, 2024, Justice Dias Toffoli of Brazil's Supreme Federal Court (Supremo Tribunal Federal — STF) issued a ruling annulling all procedural acts taken against Marcelo Odebrecht by the 13th Federal Court of Curitiba under Operation Car Wash. [SOURCE: STF; fius.com.br citing STF ruling; La Estrella de Panamá citing EFE]
The basis: Toffoli concluded that the prosecutors involved in Operation Car Wash and the former judge, Sergio Moro, had violated Odebrecht's right to a full defense and due process, making 'constant adjustments and arrangements' to prevent him from exercising his legal rights. Moro, who later became Minister of Justice in the Bolsonaro government, was the presiding judge who issued the Car Wash convictions.
The annulment is specific: it covers the proceedings by the 13th Federal Court. It does NOT cover Odebrecht's own leniency and cooperation agreement — the document in which he admitted guilt and provided evidence against co-conspirators. That agreement remains valid. His admissions of guilt in that agreement stand.
The practical effect: Odebrecht's criminal conviction under Car Wash was annulled. He had already served his time under the cooperation deal: about two and a half years in a Curitiba jail from his June 19, 2015 arrest, then house arrest from December 2017. [SOURCE: Reuters; Agência Brasil]
The Prosecutor General (PGR) appealed Toffoli's annulment ruling in June 2024. As of September 2026, the status of that appeal requires verification — the case may be pending before the full STF bench.
The annulment does not make the bribes un-happened. The cooperation agreement — the document in which Odebrecht admitted guilt, described the bribery system in detail, and named the officials who received payments — remains legally valid. His admissions are in the record. The evidence that implicated officials across the region was produced by that agreement and its status is separate from the criminal proceedings that were annulled.
The annulment reflects something about Car Wash itself. The investigation that began in Brazil in 2014 ultimately expanded to cover the political class of an entire continent, producing convictions and resignations at the highest levels of multiple governments. Whether those convictions were procedurally sound is a question that Brazil's courts are now resolving case by case. Several other Car Wash convictions — including that of former President Luiz Inácio Lula da Silva — were also annulled by the STF on procedural grounds, and Lula returned to win the 2022 presidential election.
This piece does not editorialize on Brazilian politics or on whether the annulment reflects the justice system or its corruption. It states the outcome: proceedings annulled; cooperation agreement intact; PGR appeal pending; verify final status before publication.
SOURCES
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
THE PIPELINE
CASE TIMELINE
HOW IT WORKED
HOW BITZLATO WORKED — DEFENSIVE LEVEL
WHAT THIS CASE ESTABLISHED
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — NO QUESTIONS ASKED (800 WORDS)
Know Your Customer is not an optional framework. It is a legal requirement for any entity that transmits money — an exchange, a bank, a payment processor. The requirement exists because money-transmitting businesses are a chokepoint in the financial system, and the only way illegal money moves into the legitimate economy is through that chokepoint.
's Binance () failed to build adequate KYC/AML controls. The DOJ found the controls inadequate; the $4.3 billion company penalty reflected the scale of the failure; served four months for a BSA compliance charge.
Bitzlato was different. Bitzlato, founded around 2016 and co-founded by Anatoly Legkodymov, a Russian national, marketed itself explicitly as a 'No Questions Asked' exchange — an exchange whose users were not required to identify themselves, verify their identity, or provide information about the source of their funds. The absence of KYC was the product. The value proposition to a criminal was that no record of their identity would be attached to their transaction.
The result, per the DOJ: Bitzlato's users exchanged more than $700 million in cryptocurrency with Hydra Market alone, and the exchange also took in about $15 million in ransomware proceeds. Among the sources of those funds: proceeds from ransomware operations and funds from the Hydra Market darknet marketplace — the subject of . [SOURCE: DOJ January 18, 2023]
Legkodymov was arrested in Miami on January 17, 2023, pleaded guilty on December 6, 2023 to operating an unlicensed money-transmitting business, and on July 18, 2024 Judge Eric Vitaliano in Brooklyn sentenced him to time served — about 18 months in custody. [SOURCE: DOJ; Cointelegraph, July 2024]
A conventional crypto exchange requires users to submit identity documents, verify their residency, and link verified payment methods. The process is slow and leaves records. For users moving funds they do not want associated with their names — ransomware proceeds, narcotics sales revenue, money from sanctioned jurisdictions — this is a liability.
Bitzlato offered the alternative. Users could operate without KYC verification. Transactions were processed without identity records being attached. The exchange accepted business from jurisdictions and users that a regulated exchange would have screened out. It did not file suspicious-activity reports. It did not build the monitoring infrastructure that the Bank Secrecy Act requires of US-linked money-transmitters.
The Hydra Market connection is documented by the DOJ: Hydra — the Russian-language darknet marketplace that processed over $5.2 billion in cryptocurrency before its April 2022 takedown — used Bitzlato as part of its financial infrastructure. Hydra funds moved through Bitzlato, the exchange that would not ask. [SOURCE: DOJ January 18, 2023; cross-reference ]
Ransomware operators — groups that encrypt victim organisations' data and demand cryptocurrency payments for decryption keys — also used Bitzlato to convert and launder their proceeds. The exchange was, in this framing, a service provider to the ransomware economy.
The series now has a documented pipeline: a darknet marketplace ( — Hydra) generated illegal cryptocurrency revenue; an exchange (Case 040 — Bitzlato) moved those funds without asking; and a state actor ( — Group Profile) generates revenue at the top of the chain through direct theft.
The Bitzlato case completes the AML spectrum the series has been building. /Binance () sits at the inadequate-controls end — a large, legitimate exchange that failed to build adequate controls at scale. Legkodymov/Bitzlato (Case 040) sits at the deliberate-absence end — an exchange whose entire model was built on the absence of those controls. Between them, the spectrum covers every variety of compliance failure from negligence to service.
The sentence contrast is notable and should be stated without editorial comment: received four months in prison after a $4.3 billion company penalty, then was pardoned. Legkodymov received time served — approximately 18 months in custody — for running an exchange whose absence of controls was by design and that moved $700 million in illicit funds. The accountability spectrum across these two cases is real and its shape is the record's to explain.
SOURCES
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
THE PEOPLE AROUND IT
CASE TIMELINE
HOW IT WORKED
HOW THE STORY WAS SOLD — DEFENSIVE LEVEL
WHAT THIS CASE ESTABLISHED
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE DEMONSTRATION (900 WORDS)
Holmes () built a machine that could not do the test. Milton built a demonstration that was not happening.
In 2016, Nikola Corporation published a video of the Nikola One — its hydrogen-electric semi-truck prototype — appearing to be in motion. The video was titled 'Nikola One Electric Semi Truck in Motion.' The government alleged, and established at trial, that the truck in the video was not driving under its own power. It was rolling downhill. The camera angle and editing implied a functioning vehicle. [SOURCE: DOJ indictment / trial record]
Nikola Corporation was founded by Trevor Milton in 2014, in a basement in Utah. By 2020, amid the electric vehicle investment boom, it was worth approximately $30 billion at its peak market valuation — a figure that reflected investor belief in the technology story Milton was telling. That story, per the DOJ and per the conviction, contained material misrepresentations about the company's technology and progress.
Milton was convicted on October 14, 2022, on one count of securities fraud and two of wire fraud. He was sentenced on December 18, 2023, to 4 years in federal prison and a $1 million fine, and ordered to forfeit a property in Utah. He appealed. He was not incarcerated while the appeal was pending. He was pardoned by President Trump on March 28, 2025. [SOURCE: DOJ; Fox News/AP pardon reporting]
In September 2020, Hindenburg Research — a short-seller research firm — published a detailed report titled 'Nikola: How to Parlay an Ocean of Lies Into a Partnership With the Largest Auto OEM in America.' The report alleged that Milton had made a series of material misrepresentations about Nikola's technology, including the truck-rolling-downhill allegation.
The report was published just weeks after Nikola and General Motors had announced a major partnership in which GM would take an 11% stake in Nikola, worth about $2 billion, and supply fuel cells and other components. The short-seller report challenged the basis of that partnership. GM eventually withdrew. Milton resigned as Executive Chairman on September 20, 2020, shortly after the report's publication.
The government's investigation ran in parallel with the public controversy. Milton was charged on July 29, 2021, more than a year after his resignation and the Hindenburg report. The sequence — public short-seller challenge, then government action — is relevant because it shows the fraud was publicly contested before it was prosecuted. [SOURCE: Reuters/WSJ; DOJ indictment]
The pardon is a documented act of executive clemency. It does not reverse the conviction factually or constitute a finding of innocence.
President Trump confirmed the pardon on March 28, 2025. Milton responded: 'I am incredibly grateful to President Trump for his courage in standing up for what is right and for granting me this sacred pardon of innocence.' [SOURCE: Fox News / AP / Fortune]
The background the record establishes: Milton and his wife donated more than $1.8 million to a Trump re-election campaign fund less than a month before the November 2024 election. When asked about the pardon, Trump said: 'They say it was very unfair, and they say the thing that he did wrong was he was one of the first people that supported a gentleman named Donald Trump for president.' [SOURCE: Fox News / AP]
Per AP and Fortune reporting, the pardon may cancel the restitution for defrauded investors that prosecutors had sought — the same investors who watched Nikola's stock fall after Milton's claims were publicly challenged and then convicted. The precise effect of the pardon on pending civil and financial claims is not fully established in public records as of this writing.
Nikola Corporation filed for Chapter 11 bankruptcy in February 2025. Milton was reportedly attempting to purchase Nikola's assets from the bankruptcy estate. [SOURCE: Electrive citing Techcrunch/court documents]
The series documents the pardon and its stated context as fact. It does not editorialize on it. It belongs in the same category as the Milken pardon (2020) and the pardon (2025) and the Ulbricht pardon (January 2025): a documented pattern in the accountability spectrum, with its own record.
SOURCES
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
THE PEOPLE AND THE FIRM
THE LEGEND VS THE RECORD
CASE TIMELINE
HOW IT WORKED
WHAT HE ADMITTED — DEFENSIVE LEVEL
WHAT THIS CASE ESTABLISHED
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE LEGEND AND THE RECORD (1,300 WORDS)
Michael Milken was indicted on 98 counts in March 1989. He pleaded guilty to 6 counts in April 1990. The difference between those two numbers — 92 counts, including the RICO charges that would have defined him as a racketeering organisation — is the gap between the legend and the record, and the gap is the case.
The public story of Michael Milken is of the Junk Bond King as the face of 1980s financial excess — indicted under RICO, fined $600 million, and sent to prison. Most of that is correct in outline. The details are more specific.
He was indeed indicted under RICO. He did not plead guilty under RICO. The RICO charges were resolved as part of the plea agreement — which means the 6 counts he admitted were narrower: conspiracy, securities fraud, mail fraud, parking securities for others (holding stocks on their behalf to conceal who really owned them), assisting a false tax return, and a broker-dealer reporting violation. [SOURCE: DOJ plea record; Den of Thieves, James B. Stewart, 1991]
He agreed to pay approximately $600 million in fines and payments — the number the legend remembers wrongly. That is not what the number measures. It is the penalty figure in the plea agreement. No victim is on record receiving $600 million. The amount represents the price he paid to resolve the government's case, not money taken from an identified victim.
He was sentenced to 10 years by Judge Kimba Wood on November 21, 1990. He served approximately 22 months — released January 3, 1993. He was pardoned by President Trump on February 18, 2020. The pardon is executive clemency; it does not reverse the conviction or constitute a finding of innocence.
Drexel Burnham Lambert's high-yield department, operating out of Beverly Hills under Milken's leadership, financed the high-yield bond market into existence. The market was real. It is not gone.
High-yield debt — junk bonds — are bonds issued by companies that cannot access the investment-grade credit market. Before Milken's market, these companies had limited access to large-scale financing. Milken argued, and demonstrated, that properly priced high-yield bonds produced better risk-adjusted returns than the conventional wisdom assumed — because the premium for accepting default risk was set higher than the actual default rate.
The companies financed through Drexel's junk bond department include entities that employed tens of thousands of people and generated real economic activity. The leveraged buyout wave of the 1980s — which Drexel's bonds financed — restructured major corporations. The consequences of that restructuring were disputed and remain disputed; what is not disputed is that the financial instrument and the market were genuine.
Milken's department at Drexel was the dominant force in this market by the mid-1980s. His personal compensation was extraordinary — reportedly over $550 million in a single year (1987). The scale attracted scrutiny. The scrutiny was warranted not because the market was fraudulent, but because within that real market, specific conduct violated specific laws.
Ivan Boesky was one of the most prominent arbitrageurs of the 1980s — a trader who bet on corporate mergers and acquisitions using inside information. He pleaded guilty in November 1986 to one count of securities fraud, agreed to pay $100 million in penalties, and cooperated with federal prosecutors. His cooperation was the key that opened the wider investigation. [SOURCE: court record; Stewart, Den of Thieves]
Boesky's cooperation pointed investigators toward Drexel and Milken. The government's investigation alleged a web of reciprocal arrangements — parking securities, manipulating stock prices, sharing inside information about pending deals — that benefited both the Boesky operation and Drexel's clients. The 98-count indictment filed in March 1989 charged Milken with racketeering (RICO), securities fraud, market manipulation, and related offences.
Drexel Burnham Lambert, the firm, was separately charged. It pleaded guilty in December 1988 to six counts and paid $650 million in fines — at the time the largest securities settlement in history. It filed for bankruptcy in February 1990. The firm did not survive the investigation. Milken's departure from the firm had occurred before the bankruptcy.
On April 24, 1990, Milken pleaded guilty to 6 counts of securities violations in the Southern District of New York. The RICO counts — the charges that would have characterised him as a racketeering organisation — were dropped as part of the plea agreement.
The specific counts: conspiracy, securities fraud, mail fraud, aiding and abetting a false SEC filing through 'parking' (holding securities on behalf of others to conceal who owned them), assisting the filing of a false tax return, and a broker-dealer reporting violation. These are specific, documented violations of specific securities law provisions — neither trivial nor the sweeping fraud the indictment suggested.
He agreed to pay approximately $200 million in fines directly and approximately $400 million into a fund for claims — the combined ~$600 million figure. [SOURCE: DOJ / plea record; NYT, April 1990]
Sentenced November 21, 1990: 10 years. Served approximately 22 months before release on January 3, 1993. In August 1992 Judge Wood reduced the 10-year sentence to two years, citing his cooperation with further investigations.
The series enforces a rule: every figure labelled by what it measures. The Milken case exists in the series to apply that rule to a person.
Milken became a symbol — of 1980s excess, of the captured financial system, of the proposition that the rules did not apply to people rich enough to hire lawyers smart enough. That symbol served a cultural function: it gave a complicated decade a face. The problem is that symbols are not evidence, and the record underneath the symbol is specific and narrow in ways the symbol is not.
He is 80 years old. After his release in 1993, he funded prostate cancer research — he was diagnosed with the disease in 1993, shortly after his release — and created foundations for education and medical initiatives. These are documented activities. They do not reverse the conviction and they are not its mitigation; they are what the record shows he did afterwards.
The pardon in 2020 sits in the same position as 's pardon (): a documented fact about the legal system's response to a convicted individual, executed by a specific president for reasons that were not a finding of innocence. The pardon is stated; it is not editoralised.
The brief for this case asks: write the second version of the story — the record, not the legend — and explain why the gap between them exists. The gap exists because the legal system produced a specific outcome through a specific plea process, and the cultural record produced a far larger story. Both are real. Only one is evidence.
SOURCES
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
THE HEALTHCARE TRIO
CASE TIMELINE
HOW IT WORKED
HOW PASS-THROUGH BILLING WORKS — DEFENSIVE LEVEL
WHAT THIS CASE ESTABLISHED
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE BILLING LICENCE (700 WORDS)
The hospital was real. The building was real. The billing codes were real.
When Jorge Perez acquired struggling rural hospitals — small facilities in states with limited medical infrastructure — he acquired with them something far more valuable than the buildings: Medicare provider numbers and insurance contracts. These are the licences that allow a healthcare facility to bill government programmes and private insurers for services.
Per the DOJ, the operation submitted approximately $1.4 billion in claims to health insurers — mostly private insurers — for laboratory testing, largely urine drug tests and blood tests, billed as if the small rural hospitals had done them when most were done by outside laboratories, and many were not medically necessary. The operation received about $400 million. The patients listed on the claims were, in many cases, patients who never received those tests, never visited those facilities, or could not plausibly have needed those specific tests. The volume was the tell: a small rural hospital billing hundreds of millions in specialty lab work that its physical capacity could not have produced. [SOURCE: DOJ — verify specific hospital count and states]
He was convicted by a jury on June 27, 2022 and sentenced on December 15, 2023 to 100 months — 8 years and 4 months. His brother Ricardo Perez got 6 years and 3 months. The billed figure of $1.4 billion represents claims submitted; the amount actually paid by insurers was substantially lower. [SOURCE: DOJ — verify paid amount before publication]
Medicare billing is structured around provider numbers — identifiers that authorise a facility to bill the programme. A provider number, once obtained, is a financial asset: it allows the holder to submit claims for services at Medicare's established rates. For a scheme designed to fabricate claims, obtaining a real provider number through a real facility is the enabling step. The scheme does not require a fake hospital. It requires a real one with a cooperative or captured billing department.
This is the modern healthcare fraud insight: the institution is the instrument. Perez's rural hospitals were not the fraud — they were the vehicle. The billing department was the fraud. The provider number was the asset. Once those were in place, the volume of claims was limited only by how many patient records could be associated with the facility.
The harm is diffuse and it is enormous. Medicare is funded by taxpayers. Private insurance premiums are paid by employers and individuals. When claims are submitted for services that were not provided, the cost is absorbed into the system and ultimately paid by every participant in it. There is no single identifiable victim in the way that Madoff's investors or FTX's customers are identifiable. The harm is real — it is just spread across everyone who pays for healthcare.
This is the first of three healthcare cases in this series. Taken together, they document the full anatomy of healthcare fraud: fabricated claims (Perez), manufactured demand (Patel — ), and a purchased referral pipeline (Esformes — ).
The category is the largest source of fraud losses in the United States by DOJ measure — exceeding financial fraud, card fraud, and cryptocurrency fraud in annual recovered dollars. The cases exist not because healthcare fraud is new but because the mechanism is under-documented in financial fraud catalogues that tend to focus on markets and technology.
The hospital is a recurring vehicle. The provider number is the licence. The billing department is the engine. This is the shape the next two cases will repeat in different forms.
SOURCES
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
THE CREW
THE CARD-FRAUD TRILOGY
CASE TIMELINE
HOW IT WORKED
HOW THE CREW WORKED — DEFENSIVE LEVEL
WHAT THIS CASE ESTABLISHED
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — HACKER 1 (900 WORDS)
When the FBI charged and co-conspirators in 2009 with the Heartland Payment Systems breach — then the largest data breach ever reported — it described two unnamed Russian hackers in the indictment as 'Hacker 1' and 'Hacker 2.' These were the individuals who had actually penetrated the payment processor's network and installed the tools to harvest card data as it moved through the system.
Hacker 1 was Vladimir Drinkman.
He was arrested in the Netherlands on June 28, 2012. He fought extradition for nearly three years before arriving in the United States on February 17, 2015. He pleaded guilty in September 2015 to two counts: conspiracy to commit unauthorized computer access and conspiracy to commit wire fraud. He was sentenced to 144 months — 12 years — in February 2018 by Judge Jerome B. Simandle in the District of New Jersey. He served 10 years and 4 months — 86 percent of the sentence — before being released from a federal facility in Pennsylvania on October 28, 2022. [SOURCE: DOJ D.N.J.; RFE/RL]
His case completes the card-fraud section of this series. Gonzalez () was the coordinator. Seleznev () was the data operator and seller. Drinkman was the intruder — the one who got inside the targets.
The indictment named five individuals and described their specific functions within the operation. Understanding the crew's structure is the purpose of this case file — the Heartland breach was not a lone-actor event.
Heartland Payment Systems was a major US payment processor — a company that sat between merchants and banks, routing credit and debit card transactions for thousands of businesses. In 2007 and 2008, Drinkman and his associates penetrated Heartland's network and installed tools that harvested payment card data as it moved through the processing system.
The data harvested from Heartland alone: approximately 130 million payment card numbers. At the time of disclosure — January 20, 2009 — it was described as the largest data breach in US history. [SOURCE: Heartland SEC filing; Krebs on Security]
The crew's targets extended beyond Heartland: 7-Eleven, Hannaford Brothers, NASDAQ, JC Penney, Carrefour (France), JetBlue Airways, Dow Jones, Wet Seal, Euronet, Dexia, Global Payments, Diners Club Singapore, Visa Jordan, Ingenicard and others — 17 corporate victims in all, per the DOJ. The crew-wide card number count across all targets: approximately 160 million. [SOURCE: DOJ D.N.J. indictment; Dark Reading]
The losses: three of the corporate victims alone reported more than $300 million, according to the DOJ — borne by financial institutions, merchants, and cardholders who faced the fraud that followed. It is a crew-wide figure, not attributable to Drinkman alone.
The card-fraud series has now told the same story three times, from three different positions in the supply chain. The point of telling it three times is the point that a single arrest cannot make:
Card fraud is not one person with a laptop. It is a production chain. The intrusion specialists (Drinkman, Kalinin) obtained access to the networks. The mining specialists (Kotov) extracted the data. The infrastructure specialists (Rytikov) kept the operations hidden. The coordinator (Gonzalez) managed relationships across the chain. The broker (Smilianets) sold the output and paid the participants.
The stolen data then entered a secondary market — the carding forums where Seleznev () operated, selling POS-harvested card numbers to buyers who used them to produce fraudulent transactions. The card numbers are the input to account takeover, synthetic identity fraud, and retail fraud operations that run across other categories in this series.
Of the five crew members charged, Smilianets and Drinkman were convicted and have served their sentences. Gonzalez was convicted separately and has been released. Kotov and Rytikov remain at large. Two links in the chain were convicted; two links were never reached; the category continued running through the period of all five prosecutions.
SOURCES
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
THE SCHEME, YEAR BY YEAR
KNOWN NETWORK & THE VICTIM
THE BANK
THE SENTENCE AND THE OUTCOME
CASE TIMELINE
HOW IT WORKED
ADVANCE-FEE FRAUD AT BANK SCALE
WHAT THIS CASE ESTABLISHED
THE FULL STORY — 6 PARTS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE AIRPORT (2,700 WORDS)
In 1995, Emmanuel Nwude told a Brazilian banker named Nelson Sakaguchi that he was Paul Ogwuma — the Governor of the Central Bank of Nigeria.
He was not Paul Ogwuma. He was a director at Union Bank of Nigeria, a different institution. But he had the confidence of a man in authority, the paperwork of a man in authority, and the detailed knowledge of Nigerian banking protocols that a man in authority would have. [SOURCE: DMARGE citing sources; NAN]
He told Sakaguchi that the Nigerian government was preparing to build a major new international airport in Abuja, the federal capital. The project was large. The contract was valuable. The commission on offer — $10 million — was extraordinary. And the man making the offer was, according to the documents in front of Sakaguchi, the Governor of the Central Bank of Nigeria.
Sakaguchi paid. Between 1995 and 1998, he paid $191 million in cash and the remainder in the form of outstanding interest — $242 million total — into accounts controlled by Nwude and his co-conspirators. [SOURCE: EFCC; NAN; Guardian Nigeria]
There was no airport. There was no contract. There was no Paul Ogwuma on the other side of the transaction. There was a letterhead and a man who had studied the architecture of authority well enough to reproduce its surface.
The fraud was discovered not by an investigator but by an accountant. In late 1997, Banco Santander attempted to acquire Banco Noroeste. In a joint board meeting, a Santander official asked why two-fifths of Noroeste's total value — half its liquid capital — was sitting dormant in the Cayman Islands. [SOURCE: NAN; Wikipedia citing sources]
That question ended the scheme.
He sold a banker an airport that did not exist. The letterhead said it was real, and for three years, for a quarter of a billion dollars, it was. Every advance-fee fraud since is a cheaper print of the same page — authority asserted, paperwork attached, a mark who wants to believe.
Nwude's career at Union Bank of Nigeria is the foundation the fraud was built on. He was not a random impersonator. He was a banking professional who understood exactly how correspondent banking relationships worked, how Nigerian state procurement processes were structured, and how a foreign banker would expect a major government contract to be presented.
The fraud required specific knowledge: how central bank letterheads were formatted, what language official Nigerian government contracts used, which payment routes were appropriate for a transaction of this scale, and how to maintain the impersonation of a specific individual — Paul Ogwuma, who served as CBN Governor from October 1993 to May 1999 — across a three-year transaction. [SOURCE: NAN — Ogwuma's tenure dates]
He had accomplices. Christian Ikechukwu Anajemba (killed in 1998), his wife Amaka Anajemba and Nzeribe Okoli all played roles in the operation. (Two lawyers, Emmanuel Ofulue and Obum Osakwe, were charged separately with trying to bribe the EFCC chairman — not with the fraud.) [SOURCE: Wikipedia citing multiple sources] The scale of a $242 million, multi-year deception required multiple people maintaining consistent stories across multiple jurisdictions.
Sakaguchi, for his part, appears to have been motivated by a genuinely extraordinary proposition — a $10 million commission on a transaction with the Nigerian government, mediated by the central bank governor. The commission alone was the kind of number that made due diligence feel like an insult to the relationship. The mark's psychology matters here not because Sakaguchi shares the blame — he does not — but because the fraud was engineered specifically to exploit the place where greed and institutional authority intersect. [SOURCE: brief; series principles]
The brief for this piece states the rule clearly: explain the mechanism, do not blame the victim. Sakaguchi was defrauded. The explanation for why a sophisticated banker paid $242 million to fraudsters is the same explanation for why Google and Facebook paid $122 million to a man with a fake invoice. The institution's verification process trusted the surface. The surface was carefully produced.
Sakaguchi paid in stages across three years. The total was $191 million in direct cash transfers and the remainder — approximately $51 million — in the form of accrued interest on the original principal between 1995 and 1998. [SOURCE: NAN; EFCC reporting]
The payments moved through accounts structured to receive them — a multi-layered operation that routed money through multiple jurisdictions. By the time the fraud was discovered in late 1997 through the Santander acquisition process, a substantial portion of the funds had been dispersed. The Cayman Islands account that triggered the discovery held the dormant remainder that Noroeste's balance sheet had obscured from routine review.
The collapse of Banco Noroeste was the human consequence. After the fraud was uncovered, the Simonsen and Cochrane families — the owners of Banco Noroeste — paid the $242 million liability themselves to facilitate the Santander acquisition. The bank was absorbed into Santander Brasil in 1999. [SOURCE: Wikipedia citing sources; NAN]
The fraud triggered criminal investigations in Brazil, Britain, Nigeria, Switzerland, and the United States. Sakaguchi himself was later arrested at New York's JFK airport and dispatched to Switzerland to face charges relating to the bank accounts he had used as part of the transaction — in effect, a victim who also faced legal consequences in multiple jurisdictions for his role in creating the banking infrastructure through which the fraud moved. [SOURCE: Wikipedia citing sources]
FIGURE
WHAT IT MEASURES
$242 million
Total extracted from Sakaguchi — $191M cash + ~$51M accrued interest. [SOURCE: EFCC / NAN]
$191 million
Cash portion paid by Sakaguchi, 1995–1998. [SOURCE: NAN / EFCC]
25 years
Sentence imposed by Justice Joseph Oyewole, Ikeja High Court, 2005. [SOURCE: NAN; Guardian Nigeria]
~3 years in custody
Arrested June 2003; sentenced November 2005 to five concurrent five-year terms; released 2006. VERIFY the release date against the primary record.
3rd largest
Widely repeated description — 'third-largest bank fraud in history' at the time, after Barings and the Iraqi Central Bank. No original source found; treat as a description, not a finding.
The fraud is called 419 after Section 419 of the Nigerian Criminal Code, which makes advance-fee fraud a criminal offence. The designation is a legal fact about where the law was codified. It is not a characterisation of a country.
The 419 template — in its foundational form — has three elements: an authority figure, an extraordinary opportunity, and documentation that reproduces the surface of legitimacy. Nwude's operation ran all three at maximum scale.
The authority figure: the Governor of the Central Bank of Nigeria. Not a mid-level official. Not a fictional title. The highest-ranking monetary authority in Africa's most populous country, whose name and office were known to any serious financial institution operating in the region.
The extraordinary opportunity: a major infrastructure contract with a $10 million commission. The scale was designed to ensure that Sakaguchi would manage the relationship personally — at a level where due diligence was delegated downward and institutional checks were bypassed by the principals involved.
The documentation: forged correspondence on what purported to be Central Bank of Nigeria letterhead, supported by a contract for a facility that had been announced at the right institutional level to be plausible. [SOURCE: NAN; EFCC reporting] The airport in Abuja was not a random invention — Abuja was then Nigeria's new federal capital, and infrastructure development there was a credible government priority.
What the fraud did not require: hacking, malware, technical sophistication, or any computer capability beyond word processing. The entire $242 million extraction was accomplished with paper, a credible impersonation, and a mark who had every incentive to believe the deal was real.
() sent a spoofed email. () sent a fake invoice. Nwude sent a forged letter on official letterhead. The technique is identical across three decades and two continents. Only the medium changed. The exploit — authority asserted, paperwork attached, verification trusting the surface — has not been updated since 1995.
Emmanuel Nwude was convicted by the Ikeja High Court in 2005. The presiding judge was Justice Joseph Oyewole. The sentence was 25 years imprisonment. [SOURCE: NAN; Guardian Nigeria; The Cable]
The conviction was the first major prosecution for the Economic and Financial Crimes Commission — the EFCC, established by the Nigerian Parliament in 2002 at the request of President Olusegun Obasanjo specifically in response to the scale of advance-fee fraud emanating from Nigeria. [SOURCE: NAN] Nwude's case was not merely a landmark for its size; it was the founding conviction of Nigeria's primary anti-financial-crime institution.
He was arrested by the EFCC on June 4, 2003, and arraigned in February 2004. He pleaded guilty on November 18, 2005, and was sentenced to five years on each of five counts, to run concurrently — 25 years on paper, five in effect. He was released in 2006: about three years in custody. [SOURCE: ThisDay, November 2005; Financial Times, October 2008 — verify the release date against the primary record]
The plea came with a settlement: $110 million to be refunded to the bank and $11.5 million paid to the Federal Government from his companies, which were to be wound up, along with fourteen properties, six cars and more than 100 million shares. By 2008 the bank's lawyers reported about $138 million recovered across Nigeria, Switzerland, the US and the UK. [SOURCE: ThisDay, November 2005; ICC Commercial Crime Services]
After release, Nwude subsequently faced a 15-count charge for allegedly forging documents related to a property that Justice Oyewole had ordered him to forfeit to his victims — in effect, charged with fraud in the aftermath of a fraud conviction, relating to assets that were supposed to go to restitution. [SOURCE: NAN; The Cable] On March 11, 2026, a Lagos court convicted him on 13 of those 15 counts and sentenced him to one year on each. [SOURCE: PM News; Channels TV, March 2026] He was also reportedly arrested in 2016 on murder charges related to an attack on a town in Nigeria. [SOURCE: Wikipedia — verify primary]
The sentence was 25 years on paper — five five-year terms running at the same time. The outcome was about three years in custody.
This gap is the honest final note the brief asks for, and it is the same accountability question that runs through (, $4.3B company penalty, 4 months served, then pardoned) and (, $122M BEC, 5 years sentenced, released after sentence). In the Nwude case the gap is more extreme: a quarter-century sentence became a fraction of that, with the money substantially unrecovered.
Banco Noroeste did not survive as an independent bank. The families who owned it paid the $242 million liability out of their own assets to facilitate the Santander sale. The bank was absorbed into Santander Brasil in 1999. The restitution — whatever was returned through the plea arrangement — did not repair that outcome.
The series does not editorialize on this gap. It records it. The sentence and the time served are two different numbers. The loss and the recovery are two different numbers. Recording both is the minimum the victims of any fraud are owed by any account of what happened.
He is a living private individual. This piece reports the court record and the public record of his conviction. It does not speculate about his current circumstances beyond what the documented record establishes.
Case 021 is where the BEC/advance-fee category begins. Not historically — the technique is older than Nigeria, older than banking — but in the documented series record that runs from (001) through (017) to this case, Nwude is the origin.
He is the proof that the exploit is not technical. It is psychological. Authority, once asserted convincingly, is treated as real by institutions built to verify authority. The check on authority is usually the letterhead, the title, the established relationship. When those can be reproduced, the check fails.
Every spam filter, every email authentication protocol (SPF, DKIM, DMARC), every vendor verification process that Google and Facebook implemented after the fraud — all of it is a response to the same problem Nwude ran in 1995 with a typewriter and a telephone. The digital defenses grew around a human vulnerability. The vulnerability has not changed.
The Nigerian Criminal Code's Section 419 gave the fraud its name not because Nigeria invented it but because Nigeria was where it was codified into law as a specific offense — a recognition that the technique had become organised at industrial scale. The EFCC, which Nwude's conviction inaugurated as a serious institution, exists for the same reason. The prosecution record is documented; the generalisation is not this piece's business.
He sold a banker an airport that did not exist. The letterhead said it was real, and for three years, for a quarter of a billion dollars, it was. Every scam email since is a cheaper print of the same page — authority asserted, paperwork attached, and a mark who wants to believe. The airport was never for sale. It never had to be.
VERIFIED SOURCES AND CORRECTIONS RECORD
EXTENSIVE VERIFICATION REQUIRED — this case has significant folklore in circulation. Brief contained two factual errors corrected above. State both the 25-year sentence AND the time actually spent in custody (about three years). No national stereotyping — the 419 reference is a legal fact, not a characterisation.
[1] NAN (News Agency of Nigeria) — court coverage, 2021: 'I didn't know how $242m got into my account.' Confirmed: Ikeja High Court, Justice Joseph Oyewole, 2005 conviction. Sentence: 25 years. $191M cash + remainder interest = $242M total. Sakaguchi as director of Banco Noroeste. Nwude's impersonation of Paul Ogwuma (CBN Governor, October 1993–May 1999).
[2] Guardian Nigeria — '$242m airport scam: I'm unaware of source of funds, Nwude tells court.' Same facts. EFCC described as: Nwude 'convinced a director of the bank, Nelson Sakaguchi, to buy a yet-to-be-built airport in Abuja for $242 million.' Third-largest bank fraud in history at time.
[3] The Cable — '$242m airport scam: I don't know anything about the money, says Nwude.' Reports the 15-count post-conviction charge for forging forfeited property documents. First major EFCC conviction confirmed.
[4] DMARGE — detailed reconstructed account: Santander acquisition December 1997 trigger; Cayman Islands dormant funds; the $10M commission; co-conspirators named; the end of Banco Noroeste (absorbed by Santander, 1999).
[5] Wikipedia — Emmanuel Nwude. Confirmed: 'Date apprehended: February 2004; released in 2006.' Title: Director of Union Bank of Nigeria (not CBN). Also: Sakaguchi arrested at JFK and dispatched to Switzerland. Nwude arrested on murder charges 2016. [Aggregator — verify all to primary]
CORRECTIONS TO BRIEF (1) EMPLOYER: Union Bank of Nigeria, not CBN. He impersonated Paul Ogwuma, CBN Governor. (2) AIRPORT: fictitious new airport in Abuja, not Murtala Muhammed International Airport. (3) TIME SERVED: about three years in custody (arrested June 2003, released 2006); the 25 years ran as five concurrent five-year terms.
TO VERIFY BEFORE PUBLICATION Exact birth date · Union Bank of Nigeria employment dates and title · Precise US court involvement (if any — this appears primarily to be a Nigerian prosecution) · Exact plea arrangement terms and amounts returned · Primary EFCC sentencing documents · The 2016 murder charge outcome · Co-defendant outcomes (Christian Anajemba reportedly assassinated — verify) · $110M offered to return (brief figure — not found in available sources)
SOURCES
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
CASE TIMELINE
HOW THE FRAUD WORKED
SOCIAL ENGINEERING METHODOLOGY — THREE ROLES
(Genesis creditor)
(trust established)
(screen share)
4,100 BTC drained
laundered
KNOWN NETWORK & CO-CONSPIRATORS
DOCUMENTED SPENDING — 30 DAYS AFTER THE HEIST
ASSET RECORD — SOURCED FROM DOJ COURT FILINGS
WHAT THIS CASE ESTABLISHED
THE FULL STORY — 12 CHAPTERS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE (3,700 WORDS)
That is a real number. It is not a monthly rent, a car price, or an investment. It is a receipt from a single night at a nightclub in Los Angeles.
One night. One club. $569,528.39 spent — documented in a court filing, sourced to the club's management, submitted as evidence by federal prosecutors. [SOURCE: NBC News / DOJ filing]
The man who ran up that tab was twenty years old. He had arrived in the United States fourteen months earlier on a tourist visa from Singapore. He had no job, no degree, and no source of income that could be explained to a tax authority.
He had, however, recently stolen 4,100 Bitcoin from a single investor in Washington D.C. — a theft that authorities would describe as the largest known single-victim cryptocurrency heist in history. The Bitcoin was worth approximately $230 million at the time of the theft. [SOURCE: NYT, Sept 2024; DOJ]
He spent it as fast as he could. He was arrested within a month.
The neighbourhood of Choa Chu Kang sits in the western reaches of Singapore, a planned residential town of Housing Development Board flats, hawker centres, and the particular density of a city that fits six million people into seven hundred square kilometres.
Malone Lam Yu Xuan was born there on July 19, 2004. He attended Unity Secondary School in the same neighbourhood, part of the ordinary infrastructure of Singaporean education — a system that routes its students through standardised examinations toward university or polytechnic, toward careers in finance, engineering, or the professions.
He dropped out in his teens.
What he did instead was go online. The platforms were Minecraft and Discord — the spaces where a generation of young men with internet connections and time on their hands built their first social worlds, learned to read communities, and discovered that the online economy ran on different rules than the one outside.
He was good at reading those rules. By the time he was a teenager he was trading cryptocurrency — not as a hobby but as a primary activity, with the focus of someone who had decided that this was the path and everything else could wait.
By the time he was nineteen, he had decided that earning it was slower than taking it.
In October 2023, Malone Lam boarded a flight to the United States. He entered on the Visa Waiver Program — no interview, no sponsor, no questions that mattered. He arrived in Miami, moved through Los Angeles, touched the Hamptons. He started with two roommates in Texas. He had a plan.
The blockchain was not broken. It never is, in cases like this. What Malone Lam and his associates broke was something far older and more reliable than cryptography: human trust.
Social engineering is the technical term for what the group did. The plain English version: they called people and convinced them to hand over their money by pretending to be people they were not.
The target in August 2024 was a wealthy early Bitcoin investor in Washington D.C. — a Genesis creditor whose holdings had been accumulating since the early days of the network, some of the Bitcoin reportedly dormant since 2012. [SOURCE: ZachXBT/@zachxbt; DOJ] The kind of investor whose wallet, if you could access it, represented a number most people would not see in a lifetime.
In August 2024, the scheme reached its peak. More than 4,100 Bitcoin transferred from a single investor. Worth approximately $230 million at the time. The largest known single-victim cryptocurrency theft in history. [SOURCE: Courthouse News, Oct 2024; DOJ]
Lam and his co-conspirator Jeandiel Serrano celebrated. They did not do this quietly.
They live-streamed it. On a Discord voice chat, to friends, they watched the Bitcoin arrive. 'Oh my god! 243 million dollars! Yes!' [SOURCE: ZachXBT; reported by NYT, NBC News] During the stream, one participant's screen inadvertently displayed his real Windows username. A separate recording showed another participant being referred to by his first name. These were the threads that would unravel everything.
He did not hide the money. He displayed it. With the same instinct that drove to post every watch, every car, every front row — Malone Lam converted 4,100 Bitcoin into the most visible lifestyle money could buy, as fast as it was physically possible to spend it.
Within weeks of the theft, he was in Los Angeles. The clubs in LA told investigators that Lam had been trying to pay his tabs in cryptocurrency and was spending approximately $400,000 to $500,000 per night. [SOURCE: NBC News / DOJ filing] One receipt entered into evidence showed a single night's tab of $569,528.39. [SOURCE: NBC News / court filing]
He bought 31 luxury vehicles. [SOURCE: DOJ — prosecutors' own figures] Among them:
The prosecution noted that 'many of Lam's vehicles have not been located as of yet, such as his Pagani Huayra that he purchased for $3,800,000.' [SOURCE: NBC News quoting DOJ filing] Twenty-two of the thirty-one cars remained unrecovered. The money had physically disappeared into metal and carbon fibre and been driven away.
The Hermès Birkin is a handbag that starts at approximately $10,000 for the most basic configuration and climbs from there — to $20,000, to $50,000, to prices that require an invitation from the house to spend. It is an object that carries its price in its scarcity, its waitlist, its deliberate exclusivity.
Malone Lam gave them away at nightclubs.
Five Hermès Birkin bags, worth approximately $20,000 each, handed to women he met at clubs. [SOURCE: The Droid Guy reporting on DOJ filing] Not as gifts in the romantic sense — as favours, as calling cards, as the currency of a man who had decided that money was the language and he was fluent.
One woman reportedly received a Birkin after chatting with him for ten minutes. Another found one on her nightstand. The bags were sourced, paid for, and distributed as casually as most twenty-year-olds buy rounds of drinks.
Then there was the Lamborghini.
A pink Lamborghini Urus. Gifted — or attempted to be gifted — to a woman on Instagram as a means of winning her back or winning her over, the record is not precise on which. Her response, documented in reporting: 'I am taken once again.' [SOURCE: The Droid Guy] The car, reportedly, was still sent. She still declined. The Lamborghini sat somewhere, ungifted, as a monument to the specific failure of money to solve problems that money did not create.
And then there were the Birkins sent to his girlfriend after he was arrested.
This is documented in the IRS Criminal Investigation press release and the DOJ superseding indictment. Following his arrest in September 2024, while in pretrial detention, Lam allegedly continued working with members of the enterprise — directing them to buy luxury Hermès Birkin bags and hand-deliver them to his girlfriend in Miami, Florida. [SOURCE: IRS/DOJ Nov 2025 press release; DOJ superseding indictment]
He was in a detention cell. He was still ordering Birkins. From prison. For delivery. To Miami.
On September 10, 2024, Malone Lam boarded a private jet from Los Angeles to Miami. He had spent weeks in LA accumulating receipts, cars, and attention. Now he moved the operation to Florida.
In Miami, he rented multiple homes. One was on Hibiscus Island — a private island in Biscayne Bay accessible only by a guarded causeway, where the houses sit behind gates and the water is visible from every window. Another was near the water. A third was a luxury mansion with ten bedrooms and ten bathrooms — the kind of property typically used, the reporting notes, by actors, businessmen, and politicians. [SOURCE: The Droid Guy / NBC News]
The monthly rent on one of the Miami properties: $68,000. [SOURCE: NBC News / DOJ filing — Malay Mail]
He was twenty years old. He had been in the United States for less than a year. His visa had expired.
The enterprise was not just renting property in his own name. Co-conspirators obtained luxury rental homes for members of the enterprise using fake identity documents. [SOURCE: IRS/DOJ superseding indictment] They booked private jet travel with stolen cryptocurrency. They concealed ownership of exotic cars by registering them in shell company names. They shipped bulk cash through US mail to members of the enterprise — hidden inside Squishmallows stuffed animals. [SOURCE: DOJ superseding indictment, Nov 2025]
The Squishmallows detail is in the federal indictment. Bulk cash, mailed across the country, packed into stuffed animals.
It started with two roommates in Texas.
By the time the superseding indictment was filed in November 2025, the network had grown to Lam plus twelve others — fourteen people in total, operating across California, Connecticut, New York, Florida, and overseas. [SOURCE: DOJ superseding indictment Nov 2025; IRS Criminal Investigation]
The enterprise had specialised roles. Some members ran the unlicensed crypto-to-cash conversion services that turned stolen Bitcoin into spendable dollars. Others obtained the rental properties using fake identities. Others booked the private jets. Others — this is in the indictment — hid the cash in the stuffed animals and mailed it.
The operation had gone from two roommates to a structured criminal enterprise with a supply chain, a logistics function, and a money laundering operation that the DOJ would ultimately charge under RICO — the Racketeer Influenced and Corrupt Organizations Act. The first Bitcoin-related RICO case in American legal history. [SOURCE: DOJ Sept 2026 press release; BBC]
In July 2024, the group expanded into physical crime. Marlon Ferro traveled to New Mexico and broke into a victim's home to steal their hardware cryptocurrency wallet while Lam monitored the victim's location by logging into their iCloud account remotely. [SOURCE: DOJ indictment] They had gone from calling people to burglary. The network was arming itself.
While Malone Lam was spending $569,528 in a single night at an LA club, a pseudonymous blockchain investigator who goes by ZachXBT was watching the Bitcoin move.
ZachXBT is a former crypto scam survivor who became, by reputation, the most effective private blockchain forensics investigator in the industry. He operates under a pseudonym, has never revealed his real name, and maintains a following of hundreds of thousands of people who track his work exposing fraud in the cryptocurrency space. He is, in the context of this case, the person the story turns on.
On the day of the August 2024 theft, ZachXBT was in transit when he saw the blockchain movement. He began tracking. The stolen funds split into three main flows — he identified three suspects. He posted publicly on X (formerly Twitter) that a theft was occurring. He received a tip from an informant with leads on the hacker's identity. For the following week he worked through the night, sleeping four to five hours a day, sharing his findings directly with law enforcement. [SOURCE: ZachXBT reporting compiled by Chaincatcher/Bitget; ZachXBT @zachxbt on X]
Then he found the video.
A 90-minute recording of the Discord session during the heist — the voice chat in which Lam, Serrano, and others had celebrated as the Bitcoin arrived. During the stream, one participant's Windows screen had briefly displayed his real username. People on the call referred to others by their first names. 'Oh my god! 243 million dollars! Yes!' [SOURCE: ZachXBT; reported by multiple outlets including TradingView News, NYT]
ZachXBT posted the recording. He identified three suspects. He shared everything with law enforcement.
The mechanism of exposure was the same mechanism that had made vulnerable: the compulsion to share the moment. To have an audience for the win. To let people see. Lam and Serrano had streamed themselves committing the largest single-victim cryptocurrency theft in history, and that stream had been obtained, posted publicly, and delivered to the FBI by a man on a plane watching the blockchain move in real time.
On September 18, 2024, an off-duty police officer tipped off Malone Lam that the FBI was coming.
What he did with this information: he threw his mobile phone into Biscayne Bay. [SOURCE: Wikipedia citing primary reporting; DOJ record] Not into a bin, not wiped and handed to a friend, not left in a hotel room. Into the water. Biscayne Bay, which is a body of water, into which he threw the device that contained whatever he believed the FBI most needed to find.
The FBI arrived at the mansion on Hibiscus Island anyway. Lam was there. He was arrested. The phone was in the bay.
Jeandiel Serrano was arrested the same day at Los Angeles International Airport — returning from a holiday in the Maldives with his girlfriend. [SOURCE: Malay Mail / DOJ]
The network continued operating without them. Through the autumn of 2024, through the winter, through the spring of 2025. The superseding indictment in May 2025 named Lam plus twelve others. By May 2026, nine of the thirteen defendants had pleaded guilty. Some agreed to testify against Lam. [SOURCE: DOJ press release May 2026]
And Lam, in pretrial detention, allegedly continued directing the enterprise from inside. The Birkins sent to his girlfriend in Miami were not an act of romance. They were evidence, documented in a federal indictment, that he was still running the operation from a detention cell. [SOURCE: IRS/DOJ Nov 2025]
This is the case that explains why the METRIC row exists on every TraceChain card.
The lesson: 4,100 Bitcoin from one victim is the only figure that does not change depending on when you measure it. Every dollar figure in this case is a dollar figure measured at a specific moment on a specific exchange. Lead with the BTC. Label the dollars.
On September 8, 2026, Malone Lam Yu Xuan pleaded guilty in the US District Court for the District of Columbia to RICO conspiracy.
The charge — the Racketeer Influenced and Corrupt Organizations Act — was not designed for cryptocurrency. It was designed for organised crime. For the Mafia. For enterprises that operate as ongoing criminal organisations across multiple states, with structured roles and coordinated operations. The DOJ determined that what Lam had built, in less than two years from two roommates in Texas, qualified. [SOURCE: DOJ Sept 2026 press release; BBC]
It was the first Bitcoin-related RICO prosecution in American legal history.
The DOJ press release was headlined: 'Singaporean Ringleader of $245 Million Cryptocurrency Racketeering Enterprise Pleads Guilty.' [SOURCE: DOJ/US Attorney DC, Sept 8, 2026]
Lam appeared in court in a green prison jumpsuit. A status hearing was scheduled for December 2026. He has not yet been sentenced as of this writing. He faces up to 20 years. [SOURCE: DOJ; Malay Mail]
Singapore is a country with a specific relationship to crime and consequence. The legal system is strict, the consequences are public, and the national mythology around meritocracy and order runs deep enough that a twenty-year-old from a Choa Chu Kang HDB block committing the largest single-victim cryptocurrency theft in history and spending it in Hollywood nightclubs was not a story the country could process quietly.
The Straits Times — Singapore's newspaper of record — covered the case extensively, running multiple stories at different dollar figures as the investigation developed. The Business Times reported on the plea. The coverage was not congratulatory. It was, in its own way, a reckoning with what it meant that one of their own had left, had reached, and had been caught.
He was, by most measures, a dropout from a respectable neighbourhood who had found a way to make the system irrelevant to him. The school he had left — Unity Secondary — is not a school that produces criminals. It produces engineers, managers, the ordinary working population of a city-state built on competence and order.
He found a different order. It lasted fourteen months in the United States before the blockchain gave him up.
was about the flex as evidence. posted his way into a federal case file. He turned his Instagram into the prosecution's exhibit list.
Case 002 is the same story told in a different register. Malone Lam did not build an Instagram persona over nine years. He was twenty years old. He had no patience for nine years of careful brand-building. He had 4,100 Bitcoin and a phone and the specific generational instinct to share the moment — to stream it, to show it, to let the people in the Discord chat see.
The live-stream of the heist. The Discord where people referred to each other by name. The Instagram posts that let ZachXBT track his location through his girlfriend's location tags. The $569,528 receipt that is now a court exhibit. The Squishmallows stuffed with cash. The pink Lamborghini.
Every element of the story is evidence. Every element of the evidence was content.
In , the persona was built over years and then dismantled by the prosecution. In Case 002, the persona lasted months — barely long enough to buy all the cars. The speed compressed the arc but did not change its shape. The instinct was identical: to take the money and make it visible, to have an audience for the arrival, to let the world see what you had reached.
sat in the front rows of Paris fashion weeks and built a brand that 2.5 million people believed in for nine years before the FBI arrived.
Malone Lam threw a phone into Biscayne Bay and was arrested within a month.
$569,528.39.
One night. One club. One receipt that is now a line in a federal court filing in the District of Columbia. [SOURCE: NBC News / DOJ]
The Pagani Huayra is somewhere. Twenty-two of the thirty-one cars have not been located. The phone is in Biscayne Bay. The Birkins were delivered to a woman in Miami by people following instructions from a detention cell. The Bitcoin is partly recovered — approximately $70 million frozen or recovered as of October 2024 — and the rest is still in the trail. [SOURCE: Malay Mail / DOJ]
He was twenty years old when he stole it. He will not be free for most of his twenties.
The blockchain detective who caught him was on a plane when the Bitcoin started moving. He posted his findings publicly. He worked through the night. He found the video of two men celebrating in a Discord call. He delivered the evidence to the FBI.
Twenty-two cars still missing. One phone in the bay. A girl who said no to the Lamborghini. Nine co-defendants who said yes to the prosecutors.
All figures labelled by what they measure. Dollar amounts vary by source — see Part 9. The stable anchor throughout is 4,100 BTC from one victim. Lam has pleaded guilty; sentencing has not yet occurred as of this writing.
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
THE DOUBLE LIFE
BRIEFING THE AGENTS WHO WERE HUNTING HIM
Computerworld, August 2009 — when the third indictment dropped
The Secret Service recruited Gonzalez as a cooperating source after his 2003 arrest. He briefed agents on the carding ecosystem — the forums, the methods, the markets. He was useful. He was real. He was providing genuine operational intelligence that led to arrests of other people in the ecosystem. And then he went home and ran the largest version of the operation he had just described. Every briefing was an autobiography with the identifying details edited out.
He is the only person in this series who was inside the investigation while it was looking for him. Not separate from it — inside it. The photograph the Secret Service used for the target was taken before 2009, when he was on file as an asset.
CASE TIMELINE
HOW THE FRAUD WORKED
HOW IT WORKED — FROM THE CASE BRIEF
KNOWN NETWORK & CONNECTED CASES
WHAT THIS CASE ESTABLISHED
BACKGROUND & BIOGRAPHY
EARLY LIFE & CAREER
THE BREACHES
THE DOUBLE AGENT — INFORMANT AND CRIMINAL SIMULTANEOUSLY
THE INFORMANT PERIOD
SENTENCING & RECORD
WHAT THIS CASE ESTABLISHED
THE FULL STORY — 11 PARTS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE INFORMANT (3,300 WORDS)
He complained about counting it by hand.
The currency-counting machine had broken, and he had $340,000 in cash that needed to be tallied, and the inconvenience of doing it manually was, to him, a logistical problem worth mentioning. Not the fact of having $340,000 in cash in a room. Not the source. The counting. [SOURCE: Miami Herald / reporting]
This is the detail that opens the case because it tells you everything about the man in a single image: money so abundant it became a chore. Stacks high enough to require a machine. And when the machine failed, the complaint was not about the money or the risk or the exposure — it was about the tedium of touching every bill.
He also threw himself a birthday party that cost $75,000. [SOURCE: Reporting / Miami Herald]
His name was Albert Gonzalez. He stole more than 170 million credit and debit card numbers — the largest such theft in American history. And while he was doing it, he was a cooperating informant for the United States Secret Service.
He was born in 1981, in Cuba, and raised in Miami.
The family settled in the kind of neighbourhood that produces the working class of a city built on tourism, trade, and the particular American ambition of people who arrived from somewhere else. Miami in the 1980s and 1990s was a city of reinvention — a place where origin was less important than what you did with the opportunity the city offered.
What Albert Gonzalez did with it was buy a computer. He was twelve years old. [SOURCE: Court record / reporting]
At South Miami High School, he was described as the leader of a group the reporting calls the computer nerds — but the word "troubled" appears alongside it. He was not the quiet kid in the back of the lab. He was the kid who ran the lab, who understood what the machines could do before the teachers did, and who had already decided that the boundary between learning how a system worked and breaking into that system was a distinction other people cared about more than he did.
At fourteen, he hacked NASA. [SOURCE: Reporting]
That sentence requires a pause. Not because hacking NASA at fourteen is unprecedented — the history of American computer crime is populated with teenagers who reached further than anyone expected and touched systems that should have been unreachable. But because it establishes, very early, the specific quality that made Gonzalez different from the other carders and hackers of his era: he did not operate at the edges of the system. He went to the centre. He touched the thing that mattered most. And he did it before he was old enough to drive.
In 2000, Gonzalez moved to New York City. He lasted three months. Then he moved to Kearny, New Jersey — a working town across the Meadowlands from Manhattan, the kind of place where rent was cheap and nobody asked what you did for a living as long as you paid on time.
In Kearny, he found his community. Or built it.
ShadowCrew was an online forum — a marketplace where stolen credit card numbers, ATM PINs, and the tools to use them were bought, sold, and traded by a community of carders who operated in the open, behind screen names, with the confidence of people who believed the internet was a jurisdiction unto itself. [SOURCE: DOJ / court record]
Gonzalez's handle was CumbaJohnny. He was accused of being a mastermind of the operation. The numbers associated with ShadowCrew: 1.5 million stolen card and ATM numbers trafficked through the forum. [SOURCE: Court record]
1.5 million is a large number. It would not remain the largest number associated with his name for long.
In 2003, he was caught. Busted for hacking. The details of the arrest are straightforward — he was identified, detained, and faced the full weight of federal charges that could have sent him to prison for years.
What happened next is what makes this case different from every other case in this series.
He became an informant. A cooperating source for the United States Secret Service. [SOURCE: DOJ / Secret Service / Computerworld]
The Secret Service — which handles financial crimes alongside its protective duties — recruited him. The logic was sound from their perspective: here was a young man who understood the carding ecosystem from the inside, who spoke the language, who knew the players. A man like that, cooperating, could map the networks that agents spent years trying to penetrate from the outside.
He cooperated. He provided intelligence. He helped agents understand how carding operations worked — the acquisition of numbers, the encoding onto blank cards, the cash-out at ATMs, the resale on forums. He was useful. He was knowledgeable. He was, by the assessment of the agents who worked with him, an asset.
He was also, per the record that would later emerge, still hacking. Still stealing. Still running operations that made the work he'd been caught for look like a practice round.
The headline that would eventually describe this arrangement, from Computerworld in August 2009: "Government informant is called kingpin of largest U.S. data breaches."
The man briefing federal agents on how carding worked was the largest carder alive. Every explanation he gave them was a description of his own operation, with the identifying details edited out.
The number requires context before it can be understood.
170 million. That is the combined count of credit card and debit card numbers that Albert Gonzalez and his associates stole between 2005 and 2007. [SOURCE: DOJ indictment] It is not a dollar figure — it is a count of card numbers. Each number represents a person's financial identity: the card number, the expiration date, and in many cases the associated data needed to create a functioning clone.
The victims were not individuals. They were the companies that held those individuals' data:
TJX Companies — the parent of TJ Maxx, Marshalls, and HomeGoods. 45.6 million card and debit numbers stolen over an eighteen-month period ending in 2007. [SOURCE: Court record]
Heartland Payment Systems — a payment processor that handled transactions for hundreds of thousands of merchants. 130 million card numbers. The single largest breach in the set. [SOURCE: Court record]
Hannaford Brothers — a supermarket chain. 4.6 million numbers. [SOURCE: Indictment]
Also named in the indictments or associated with the scheme: Dave & Buster's, 7-Eleven ATMs, and others.
The method, as the court record describes it, operated in layers. The first layer was finding a way in — and the way in was almost always the same: SQL injection against a company's web-facing systems. A technique that, even in 2005, was well-understood and well-defended against by companies that took the basic precautions. The companies that Gonzalez targeted had not taken those precautions, or had not taken them thoroughly enough.
Once inside, he deployed tools that maintained access — backdoors that allowed his team to return without being detected. From that foothold, they moved laterally through internal networks. And then the part that made the operation extraordinary: they intercepted card data in transit. Packet sniffing. ARP spoofing. The technical terms describe a man sitting inside a company's own network, watching card numbers flow past like water through a pipe, and capturing them.
The data was exfiltrated and sold.
Every step of that chain has a standard defence. That is the lesson the case teaches — not the method, which belongs in a textbook, but the fact that 170 million people's card numbers were exposed because the companies holding those numbers had not deployed the controls that already existed.
The scale of what Gonzalez did was so large that no single federal district could contain it.
May 2008: the first indictment, in New York, for the Dave & Buster's case. [SOURCE: DOJ]
May 2008 — the same month: the second indictment, in Massachusetts, for the TJX case. The one that put 45.6 million card numbers into the public record. [SOURCE: DOJ]
August 2009: the third indictment, in New Jersey, for Heartland Payment Systems. 130 million numbers. The biggest single breach, filed as a separate case because it involved different victims, different infrastructure, different evidence. [SOURCE: DOJ / District of New Jersey]
Three federal indictments. Three jurisdictions. Three sets of prosecutors, three courtrooms, three evidence chains — all converging on the same man, who had been cooperating with the Secret Service while committing the crimes that generated each of those filings.
The Computerworld headline ran in August 2009, when the third indictment dropped and the scale became visible to the public for the first time. The informant was the kingpin. The briefings had been autobiographies.
This is the part that distinguishes Gonzalez from every other fraudster in this series.
built a persona. built a spending spree. built a company. Madoff built duration. Holmes built a story. Each of them operated in a space that was, fundamentally, separate from the people who would eventually investigate them. There was the fraud, and there was the investigation, and the two met at the point of arrest.
Gonzalez was inside the investigation.
He sat with the agents. He explained how the systems worked. He provided intelligence — real intelligence, useful intelligence, intelligence that led to arrests of other people in the carding ecosystem. The Secret Service valued him. He was not pretending to cooperate while providing nothing. He was providing genuine operational detail about the world he dominated.
And then he went home and ran the operation.
The photograph the Secret Service used in connection with the case was taken before 2009 — because they had him on file. As an asset. As someone who worked for them. The photograph of their informant became the photograph of their target. [SOURCE: Secret Service / reporting]
The duality is not something the record resolves into a clean narrative. It would be easy to write that he was cynically manipulating the government from inside, or that the government was negligently failing to supervise its own asset. The truth is probably less dramatic and more human: he was a man who understood two systems — the federal law enforcement system and the criminal carding system — and who lived comfortably inside both of them simultaneously, giving each one exactly enough to sustain the relationship, until the scale of the operation made the duality impossible to maintain.
He was, in the end, too good at both jobs. The informant provided real value. The carder stole 170 million numbers. Both of those things were true at the same time, and neither cancelled the other out.
The money was enormous. The life was strange.
Gonzalez stayed in lavish hotels. He threw the $75,000 birthday party. He had the $340,000 that needed counting by hand. The lifestyle trappings were present — the visible, performative spending that appears in every fraud case in this series.
But his actual homes were described as modest. [SOURCE: Reporting / Miami Herald]
That detail matters because it reveals something different from the model or the model. Those men spent to be seen spending. The money was fuel for the image. The lifestyle was the product.
Gonzalez spent for the theatre of it — but not for the permanence. He did not build a brand. He did not post the party. He lived in an era before Instagram made every purchase a content opportunity, and his instinct was not toward documentation but toward experience. The $75,000 party was for the people in the room. The $340,000 was for counting, not for photographing.
The money was not the point. The access was the point. The knowledge that he was operating at a level that no one around him fully understood — that the agents he briefed did not know they were being briefed by the man they were hunting, that the companies whose networks he had penetrated did not know they had been penetrated, that the card numbers flowing through global payment systems carried his fingerprints and nobody had yet matched the prints.
That was the high. Not the party. The knowing.
On September 11, 2009, Gonzalez pleaded guilty in the Secret Service's TJX case. [SOURCE: Secret Service press release, 11 Sept 2009]
On March 25, 2010, he was sentenced to twenty years in federal prison. [SOURCE: NYT, 26 Mar 2010; Reuters, 26 Mar 2010; DOJ]
The sentence reflected the scale. The judge considered the informant cooperation — and sentenced him to twenty years anyway. The cooperation had been real, but the crime committed during the cooperation was too large for the cooperation to substantially mitigate.
DOJ's own language: "Leader of Hacking Ring Sentenced for Massive Identity Thefts from Payment Processor and U.S. Retail Networks." [SOURCE: DOJ Office of Public Affairs]
Twenty years. The same sentence the federal system would later give Sebastian Greenwood for OneCoin. The same range that applies to armed bank robbery. For a man who never touched a weapon, never met his victims, never entered a bank. He sat at a keyboard, found the holes in systems that should not have had holes, and took 170 million numbers that were not his to take.
A note on the names, because they tell you something about the culture.
segvec — a segmentation violation, a specific kind of software crash. A technical handle that signals competence to other technical people.
soupnazi — a Seinfeld reference. The character who withheld soup from customers who did not follow his arbitrary rules. The handle of a man who controlled access and enjoyed the power of it.
j4guar17 — the animal and a number. Speed and youth.
cumbajohny, kingchilli, stanozlolz — the others, less serious, more playful, the kind of handles a man generates when he needs a new identity for a new forum and does not think anyone will ever read them in a court filing.
They read them in three court filings. In three jurisdictions. The handles that were supposed to be walls between his identity and his activity became exhibits. The anonymity of the internet, which he had relied on as an article of faith, failed at the exact moment that the Secret Service realised their informant and their target shared the same operational knowledge because they were the same person.
Albert Gonzalez was released from federal custody in 2023. [SOURCE: Federal Bureau of Prisons records / reporting]
He served approximately thirteen years of a twenty-year sentence. He is now in his early forties. He lives, as far as the public record indicates, as a private citizen. He has not spoken publicly about the case in any substantial way since his sentencing.
The companies he breached have rebuilt. Heartland Payment Systems was acquired by Global Payments. TJX Companies continues to operate TJ Maxx, Marshalls, and HomeGoods across thousands of locations. The 170 million card numbers were replaced, reissued, and forgotten by most of the people whose wallets held them.
The payment industry changed. EMV chip cards — which Gonzalez's method could not have intercepted in the same way — became the global standard. Point-to-point encryption became a baseline requirement. PCI DSS compliance, which was already a standard during his spree but unevenly enforced, became the cost of doing business for any company that touched card data.
He did not cause these changes alone. But his name is in the room every time the payment security industry explains why the controls matter. He is the example. He is the reason the auditor can point at a company and say: this is what happens when you do not encrypt card data in transit.
170 million card numbers — the largest card data theft prosecution in US history at the time of indictment. [SOURCE: DOJ]
The first major case to demonstrate that a cooperating informant could simultaneously operate at the highest level of the crime they were helping investigate — and that the federal system's own oversight mechanisms could fail to detect it.
SQL injection, a well-understood vulnerability with well-understood defences, was the entry point for every major breach in the case. The lesson is not technical sophistication — it is the cost of leaving known doors unlocked.
Three simultaneous federal prosecutions across three jurisdictions — New York, Massachusetts, New Jersey — for crimes committed by the same person during the same period while cooperating with federal law enforcement.
The case accelerated the adoption of chip-based card technology (EMV), point-to-point encryption, and stronger PCI DSS enforcement across the US payment industry.
He taught the investigators how carding worked.
He sat across the table from Secret Service agents and explained the ecosystem — the forums, the methods, the markets, the way stolen card data moved from breach to buyer to blank card to ATM withdrawal. He gave them real intelligence. Real names. Real operations. He helped them make arrests.
And when the briefing was over, he went home and executed the largest version of the operation he had just described.
170 million card numbers. Three federal indictments. A $75,000 birthday party. A broken counting machine and $340,000 in cash. A man who hacked NASA at fourteen, became a federal informant at twenty-two, and was sentenced to twenty years at twenty-nine.
Every other case in this series is about a person who built something — a persona, a company, a Ponzi, a product — and then watched the investigation close in from outside. Gonzalez is the only one who was inside the investigation while it was looking for him.
He taught them how it worked. He was the best at it. They were the same thing.
All figures labelled by what they measure. Card counts are card counts — not dollar amounts. This involves a living person released from federal custody in 2023.
*What would prove it wrong?*
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
THE WOLF OF WALL STREET — FILM VS RECORD
THE GAP BETWEEN THE IMAGE AND THE RECORD
The film grossed over $390M worldwide. Five Academy Award nominations. DiCaprio plays Belfort. It is based on a memoir written by a man with strong financial incentives to make his life sound as entertaining as possible. The court record tells a more specific story: 1,513 clients, $200M in losses, 22 months, a wire worn on his own partners.
CASE TIMELINE
HOW THE FRAUD WORKED
HOW IT WORKED — FROM THE CASE BRIEF
KNOWN NETWORK & CONNECTED CASES
WHAT THIS CASE ESTABLISHED
BACKGROUND & BIOGRAPHY
EARLY LIFE & EDUCATION
STRATTON OAKMONT — THE OPERATION
THE AFTERMATH — WIRE, PRISON, AND THE BOOK
THE COOPERATION
THE LEGEND — HOW IT OUTRAN THE FRAUD
THE GAP — FRAUD VS. FILM
THE FULL STORY — 7 PARTS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE LEGEND (2,500 WORDS)
The movie opens with Leonardo DiCaprio screaming.
He is on a yacht. He is high. He is rich in a way that seems to exist on a different plane from ordinary richness — not the quiet, managed, invested richness of people with advisors and portfolios, but the velocity-of-cash richness of a man who has more money coming in than he can spend fast enough to keep up. The film runs three hours. For most of those three hours, someone is screaming, or taking drugs, or throwing things, or spending money on something obscene.
Martin Scorsese directed it. Leonardo DiCaprio plays Jordan Belfort. The film received five Academy Award nominations. It grossed over $390 million worldwide. It is one of the most profitable biopics ever made.
Jordan Belfort watched it from the other side of the screen as a famous man. He had already written the memoir. He had sold the film rights. He was being played by the biggest movie star on earth.
The record — the court record, the NASD record, the SEC record, the bankruptcy filing — tells a different story. Not a less interesting one. A more specific one. 1,513 clients. Approximately $200 million in investor losses. Twenty-two months in federal prison. $110.4 million in restitution ordered.
He is, by the numbers in this series, a relatively small operator. His losses are a fraction of Madoff's. His victims are numbered in the thousands, not the millions. His sentence was shorter than anyone else in this collection.
He is also the one a stranger can name.
Jordan Ross Belfort was born on July 9, 1962, in the Bronx, New York City. His parents were both accountants. He grew up in Bayside, Queens — a middle-class neighbourhood in the northeastern corner of the borough, the kind of place that produces people who know how close they are to Manhattan and who measure their lives against that distance.
He attended American University in Washington D.C. and graduated with a bachelor's degree. He then, by his own account, briefly enrolled in a dental school programme before deciding that dentistry was not where the money was and pivoting toward finance.
He started as a broker. The conventional path. A licensed broker placing trades for clients, earning commissions, learning the mechanics. He was good at it, or specifically good at the part of it that involved persuading people to buy things — which, in the brokerage world, is the primary skill.
He co-founded Stratton Oakmont, named to evoke the Ivy League establishment — the kind of patrician, old-money credibility that a firm operating from Long Island had no actual claim to. The name was the first fiction. What followed was the operation.
Stratton Oakmont was a boiler room. Not in the metaphorical sense that it was aggressive or high-pressure. In the specific, regulatory sense: a firm that used manipulative sales tactics and broker misconduct to push clients into investments that served the firm's interests rather than the clients'.
The product was penny stocks — low-priced securities in small companies, trading on markets with lower listing requirements, with thin trading volume that meant even modest buying pressure could move the price significantly. These are not inherently fraudulent instruments. But they are instruments that are relatively easy to manipulate when a firm controls the supply and the sales force simultaneously.
Stratton Oakmont's model was a pump-and-dump. The firm would obtain a large position in a penny stock — often through an IPO that it managed, giving it allocations of shares at prices before the public offering. Its brokers, trained in high-pressure selling techniques, would then call clients and push the stock hard: rising fast, limited time, get in now. The calls created buying demand. The demand pushed the price. When the price was high enough, the firm sold its own position into the market the sales force had just created. The clients who had been told to buy were left holding stock the firm had already sold at a profit. [SOURCE: NASD / SEC; case record]
At peak, Stratton Oakmont had approximately a thousand brokers. It was one of the largest broker-dealers on Long Island. It processed enormous volumes of transactions. It made a great deal of money for the firm. It lost approximately $200 million for approximately 1,513 clients. [SOURCE: US v. Belfort, E.D.N.Y.; SIPC filing]
This is where the case requires the sharpest separation in the series.
The film is not a fraud. It is a movie. It is based on a memoir written by a man with strong financial incentives to make his life sound as entertaining as possible. Scorsese made a great film about a real event and in doing so produced something that most people have seen — which means most people's mental model of Jordan Belfort is a three-hour dramatisation of a self-serving memoir, not a court document.
This matters because the gap between the image and the record is the specific lesson of Case 012. It is not that Belfort was worse than the film shows. It is that the film made him aspirational in a way that the record does not.
The National Association of Securities Dealers had been examining Stratton Oakmont since 1989. The firm operated under regulatory scrutiny for years — which is itself a data point. The boiler room ran, expensively and loudly and visibly, for the better part of a decade before it was shut down.
In December 1996, the NASD expelled Stratton Oakmont. The firm was finished. The expulsion was the end of the operation as a regulated entity. [SOURCE: NASD action, December 1996]
The federal case built more slowly. Belfort was indicted for securities fraud. He did not fight it. He pleaded guilty in 1999. He then did something that the film handles but does not dwell on: he cooperated. Fully and specifically.
He became an FBI informant. He wore a recording device. He gathered evidence against his former partners and subordinates — the people who had worked for him, run the operation with him, profited alongside him. He testified against them. [SOURCE: US v. Belfort, E.D.N.Y.; case brief]
This cooperation is the reason his sentence was 22 months. The cooperation credit is substantial. He received a 22-month sentence for the leadership of an operation that cost clients $200 million because he gave the government his own people.
In this he is the operational counterpart to in . Different context, different fraud, different relationship to the person he was cooperating against. But the structure is the same: he wore a wire on the people closest to him, and the sentence reflects it.
The series applies the same discipline to every case: figure, label, source. Case 012 has four numbers that must not be blurred.
The restoration rate — $110.4 million ordered against approximately $200 million in losses — is roughly 55 cents per dollar lost. This is not unusual in financial fraud cases. Asset recovery is partial, restitution orders are not always collected in full, and the gap between what a court orders and what victims actually receive is often significant. In Belfort's case, the restitution structure tied payment to his income — 50% of earnings — which created the specific incentive for the post-prison career.
He was released from prison and became a motivational speaker.
The logic is not as cynical as it sounds, or rather it is exactly as cynical as it sounds but with a legal structure attached. Fifty percent of his income went toward the $110.4 million restitution order. The more he earned, the more went to victims. The career that let him earn the most — the book, the film rights, the speaking fees — was structurally connected to the restitution obligation.
The memoir, The Wolf of Wall Street, was published in 2007. It is written in the register of a man who wants you to enjoy the ride before you get to the part where everything collapses. It is entertaining. It is self-serving. It is careful in the way that people who have lawyers and reputations to manage are careful. It is the document that Scorsese optioned.
The film, released in 2013, grossed over $390 million worldwide. It received five Academy Award nominations. It turned Jordan Belfort into a global cultural figure. The man who had defrauded 1,513 clients and worn a wire on his partners became one of the most recognisable names in finance — not despite having committed fraud, but specifically because of a three-hour cinematic rendering of that fraud.
He consults. He speaks. He charges substantial fees to speak about sales and motivation and the lessons of his experience. His image — the one the film created — is part of the commercial product. The Wolf of Wall Street is not a cautionary tale in the way he deploys it. It is a brand.
Every case in this series has a thesis. A single thing it documents about how fraud at scale works.
Case 012's thesis is different from every other case, because it is not primarily about how the fraud worked. It is about what happened to the fraud after it ended.
Madoff's fraud ran for 48 years. destroyed $40 billion in market value. Ignatova took $4 billion from 3.5 million victims and disappeared. deceived the most credentialed investors in the country. Stanford defrauded 20,000 people across 100 countries.
Jordan Belfort defrauded 1,513 people and approximately $200 million.
He is the one a stranger can name.
The film did something that none of the fraud itself could do: it made the experience of the fraud cinematic. It gave it a soundtrack, a runtime, a DiCaprio performance, and a three-hour arc that ends with Belfort being led away in handcuffs and then — inevitably, because this is the shape the story has — beginning again. The film closes on a motivational seminar. The room is full. He is telling the story again.
This is where the series contrast is sharpest. built a brand on Instagram. spent faster than he could count. told the world the algorithm was working. Madoff fabricated 48 years of returns. All of them built their own legend as part of the fraud.
Belfort built his legend after. After the guilty plea, after the wire, after the 22 months, after the release — the film came out and turned a convicted fraudster who cooperated against his partners into a cultural icon. He did not build the legend as the fraud. The fraud ended. Then the legend was built.
That is the specific lesson of Case 012: the retelling can outlast, outscale, and outperform the original. $200 million in losses put him at the bottom of this series by scale. The film put him at the top by recognition. The gap between those two things — between what he did and what he is known for — is the whole case.
Jordan Belfort is 64 years old. He consults on sales. He speaks at conferences. He charges fees. His face appears on the cover of his book. Leonardo DiCaprio played him. He is, by several measures, the most famous person in this series who is still actively trading on the fame.
He is also the only person in this series who turned his fraud into a performance career before anyone was convicted. The memoir preceded the conviction. The film came a decade after the plea. The speaking career runs alongside both. The entire arc — from fraud to prison to book to film to keynote — is a single coherent commercial operation, and it is built on a crime that cost 1,513 people approximately $200 million.
The victims are part of the record too. They are 1,513 people who were told by trained brokers, using specifically designed sales techniques, to buy stock that those brokers already knew was going to be sold out from under them. They did not get to write the memoir. They did not get the film. They got the loss.
This does not make Jordan Belfort uniquely bad. Every fraudster in this series left victims behind. The victims of Madoff are still waiting on the Picard trustee. The victims of Stanford got partial recovery after a decade of litigation. The victims of Ignatova may never see the money.
What makes Case 012 distinct is the specific way the story was retold — not by investigators or prosecutors but by the man himself, in a memoir and a film rights deal, and then amplified by one of the greatest directors alive. The fraud produced losses. The retelling produced revenue. Both of those things are true about the same set of events.
The party was the movie. And the movie was not the crime.
Film is not record. Memoir is self-serving. Court documents are the authority. Figures: $200M investor loss vs $110.4M restitution — different things, both labelled. Living person — accurate sourced language throughout.
VERIFY BEFORE PUBLICATION Tommy Chong cellmate detail (widely reported, secondary sources only) · Current restitution repayment total · Exact restitution schedule post-2009 · Film gross figure verification
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
HOW THE PATIENTS WERE FOUND
CASE TIMELINE
HOW IT WORKED
HOW THE KICKBACK ENGINE WORKED — DEFENSIVE LEVEL
WHAT THIS CASE ESTABLISHED
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE KICKBACK ENGINE (700 WORDS)
The test was real. The need for it was not.
Minal Patel, owner of a genetic testing laboratory called LabSolutions LLC in Atlanta, Georgia, built a business model around manufactured demand. The genetic tests his laboratory performed were legitimate medical procedures. The question they were intended to answer — does this patient have a genetic predisposition to a condition, and does this affect their medication options — is a real clinical question. But the patients who received those tests under Patel's scheme, per the DOJ, were not patients whose doctors had determined they needed genetic testing. They were people whose details had been obtained by marketers who were paid for every test they brought in.
The kickback structure: Patel's laboratory paid marketers a fee per test — not a per-referral fee that a physician might receive, but a per-unit payment to salespeople whose job was to generate test orders from elderly and vulnerable people, often by using their Medicare or insurance information without the patients' full understanding. Some patients did not know a test had been ordered in their name. Some were told they were receiving a service they had not requested. [SOURCE: DOJ]
~$463 million was billed to Medicare and private insurers. ~$187 million was paid. The difference is the portion that was refused, reversed, or detected. Patel was convicted by a jury in December 2022 and sentenced in August 2023 to 27 years in federal prison — one of the longest sentences in the history of healthcare fraud prosecutions. He personally received more than $21 million. [SOURCE: DOJ, August 2023]
The conventional healthcare fraud case involves a false claim — a service that was not provided, billed as if it were. Patel's case is the complement: a service that was provided, but should not have been, because the patient had no genuine need for it and the need was invented by a payment structure.
Genetic testing is expensive and covered by Medicare when medically indicated — when a physician, based on clinical judgment, determines that the test result would affect the patient's treatment. The kickback network Patel operated bypassed that clinical judgment entirely. Marketers recruited elderly patients — mostly through telemarketing calls that falsely said Medicare covered the tests, with telemedicine doctors signing the orders, and senior communities — and generated test orders associated with their identities, sometimes without the patients' knowledge or meaningful consent.
This is manufactured demand: the creation of apparent need through financial incentives paid to people whose interest is the kickback, not the patient's clinical outcome. The test results, once generated, provided cover for the billing claim. The patient exists; the test was performed; the claim is technically defensible. The fraud is in the kickback that generated the order in the first place.
The victims include people who were tested without genuine need and whose insurance details were used without full consent. They were targeted because they were elderly and because Medicare coverage made the billing easy. [SOURCE: DOJ]
Three healthcare cases in this series; Patel is the second. Perez (043) used a billing licence to fabricate claims. Patel used a kickback network to manufacture demand. Esformes (045) used kickbacks to purchase patient referrals into a nursing-home network.
The 27-year sentence distinguishes Patel's case from the others in the healthcare category. It reflects the specific harm documented — the targeting of vulnerable patients, the sustained operation of the kickback network, and the scale of the billing. It is one of the longest sentences in US healthcare fraud history as of its imposition in 2023. State it factually; do not editorialize about proportionality.
SOURCES
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
KNOWN NETWORK & THE POLITICS
GONZALEZ (CASE 011) VS SELEZNEV (CASE 029)
CASE TIMELINE
HOW IT WORKED
HOW THE CARD BUSINESS WORKED — DEFENSIVE LEVEL
WHAT THIS CASE ESTABLISHED
THE FULL STORY — 4 PARTS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE SENATOR’S SON (1,700 WORDS)
In July 2014, Roman Valerevich Seleznev was arrested in the Maldives. US authorities apprehended him at Malé International Airport and transferred him to Guam, then to the United States. He was subsequently tried in the Western District of Washington — Seattle — on charges relating to one of the largest carding operations the DOJ had prosecuted.
His father, Valery Seleznev, is a member of the Russian State Duma. When news of the arrest reached Moscow, Valery Seleznev publicly characterised it as a 'kidnapping.' The statement was made from the floor of the Duma. It was reported internationally. [SOURCE: BBC; Reuters]
The US position: the arrest was a lawful apprehension of a fugitive. The Maldivian authorities cooperated. The legal process then ran in US federal courts. [SOURCE: DOJ]
In August 2016, after a trial in Seattle, Roman Seleznev was convicted on 38 counts. In April 2017 he was sentenced to 27 years in federal prison — the longest sentence for a hacking crime in US history at the time of sentencing. [SOURCE: DOJ sentencing press release, April 2017] Later in 2017 he pleaded guilty in separate cases in Nevada and Georgia.
He spent a decade in US custody. On August 1, 2024, he was freed in the US–Russia prisoner exchange and flown home. His father sits in the Russian parliament. The piece is the space between the courtroom and the exchange.
He sold card numbers from a server in Russia. America asked the Maldives to arrest him, and the Maldives said yes. His father called it a kidnapping from the floor of the Duma. In 2024 the politics brought him home: he was traded back to Russia in a prisoner exchange. The keyboards stopped. The politics never did.
The carding economy runs on two things: stolen card data and the infrastructure to sell it. Seleznev supplied both.
He operated under the handle 'Track2' — a reference to the magnetic stripe data on the back of a credit card, which contains the information needed to clone the card or process transactions. The handle is a precise technical description of what he was selling. [SOURCE: DOJ; Krebs on Security]
His operation, per the DOJ indictment and trial record, involved obtaining stolen credit card numbers through point-of-sale malware — software that, when installed on retail payment terminals, harvested card data as customers swiped their cards. The data was then sold in bulk through carding forums: underground marketplaces where stolen card data is priced by type, country, freshness, and associated cardholder information.
The scale: approximately 2.9 million credit card numbers obtained and sold. The attributed fraud losses: approximately $170 million — the losses suffered by card holders and financial institutions as a result of the fraudulent transactions that followed the data theft. [SOURCE: DOJ — verify exact figures to primary charging documents]
The distinction matters: the card count and the fraud loss are different measurements of a different quantity. The card count is how many records were in the database. The loss figure is the dollar harm that resulted from those records being used. They are connected but not interchangeable.
His operation targeted point-of-sale systems at restaurants and small businesses across the United States. The victims were ordinary consumers whose card data moved from their local restaurant's payment terminal to a server controlled by Seleznev, and then to buyers on carding forums who used the data to make fraudulent purchases. The harm was distributed across thousands of individual victims and the financial institutions that bore the chargeback costs.
() and Case 029 (Seleznev) complete the card fraud section of this series. The brief frames them accurately: the insider and the outsider, the American and the Russian, the informant and the exile-turned-prisoner.
GONZALEZ () vs SELEZNEV (Case 029)
Background
Gonzalez: US citizen, Miami, became Secret Service informant while hacking. Seleznev: Russian national, operated from Russia.
Method
Gonzalez: SQL injection attacks on major US retailers (TJX, Heartland). Seleznev: point-of-sale malware + carding forum sales.
Scale
Gonzalez: 170M+ card numbers. Seleznev: 2.9M card numbers, $170M fraud losses.
Sentence
Gonzalez: 20 years (longest hacking sentence at the time). Seleznev: 27 years (then overtook it as the longest).
Political dimension
Gonzalez: none — US citizen, tried domestically. Seleznev: his arrest became a US-Russia diplomatic incident; his father is a Duma member.
The comparison is not to suggest equivalence of conduct — the cases are different in mechanism, scale, and context. It is to make the series argument: card fraud operates at industrial scale, perpetrated by distinct actors with distinct methods, and the US sentencing response has escalated in kind. Gonzalez's 20 years was, in 2010, the longest hacking sentence in US history. Seleznev's 27 years, in 2016, set a new record. The numbers move in one direction.
The Maldives is an island nation in the Indian Ocean with which Russia does not have an extradition treaty. It is a place where a Russian national might reasonably feel less exposed to US law enforcement than in a country where cooperation was more established.
In July 2014, Seleznev was at Malé International Airport in the Maldives when US authorities, working with Maldivian officials, apprehended him. He was transferred to Guam — US territory — and from there to the continental United States to face charges. [SOURCE: DOJ; Reuters]
The Russian government's response was immediate and sharp. Valery Seleznev, his father and a member of the State Duma, characterised the arrest as a 'kidnapping' — an illegal seizure of a Russian citizen on foreign soil, orchestrated by the US government. The Russian Foreign Ministry made similar objections through official channels. [SOURCE: BBC; Reuters]
The US did not acknowledge the characterisation. The DOJ described the arrest as a lawful apprehension facilitated by cooperation with Maldivian authorities. The legal proceedings ran in US federal courts. Both positions — the DOJ's account and Valery Seleznev's account — are part of the record. This piece states both, attributed. The legal determination was made by the US courts: he was convicted.
The political dimension of the arrest is context for how the case was received, not the subject of the case. The subject is 2.9 million card numbers and $170 million in fraud losses and 27 years in federal prison.
The trial in Seattle took place in the Western District of Washington. In August 2016, after a jury trial, Roman Seleznev was convicted on 38 counts — wire fraud, intentional damage to a protected computer, and related charges. [SOURCE: DOJ press release, 2016]
In April 2017 he was sentenced to 27 years in federal prison. At the time of sentencing, it was the longest sentence ever imposed in the United States for a hacking crime. The DOJ described the sentence as appropriate given the scale of the operation and the harm caused to victims. [SOURCE: DOJ sentencing press release, April 2017]
In 2017 he also pleaded guilty in separate cases in Nevada and Georgia, related to different victims and a parallel conspiracy; the resulting sentence was reported as 14 years, running concurrently. [SOURCE: DOJ — verify counts and how the Nevada sentence interacted with the Seattle sentence in terms of total time]
He served about ten years in US custody. On August 1, 2024, he was released in the US–Russia prisoner exchange in Ankara and returned to Russia. [SOURCE: CNN; Krebs on Security, August 2024]
His father, Valery Seleznev, has continued in his role in the Russian Duma. He has spoken publicly about his son's case. His son was released in the August 2024 prisoner exchange, not through the courts. The 27-year sentence was the court's answer; the exchange was the politics'. Both are part of the record.
He sold card numbers from a laptop in Russia. America asked the Maldives to arrest him, and the Maldives said yes. He got twenty-seven years — the longest hacking sentence the country had ever handed down. His father called it a kidnapping from the floor of the Duma. In 2024 the politics brought him home: he was traded back to Russia in a prisoner exchange. The keyboards stopped. The politics never did.
SOURCES
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
THE PEOPLE AROUND IT
CASE TIMELINE
HOW IT WORKED
HOW THE MONEY LEFT TYCO — DEFENSIVE LEVEL
WHAT THIS CASE ESTABLISHED
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — HE WROTE THE APPROVAL (800 WORDS)
The fraud was not exotic. A public company paid for a CEO's apartment, his wife's birthday party in Sardinia, and a shower curtain that cost $6,000. The company's board approved these payments — or appeared to, because the documentation said so. The documentation was false because Kozlowski had written it.
L. Dennis Kozlowski joined Tyco International in 1975 and rose to CEO. By the late 1990s he had built Tyco into one of the largest conglomerates in the world — diversified manufacturing, fire protection, electronics. The company was real. Its earnings were substantial. The fraud was not in the earnings; it was in what the CEO took out of the company for himself.
The prosecution established two categories of conduct. First: unauthorized compensation — bonuses, loans that were never repaid, and expense reimbursements that the board had not approved and that were structured to look as if it had. Second: falsified records — documentation created or altered to make unauthorized payments appear to have proper board authorization. The first category is self-dealing; the second is fraud.
The first trial, in 2004, ended in a mistrial after a juror received a letter about the case. The retrial produced a conviction on June 17, 2005. Kozlowski and CFO Mark Swartz were each sentenced to 8 years 4 months to 25 years on September 19, 2005, in New York State Supreme Court in Manhattan; Kozlowski was also fined $70 million. The case was brought by the Manhattan District Attorney under state law — grand larceny, securities fraud and falsifying business records. Kozlowski was paroled in January 2014 after serving approximately 8.5 years. [SOURCE: DOJ; CNBC; Wikipedia]
The famous details of this case — the $6,000 shower curtain, the $2 million birthday party for his wife staged in Sardinia and billed in part to Tyco, the Fifth Avenue apartment — were presented at trial as evidence, not as tabloid colour. They served a purpose: to demonstrate the scale of the self-dealing and to show the jury what the unauthorized payments were for.
The shower curtain was part of an apartment that Tyco paid for in New York City. The birthday party — a week-long event in Sardinia for Karen Kozlowski's 40th birthday, attended by business contacts alongside family and friends — was billed partially as a corporate function. Both are in the trial record because both were presented as examples of the kind of expenditure that was being run through the company under falsified authorizations.
The point the prosecution made: these expenditures are what the money was for. Not sophisticated financial manipulation — actual spending, on real things, that a CEO decided a public company owed him without his shareholders or his board having approved it.
The mechanism by which Kozlowski concealed the unauthorized compensation was the falsification of internal records — specifically, the creation of documentation purporting to show board approval for loans and compensation that the board had not approved.
This is the same governance theme the series returns to in Leeson (022), in Kerviel (030), and in the machine-gate framework: a control can be forged. If the person committing the fraud is also the person generating the authorization, the control does not check the conduct. It certifies it.
The board's independent oversight function — the audit committee, the compensation committee, the governance structure that was supposed to prevent exactly this — was bypassed not by breaking it, but by producing false documentation that it appeared to have operated normally. The records said the board approved it. The board had not approved it.
Sarbanes-Oxley (produced by the Ebbers/WorldCom case in 2002) was already law by the time Kozlowski was convicted in 2005. Its personal-certification requirements — CEOs and CFOs signing off on financial statements under criminal penalty — are a response to precisely the conduct Kozlowski engaged in.
SOURCES
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
THE VICTIMS & WHAT CAME BACK
CASE TIMELINE
HOW THE FRAUD WORKED
FAKE-VENDOR INVOICE FRAUD — FIVE STEPS
IN THEIR WORDS
WHAT THIS CASE ESTABLISHED
THE FULL STORY — 4 PARTS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE INVOICE (1,600 WORDS)
$49.7M = forfeiture ordered at plea — NOT the same as the loss.
$26M+ = restitution ordered at sentencing — a third, separate figure.
Google fully recovered its money. Facebook recovered most of its money.
Convicted: guilty plea March 2019. Sentenced: 5 years federal prison, December 2019.
Between 2013 and 2015, a Lithuanian national named Evaldas Rimasauskas sent emails to employees of Google and Facebook.
The emails looked like they came from Quanta Computer — a Taiwanese hardware manufacturer that both companies legitimately did business with, routinely, for tens of millions of dollars. The emails asked Google and Facebook to wire money to bank accounts for hardware the companies believed they had received. The purchase orders looked correct. The invoices looked correct. The corporate letterhead, the stamps, the signatures — all of it looked correct.
Google wired approximately $23 million. Facebook wired approximately $99 million. [SOURCE: SecurityWeek / Sophos citing sentencing record] The total: more than $122 million sent to accounts he controlled, then moved through banks in Latvia, Cyprus, Slovakia, Lithuania, Hungary, and Hong Kong.
He did not hack Google. He did not breach Facebook's systems. He did not plant malware or exploit a zero-day. He sent emails and invoices. The payment processes trusted the paperwork and paid.
He was approximately 50 years old when he pleaded guilty in March 2019 before US District Judge George Daniels in the Southern District of New York. He was sentenced to five years in federal prison in December 2019, ordered to forfeit $49.7 million, and ordered to pay over $26 million in restitution. [SOURCE: SecurityWeek; DOJ sentencing]
The two companies that built the modern internet — whose entire business is organising and verifying information — were defrauded for two years by invoices that were not real. You cannot patch a process that trusts a PDF.
Quanta Computer is a Taiwanese electronics manufacturer. It builds servers, laptops, and hardware for some of the largest technology companies in the world. Google and Facebook were legitimate, ongoing Quanta customers — the kind of relationship that produces routine multimillion-dollar transactions on established invoice schedules.
Rimasauskas registered a company in Latvia with the name Quanta Computer. [SOURCE: DOJ; Reuters] He created email addresses that appeared to come from the same company. He generated invoices, purchase orders, contracts, corporate stamps, and letters — a complete documentation package designed to match what Google and Facebook expected to receive from their real hardware supplier.
He and his co-conspirators then sent those emails and invoices to employees at both companies, requesting payment for hardware those employees believed they had received. The accounts payable processes at both companies processed the payments.
The money went to bank accounts in Cyprus and Latvia, then moved to additional accounts across multiple jurisdictions. [SOURCE: DOJ plea agreement; SecurityWeek] The scheme ran from 2013 to 2015 — two years, more than $122 million in fraudulent wire transfers, before it was detected.
Lithuanian authorities arrested him in March 2017. He was extradited to the United States in August 2017. [SOURCE: SecurityWeek; Bloomberg citing extradition date]
VICTIM
AMOUNT / OUTCOME
~$99 million wired to accounts controlled by Rimasauskas · Facebook: recovered bulk of the funds [Facebook statement]
~$23 million wired · fully recovered: 'We detected this fraud against our vendor management team and promptly alerted the authorities. We recouped the funds.' [Google statement]
Total
More than $122M transferred [Sophos/DOJ sentencing] · DOJ charged 'more than $100 million' in the indictment
The reason Case 017 exists in this series is not the dollar amount. It is who the victims are.
() defrauded a law firm, a Qatari businessman, wealthy individuals. The mechanism was identical: business email compromise, fake payment instructions, misdirected wires. The dollar amounts were significant.
Rimasauskas defrauded Google and Facebook.
Google is Alphabet — one of the most valuable technology companies in history, whose core product is the organisation and verification of information. Its security apparatus is among the most sophisticated and expensive in the world.
Facebook — now Meta — built the social graph of the internet. It operates at a technical depth that places it in a category with perhaps a dozen other organisations on earth.
Both companies paid fake invoices. Not because their security systems failed technically — those systems were never the attack surface. Because their accounts payable process trusted a PDF with the right name on it.
The FBI's annual IC3 reports rank BEC among the costliest categories of cybercrime loss year after year. This case is one of the most expensive documented proofs of why: the attack surface is human verification, not software. The best security engineers in the world were in the next building. The payment process that processed the fake invoices did not ask them.
One of the most expensive BEC cases on record targeted two of the most sophisticated technology companies on earth. The fraud was a paperwork attack. No malware. No breach. Just invoices that looked correct — and a process that trusted them.
On March 20, 2019, Evaldas Rimasauskas pleaded guilty to one count of wire fraud before US District Judge George Daniels in Manhattan. He agreed to forfeit $49.7 million.
US Attorney Geoffrey Berman at the time of the plea: 'As Evaldas Rimasauskas admitted today, he devised a blatant scheme to fleece US companies out of $100 million, and then siphoned those funds to bank accounts around the globe. Rimasauskas thought he could hide behind a computer screen halfway across the world while he conducted his fraudulent scheme, but as he has learned, the arms of American justice are long.' [SOURCE: DOJ press release, March 2019]
At sentencing in December 2019, Judge Daniels sentenced him to five years in federal prison plus two years of supervised release, and ordered him to pay over $26 million in restitution in addition to the $49.7 million forfeiture. [SOURCE: SecurityWeek; DOJ]
The sentence contrast is part of the record. Five years for $122 million in losses that were largely recovered from corporate balance sheets. Madoff received 150 years for a fraud more than a hundred times larger, in which the victims were pensioners and charities with no means of recovery. The difference — victim identity, restitution potential, and cooperation — is how federal sentencing works. It is stated here as observation, not as a claim about proportionality.
He faces almost certain deportation following his sentence. He was convicted and sentenced. The record is closed.
Every BEC case in this series — and the FBI's annual IC3 report — makes the same argument: the vulnerability is the human, not the machine. The phishing email works not because it defeats technical controls but because the person receiving it believes it came from somewhere legitimate.
Rimasauskas took that principle to its logical conclusion. He did not target individuals. He targeted a corporate payment process. He registered a company with the same name as a real vendor. He created documents that matched what the accounts payable department expected. He sent them. The process ran.
Google and Facebook subsequently improved their vendor verification processes. Both companies acknowledged the fraud after Reuters obtained Lithuanian court records in 2017 that identified them. Google confirmed full recovery. Facebook confirmed partial recovery. The money moved quickly enough through multiple jurisdictions that recovery was not complete.
The series thesis for Case 017: the invoice. He did not build a persona like . He did not build a brand like Ignatova. He did not build a company like Petters. He built a piece of paper with the right name on it, and the process that was supposed to verify it did not.
It is one of the most expensive business-email-compromise cases on record. The victim companies build software to detect fraud. The fraud was two years of invoices that looked correct. You cannot patch a process that trusts a PDF.
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
THE DARKNET TRILOGY
CASE TIMELINE
HOW IT WORKED
HOW INCOGNITO WORKED — DEFENSIVE LEVEL
WHAT THIS CASE ESTABLISHED
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE SEVERANCE PACKAGE (800 WORDS)
Incognito Market was not an ideology. It was a business.
Rui-Siang Lin, 24 years old at the time of sentencing, a Taiwanese national, built Incognito Market and operated it from October 2020 to March 2024 under the alias 'Pharaoh' — from locations including St. Lucia, where he had concurrently established himself as a resource for local law enforcement on cybercrime and cryptocurrency. He provided training to Caribbean police on blockchain and cyber investigations while operating a major narcotics darknet marketplace. [SOURCE: DOJ press release; SecurityAffairs]
The platform: over 400,000 buyers, 1,800+ vendors, 640,000+ completed transactions. $105 million in narcotics sales — cocaine, methamphetamine, heroin, MDMA, counterfeit prescription drugs including fentanyl-laced pills sold as oxycodone. [SOURCE: DOJ February 4, 2026]
Vendors paid a 5 percent commission on each sale. Lin also operated an internal cryptocurrency 'bank' through which he collected payments and held escrowed funds. His total operating profit: approximately $6 million. The $105 million in sales is the platform volume, not his take. [SOURCE: Decrypt citing DOJ]
In January 2022, Lin explicitly allowed the sale of opiates on the platform. This led to counterfeit prescription drug listings. In September 2022, a 27-year-old man in Arkansas died after taking pills he had purchased on Incognito Market that contained fentanyl disguised as oxycodone. The DOJ described Lin as responsible for at least one death. [SOURCE: DOJ press release]
In March 2024, Lin abruptly shut down Incognito Market without warning. He stole at least $1 million in user deposits from the platform's internal escrow bank — funds that vendors and buyers had deposited with the expectation they would be returned or applied to transactions.
He then posted a message on the site. The message threatened to publish the transaction histories and cryptocurrency addresses of users unless they paid. It stated, in his own words: 'YES, THIS IS AN EXTORTION!!!' [SOURCE: Bitdefender citing DOJ; SecurityAffairs]
The users he was extorting were criminals — vendors who had sold narcotics on the platform and buyers who had purchased them. They could not file a police report about the theft of their escrow funds or the threat to expose their darknet market activity. They had no recourse. Lin's leverage was precisely their own criminality.
This is the moral inversion unique to this case in the series: every other case involves a fraudster and a victim outside the scheme. Incognito's victims, in the exit scam, were the scheme's own participants. The piece states this factually. It does not frame them as sympathetic; it does not excuse Lin.
Lin was arrested on May 18, 2024 when he flew into New York's JFK Airport en route from the Caribbean to Singapore. He was taken into custody by US authorities. [SOURCE: DOJ; Cyberinsider]
He pleaded guilty on December 16, 2024 before US District Judge Colleen McMahon in the Southern District of New York, to conspiracy to distribute narcotics, money laundering, and conspiring to sell adulterated and misbranded medication.
He was sentenced on February 4, 2026 to 30 years in federal prison. Judge McMahon described Incognito Market as 'a business that made [Lin] a drug kingpin' and called it 'the most serious drug crime I have ever been confronted with in 27.5 years.' [SOURCE: Bitdefender citing DOJ] He was also ordered to forfeit $105,045,109.67 — the platform's total sales volume. He received five years of supervised release to follow his prison term.
US Attorney Jay Clayton stated: 'Rui-Siang Lin was one of the world's most prolific drug traffickers, using the internet to sell more than $105 million of illegal drugs throughout this country and across the globe. While Lin made millions, his offenses had devastating consequences. He is responsible for at least one tragic death.' [SOURCE: DOJ press release February 4, 2026]
SOURCES
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
THE NETWORK
CASE TIMELINE
HOW IT WORKED
HOW THE PIPELINE WORKED — DEFENSIVE LEVEL
WHAT THIS CASE ESTABLISHED
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE PIPELINE (1,000 WORDS)
Pig-butchering is the English translation of sha zhu pan — a Chinese term for an investment fraud built on a romance. The victim is cultivated over weeks or months, introduced to a fake investment platform, encouraged to deposit increasing sums, and then the platform disappears and the money is gone.
The operations run these schemes from compounds in Southeast Asia — Myanmar, Cambodia, Laos — where workers generate the messages and maintain the fake relationships. The compounds are largely beyond US law enforcement reach. The operators may be effectively untouchable.
But the money cannot teleport. It exits a US victim's bank account in US dollars and needs to arrive at a compound in Cambodia as something usable. Between those two points, it passes through a banking system — and banking systems have US correspondents, US regulatory requirements, and US paper trails.
Daren Li's role, per the DOJ, was the passage. He held dual citizenship in China and St. Kitts and Nevis. He controlled US-registered shell companies and US bank accounts. At least $73.6 million in victim funds moved through his pipeline, $59.8 million of it through US shell companies. [SOURCE: DOJ, 9 February 2026] He was arrested at Atlanta airport in April 2024 and pleaded guilty in November 2024. In December 2025 he cut off his ankle monitor and fled. In February 2026 he was sentenced in absentia to 20 years. He is a fugitive.
This piece does not describe how pig-butchering fraud is operated. The series' Category 04 page explains the pattern at the required defensive level. What this case requires is the money-movement context.
The victims of pig-butchering fraud are people who were cultivated in a fake relationship, trusted the person on the other end of the phone, and were convinced to deposit money into what appeared to be a legitimate investment platform. Returns were fabricated. The platform was fake.
The losses are often catastrophic — life savings, retirement accounts, emergency funds. The fraud is designed to maximise extraction by building trust slowly, showing early fake profits, and encouraging reinvestment before the exit. The victims are not naive in any unusual sense. They are people who trusted someone they believed cared about them. This piece does not blame them. The series rule is clear: explain the machine, do not mock the people caught in it.
The UNODC estimates that pig-butchering operations in Southeast Asia generated tens of billions of dollars in the years spanning the pandemic period. The infrastructure is industrial — relationship workers, platform maintainers, and financial pipeline operators. That last piece is where the US has legal reach.
Per the DOJ, Daren Li directed and controlled US-registered shell companies and US bank accounts that existed primarily to receive and launder fraud proceeds. Victim funds — money stolen from Americans through romance-investment fraud — was wired to these accounts. [SOURCE: DOJ — verify charging document and figures before publication]
The money was then layered through additional accounts to obscure its origin and transmitted onward to Cambodia. The passage through the US banking system was a feature: it made the international transfer appear to originate from a legitimate US business.
At least $73.6 million moved through the pipeline. [SOURCE: DOJ] This is money taken from real people in fraudulent schemes. Li did not commit the romance fraud. He laundered its proceeds — moving money from where victims paid it to where operators could use it.
This case exists in US federal court because the pipeline is the soft spot. The scam operators in Cambodia may be beyond reach. The shell company addresses in the United States are not. The bank accounts are not. The laundering arm is where US law enforcement can act. Chokepoints get charged.
Daren Li was arrested on 12 April 2024 and charged in Los Angeles. On 12 November 2024 he pleaded guilty to money-laundering conspiracy — an admission before a federal judge that he conspired to launder fraud proceeds through US accounts. [SOURCE: DOJ — verify plea date and court venue]
He did not appear for sentencing.
The sequence matters: he was not a fugitive who was never caught. He came into a courtroom, admitted his conduct, and then failed to appear for the consequence. He fled after pleading guilty: in December 2025 he cut off his ankle monitor and disappeared. That detail is part of the record.
In February 2026 (the DOJ release is dated 9 February), a US federal judge in Los Angeles sentenced Daren Li in absentia to 20 years in federal prison. He holds dual citizenship in China and St. Kitts and Nevis — the St. Kitts citizenship, like 's (), provides travel options when avoiding a specific jurisdiction.
He is currently a fugitive. Whether the sentence is ever served depends on whether he is found and whether the country where he is found cooperates with extradition.
SOURCES
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
TWO PEOPLE — TWO CHARGES — TWO SENTENCES
RAZZLEKHAN — THE PUBLIC PERSONA
KNOWN NETWORK
WHAT INVESTIGATORS FOUND
IN THEIR WORDS
CASE TIMELINE
HOW IT WORKED
LAUNDERING STOLEN CRYPTO — AS THE DOJ DESCRIBED IT
WHAT THIS CASE ESTABLISHED
THE FULL STORY — 6 PARTS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE ALIBI (2,500 WORDS)
The music videos are the point.
Not because they are amusing, or strange, or because the internet found them funny in February 2022 when the DOJ unsealed its case. They are the point because a person who launders money needs a public identity that makes them look harmless — and nothing makes a person look more harmless than being a joke.
Heather Rhiannon Morgan, known online as Razzlekhan, had a rap persona. Self-described: 'the most dangerous woman in tech.' She wrote columns about cybersecurity, small business, and social engineering for Forbes and Inc. She performed at cryptocurrency events. Her music videos — produced, uploaded, and distributed under her own name — circulated widely in the crypto community.
The DOJ's case, as it emerged in February 2022, was about something underneath all of it. Her husband, Ilya 'Dutch' Lichtenstein, had hacked the Bitfinex cryptocurrency exchange in August 2016, stealing 119,754 Bitcoin worth approximately $71 million at the time. [SOURCE: DOJ] The coins sat largely dormant. Then, from 2016 to 2022, a laundering operation moved them through a layered architecture of fictitious identities, account hops, and asset conversions designed to break the chain back to Bitfinex.
She pleaded guilty to money laundering conspiracy on August 3, 2023. She was convicted. She was sentenced to 18 months in federal prison on November 18, 2024 in Washington D.C. She served her sentence at FCI Victorville, California.
The music videos were not the crime. They were the air. While the press treated Razzlekhan as a novelty — the eccentric rapper whose husband had stolen Bitcoin — the laundering was a different operation running underneath the same name.
built a brand to display the money. Razzlekhan built a persona to explain away the money. Both were performances. One bragged. One sang off-key. The off-key one nearly worked.
This part is Lichtenstein's. It is context for her case. It is not her charge.
In August 2016, Bitfinex — a major cryptocurrency exchange — was hacked. 119,754 Bitcoin were stolen from the exchange's multisignature wallet infrastructure. The attack, at the time valued at approximately $71 million, was one of the largest crypto hacks on record and sent Bitcoin's price down nearly 20% on the day the breach was announced. [SOURCE: DOJ; Bloomberg]
The stolen coins were held in wallets controlled by the hacker. For years, the coins moved in small amounts — exploratory transactions, washing through intermediary addresses — but the bulk of the hoard remained dormant. The blockchain preserved every movement, but the connection back to Bitfinex was obscured by layering.
In August 2023, Ilya Lichtenstein pleaded guilty and admitted he had carried out the hack. He was sentenced to five years in federal prison on November 14, 2024. [SOURCE: Bloomberg sentencing coverage]
This is where his story ends in this case file. The hack is context. The laundering is the case.
LICHTENSTEIN'S ROLE — FOR THE RECORD: He carried out the Bitfinex hack — his own admission in his guilty plea.
Sentence: 5 years · sentenced November 14, 2024, Washington D.C. federal court. [SOURCE: Bloomberg]
She was 'initially unaware' of how he obtained the BTC — prosecutors stated she became aware in early 2020 when he told her he was behind the hack. Her charged involvement began from that point.
His sentence, his hack, his figure: 5 years. Her sentence: 18 months. These are different people.
Money laundering conspiracy. That is the charge. That is what she admitted.
The DOJ's description of the laundering operation: the stolen funds were moved through a layered structure designed to sever the trail back to the Bitfinex hack. The mechanism included moving funds between accounts, converting Bitcoin to other assets, using fictitious identities and fake names, and withdrawing through chains of intermediary steps. [SOURCE: DOJ plea agreement / DOJ press release]
Prosecutors described Morgan as a 'lower-level participant' relative to Lichtenstein. She played a smaller role in the conspiracy, became involved after being told about the hack in early 2020, and the government noted she had spent only 'a small fraction' of what the pair had stolen. [SOURCE: DOJ sentencing filing, October 2024]
Her lawyers argued her involvement stemmed from loyalty to her husband rather than personal intent — that she became aware of the source of the funds and, rather than reporting it, chose to assist him. Prosecutors did not dispute the outline, but were clear: 'She made a conscious decision to engage in specific criminal activity, helping her husband launder millions in stolen funds for their personal gain. It was not a momentary lapse or impulsive decision.' [SOURCE: DOJ sentencing filing quoted in CoinMarketCap/Reuters coverage]
She cooperated with the government. The cooperation credit is documented in the sentencing recommendation — prosecutors cited her 'substantial assistance' as the basis for recommending 18 months rather than a longer term. [SOURCE: DOJ filing; CoinMarketCap coverage]
FIGURE
WHAT IT MEASURES — DATE LABELLED
119,754 BTC
Total stolen from Bitfinex, August 2016. Value at hack: ~$71 million. [SOURCE: DOJ / Bloomberg]
94,643 BTC
Amount seized by DOJ, February 8, 2022. These are the same coins — the remainder had been laundered or moved. [SOURCE: DOJ forfeiture filing]
~$3.6 billion
Value of 94,643 BTC at time of February 2022 seizure. NOT the value in 2016. Same coins, different date. [SOURCE: DOJ announcement]
~$71 million
Approximate value of 119,754 BTC at the time of the August 2016 hack. [SOURCE: Bloomberg / DOJ]
18 months
Morgan's sentence — her personal sentence only. Imposed November 18, 2024. FCI Victorville, California. [SOURCE: Bloomberg; Decrypt]
5 years
Lichtenstein's sentence — his. Imposed November 14, 2024. Different person, different number. [SOURCE: Bloomberg]
The brief for this piece opens with an instruction: do not write the comedy version.
The Razzlekhan persona is easy to mock. The music videos are objectively strange. The self-description — 'the most dangerous woman in tech,' 'Crocodile of Wall Street,' 'a surrealist rapper and economist' — reads as performance art. The internet treated her as a novelty when her arrest was announced. That reaction is the whole point.
Consider the operational logic. A person who assists in laundering billions in stolen cryptocurrency needs a public identity. The identity needs to explain the lifestyle — the appearances at conferences, the international travel, the proximity to crypto money — without triggering the question of where the money actually comes from. It needs to be conspicuous enough to register but strange enough that nobody takes it seriously as the cover story of a money laundering operation.
The eccentric rapper persona — in this framing — performed exactly that function. It put Heather Morgan in front of cameras at cryptocurrency events. It gave her a reason to be publicly connected to the crypto world. It created a character so bizarre that scrutiny slid off it. Nobody investigates the comedian. Nobody runs due diligence on the joke.
The brief states this clearly, and it is worth stating here: this is not a claim that the persona was consciously constructed as operational cover from the start. It is an observation about function. Whatever its origin, the Razzlekhan brand served as a layer of public identity that made questions feel unnecessary. In the world of money laundering, that function has a name.
Before her arrest, she wrote columns for Forbes and Inc. about protecting businesses from cybercriminals and about social engineering — 'your way into anything,' as one column put it. She wrote about how criminals exploit trust. She was, on her published record, an expert in how people get deceived.
Holmes wore a black turtleneck. Madoff chaired NASDAQ. Morgan rapped. Each disguise was calibrated to the environment it needed to work in. The most effective cover is the one that makes a reasonable person stop asking questions. Strange people do not launder money. Strange people are just strange.
On February 8, 2022, the United States Department of Justice announced the seizure of approximately 94,643 Bitcoin with a value of approximately $3.6 billion — the largest financial seizure in DOJ history at that point. [SOURCE: DOJ press release, February 8, 2022]
The same day, Heather Morgan and Ilya Lichtenstein were arrested in New York.
The seizure figure — 94,643 BTC — is not the full hack total. 119,754 BTC were stolen from Bitfinex in August 2016. The difference — approximately 25,111 BTC — had been laundered and dispersed through the operation. Investigators recovered the bulk, not all.
At the February 2022 seizure date, Bitcoin was trading at approximately $38,000. The seized 94,643 BTC was valued at approximately $3.6 billion. That is the seizure figure. That is the date it belongs to. The same coins were worth approximately $71 million in August 2016. The distance between those two numbers — $71 million to $3.6 billion — is six years of Bitcoin's price history, not the scale of the laundering operation itself.
The Decrypt coverage notes that by late 2025, the recovered Bitcoin had a value of more than $11 billion — same coins, later date, higher price. Every figure in this case must carry its date or the reader is misled.
August 3, 2023. Heather Morgan pleaded guilty to money laundering conspiracy and conspiracy to defraud the United States before a federal court. Ilya Lichtenstein pleaded guilty the same day.
More than a year passed between the guilty pleas and the sentencing. During that period, Morgan remained free on bail, subject to strict pretrial conditions. She attended some cryptocurrency conferences. She continued to create content as Razzlekhan — releasing a song about the emotional experience of impending incarceration, and maintaining an active presence on Cameo, where she billed herself as 'crypto's favorite felon.' [SOURCE: Decrypt]
Lichtenstein was sentenced on November 14, 2024: five years. Morgan was sentenced on November 18, 2024: 18 months. Both sentencings took place in Washington D.C. federal court. Judge Colleen Kollar-Kotelly sentenced both: 'You were true partners in this laundering scheme.' [SOURCE: Bloomberg; The Block]
At sentencing, Morgan addressed the court: 'I am extremely sorry and deeply regret the choices I made… I used my time and energy to do harm instead of good, and I'm ashamed of that.' [SOURCE: CoinDesk sentencing coverage]
She was designated to FCI Victorville in California. By November 2025, she was posting from custody — indicating she remained incarcerated roughly a year into her 18-month sentence. In late October 2025, she posted on X: 'I wanna give a shout-out to papa Trump for making my 18-month sentence shorter' — though her early release came from First Step Act credits, not clemency. [SOURCE: Decrypt; San Antonio news coverage] A White House official said the president 'had nothing to do with a commutation of her sentence.' Her time was cut through First Step Act credits and home confinement; her full release date was December 28, 2025. [SOURCE: CoinDesk, October 2025; Bitcoin.com, November 2025]
() built a brand around the money. The Rolls-Royces, the Gucci, the private jets, the 2.5 million Instagram followers watching the lifestyle in real time. He was the most visible BEC fraudster in the world because he chose to be visible. The brand attracted law enforcement. The Instagram account was evidence.
Razzlekhan built a brand that explained the money away. The persona was not an accident of personality — it was a functional layer. Strange people are eccentric. Eccentric people are not criminals. Eccentric people who rap about being dangerous in the crypto world are content creators, not launderers.
This is the inversion the brief identifies, and it is the right frame. Both and Morgan were performers. Both built public identities connected to the crypto world. The identities served opposite functions: one displayed the crime and got caught. One obscured the crime and nearly didn't.
The series thesis for Case 020 is not that she was a criminal mastermind. She was a lower-level participant, per the prosecutors who sentenced her. The theft was her husband's. The laundering was hers. The cooperation was significant. The sentence was 18 months.
The thesis is about the function of the persona. The most operationally significant thing Razzlekhan did was make herself impossible to take seriously. In money laundering, the best cover is the one that makes a reasonable person stop asking. The music videos worked, until they didn't.
She made music videos so strange that nobody looked at what she was actually doing. The performance was the alibi. The disguise worked so well that the world wrote her off as a joke — while the money moved. bragged and got caught. Razzlekhan sang off-key and nearly didn't.
SOURCES
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
THE NETWORK
CASE TIMELINE
HOW IT WORKED
HOW INSIDER TRADING WORKS — DEFENSIVE LEVEL
WHAT THIS CASE ESTABLISHED
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE PHONE CALL (700 WORDS)
Insider trading was one of Wall Street's worst-kept secrets. The pattern was visible: certain traders consistently bought ahead of earnings announcements, ahead of merger disclosures, ahead of FDA decisions. The timing was too consistent to be luck. The returns were too reliable to be skill. The inference was reasonable. The proof was not.
Raj Rajaratnam founded the Galleon Group in 1997. By the mid-2000s it was one of the largest hedge funds in the world, managing billions in assets. His returns were strong. His network was extensive. His phone was busy.
Between 2003 and 2009, Rajaratnam ran what the DOJ described as a network of insiders — corporate officers, board members, consultants, and others who passed him material non-public information about companies before that information was disclosed to the market. Galleon traded ahead of those disclosures. The fund made money. The network grew.
The FBI obtained wiretaps. The recordings captured him receiving tips directly — specific, clear calls in which specific people told him specific things that the market did not yet know. The suspicion became evidence. The evidence became 14 counts. The counts became 11 years. [SOURCE: DOJ/SDNY; FBI wiretap records]
The insider-trading network Rajaratnam built was not one tipster. It was multiple sources across multiple companies, providing information about earnings, M&A, and product decisions — a sustained information supply chain. Key figures in the network included Rajat Gupta, a former McKinsey managing director and Goldman Sachs board member, who was separately convicted in 2012 and sentenced to 2 years. [SOURCE: DOJ Gupta case]
The mechanism: an insider receives non-public information through their role — in a board meeting, in an earnings review, in an M&A process. They communicate that information to Rajaratnam before it is publicly disclosed. Galleon trades ahead of the disclosure. The position is closed after the public announcement moves the price. The profit is the difference between the insider's price and the market's price after disclosure.
The harm is not to Rajaratnam's own investors — Galleon's clients benefited from the returns. The harm is to every other participant in the market who traded without the same information. Market integrity depends on the assumption that prices reflect publicly available information. Insider trading corrupts that assumption without leaving a specific identifiable victim.
The DOJ attributed approximately $63.8 million in illegal profits and losses avoided to the scheme. The SEC's civil action produced a penalty of approximately $92.8 million — a separate civil figure in a separate forum. [SOURCE: DOJ criminal record; SEC civil action — verify exact SEC figure]
The trial lasted approximately two months. The jury convicted Rajaratnam on all 14 counts on May 11, 2011 — securities fraud and conspiracy. He was sentenced to 11 years on October 13, 2011 by Judge Richard Holwell in the Southern District of New York — at the time, the longest sentence ever imposed in the United States for insider trading. [SOURCE: DOJ/SDNY]
The Second Circuit upheld the conviction on June 24, 2013. On July 23, 2019 he was moved to home confinement under the First Step Act, which lets some inmates over 60 finish their sentences at home; he had served nearly eight years, mostly at FMC Devens. He was also ordered to forfeit $53.8 million and pay a $10 million fine.
The Galleon case opened a broader crackdown. US Attorney Preet Bharara's office used the wiretap precedent to investigate hedge fund information networks across the industry. Dozens of people were convicted in the broader sweep (some convictions were later overturned after a 2014 appeals ruling) — traders, analysts, corporate officers, consultants. [SOURCE: DOJ — verify exact count] The era of easy insider trading, if it had ever been easy, became definitively more dangerous.
SOURCES
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
THE PEOPLE AND THE LAWSUITS
CASE TIMELINE
HOW IT WORKED
HOW A SIM SWAP WORKS — DEFENSIVE LEVEL
WHAT THIS CASE ESTABLISHED
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE PHONE NUMBER (900 WORDS)
In January 2018, Michael Terpin's phone stopped working.
He was a prominent cryptocurrency investor. What was happening on the other end of his number: Nicholas Truglia and co-conspirators had convinced AT&T to transfer Terpin's phone number to a SIM card they controlled. SIM swap is a customer-service transaction — if you call your carrier and provide sufficient identifying information, the carrier will move your number to a new device.
Once Terpin's number was on their SIM, they reset passwords on accounts protected by two-factor authentication sent to that number. They intercepted the verification codes. They drained his cryptocurrency accounts. Approximately $23.8 million in crypto was stolen. [SOURCE: SDNY indictment; The Record]
The crypto was never hacked. The keys were never touched. The exchange's security worked as designed. The recovery channel — the phone number — was the attack.
Two-factor authentication works by sending a code to a device you own as a second check beyond your password. The assumption is that even if an attacker has your password, they do not have your physical phone. The second factor is the thing only you possess.
SIM swap breaks this assumption by going to the source: not your device, but the carrier that controls your number. If the attacker can convince the carrier that they are you, the carrier transfers the number. Your phone goes dead. Their phone now receives every code sent to your number.
The attack surface is not cryptographic. It is human and institutional. The carrier's verification process — the questions it asks, the training of its representatives — is the control that either holds or fails. When it fails, a phone number is a customer-service decision someone else made.
This is the mechanism the series' SIM-swap category has listed as an empty slot. Case 025 fills it: the documented case where this was used to steal $23.8 million from a sophisticated investor who had done nothing technically wrong.
Truglia's role, per SDNY prosecutors: he received the stolen cryptocurrency, converted it to Bitcoin, and distributed it to co-conspirators — keeping approximately $673,000 as his share. The total moved through his accounts: approximately $23.8 million. [SOURCE: SDNY; SecurityWeek]
The alleged mastermind was Ellis Pinsky — who was 15 years old at the time of the 2018 hack. In October 2022, Pinsky agreed to pay Terpin $22 million to settle his civil suit; the court approved it in November 2022. That settlement is with Pinsky, not AT&T.
Terpin also sued AT&T — the carrier whose verification process failed — for $224 million, including $200 million in punitive damages. In 2020 a federal court dismissed the fraud claims and the punitive-damages request; in 2024 an appeals court revived one claim, and the case went on. The brief for this case had these two civil outcomes confused. The correction is documented here and in the sources section.
Truglia's criminal case was in the Southern District of New York. He was sentenced in December 2022 to 18 months — with approximately 12 months already served — and ordered to pay $20,379,007 in restitution to Terpin. He was released shortly after sentencing. [SOURCE: The Record; SecurityWeek]
The restitution schedule required $12.1 million by December 31, 2022, and $8.28 million by January 30, 2023. Truglia paid neither — despite holding more than $50 million in assets.
In May 2023, he was detained in Miami for moving funds and purchasing luxury goods while owing unpaid restitution. Despite a contempt order, he was released in November 2024 — the judge determined he might repay from outside prison. He did not make any payments.
At the 2025 resentencing hearing, prosecutors presented a courtroom video of Truglia boasting about hiding stolen cryptocurrency. The judge found the non-payment wilful. Resentencing: 12 years in federal prison — more than double the federal guidelines recommendation. [SOURCE: Decrypt; Cointelegraph, July 2025]
The sentence grew not because the original crime became worse, but because the court's restitution obligation was treated with contempt.
SOURCES
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
THE TWO PEOPLE WHO BROKE HIM
THE SERIES ARGUMENT
HE NAMED THE THING THE THING IS STILL RUNNING
Charles Ponzi did not invent the Ponzi scheme. The structure — paying earlier investors with later investors’ money, maintaining a cover story about legitimate returns, collapsing when inflows can no longer fund redemptions — predates him. William W. Miller ran the “Franklin Syndicate” in Brooklyn in 1899, promising 520% annual returns. [SOURCE: Wikipedia / secondary — verify to primary before publication]
What Ponzi contributed was the version that stuck. He ran it in one summer in one city with one promise, and the Boston Post documented it in a way that gave the English language a permanent name for the pattern. Every fraud prosecutor in the world now uses the phrase he made necessary.
The template. The record-holder. The man the scheme is named after. The scheme that is named after him.
CASE TIMELINE
HOW THE FRAUD WORKED
THE SCHEME, STATED PRECISELY — FROM THE CASE BRIEF
WHAT THIS CASE ESTABLISHED
BIOGRAPHY — THE MAN BEFORE THE NAME
EARLY LIFE & IMMIGRATION
THE THREE PRISONS
THE SCHEME & THE NEWSPAPERS
THE SECURITIES EXCHANGE COMPANY
THE JOURNALISTS WHO ENDED IT
THE LEGACY — WHY THE NAME STUCK
THE FULL STORY — 9 PARTS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE NAME (3,800 WORDS)
Every fraud in this series has a name. . . Madoff. Holmes. Ignatova.
One of them gave a name to the crime itself.
Not the crime he invented — the crime that carries his name was running before he arrived, and was running after he left. What he contributed was not the mechanism. The mechanism is older and simpler than any one person. What he contributed was the version that stuck: the execution, the scale, the public spectacle, and the fall that was so complete and so documented that the newspapers found the words for it, the courts found the law for it, and the English language absorbed his name as the permanent label.
Carlo Pietro Giovanni Guglielmo Tebaldo Ponzi. Born March 3, 1882, in Lugo, a town in the Emilia-Romagna region of what was then the Kingdom of Italy. Died January 18, 1949, in Rio de Janeiro, Brazil, aged 66, in a charity ward.
Between those two facts: three countries, three prisons, one wife, one deportation, a promise of 50% in 45 days, and approximately $20 million in 1920 dollars — roughly $237 million in 2024 purchasing power — taken from somewhere between ten thousand and forty thousand investors who believed him. [SOURCE: case brief citing primary sources; exact victim count is contested in the historical record]
He did not invent the Ponzi scheme. He made it his name.
He arrived in Boston on November 15, 1903, aboard the S.S. Vancouver, sailing from Genoa. By his own account, he had $2.50 in his pocket. [SOURCE: Ponzi's autobiography, The Rise of Mr. Ponzi — use with care: self-serving. The $2.50 figure is widely repeated from his own telling.]
The Italian emigrant arriving in America with next to nothing and building something large is a specific narrative that Ponzi understood and deployed. He told the $2.50 story. He told it as an origin — the proof that he had started from the bottom, that the rise was self-made, that the money was the result of extraordinary individual capacity rather than inherited advantage. The story, whether strictly accurate or not, was part of the persona from the beginning.
He was well-educated by Italian provincial standards — he had attended the University of Rome for a time before family financial pressures ended his studies. He arrived in America speaking limited English, with facility in Italian and, eventually, several other languages. He was charming, social, and good at reading rooms. These were the tools he had.
His early years in America were characterised by a series of jobs — waiter, clerk, import-export agent — and a series of failures and marginal dealings that did not yet rise to the level of crime but established a pattern: he was drawn to schemes at the edges of the legitimate, to the gap between what was promised and what was delivered, to the specific opportunity created by the difference between what people believed and what was true.
In 1907, he moved to Montreal. There he became involved with a bank — Banco Zarossi — that was itself operating a fraud, paying interest on deposits from later depositors' money. He learned something from this, even if he did not design it. He was convicted of forgery in connection with these activities and served three years in a Canadian prison from 1908 to 1911. [SOURCE: case brief citing primary record]
He returned to the United States. He was later arrested in Atlanta in connection with smuggling Italian immigrants across the border and served time at the federal prison there, where he became a translator for the prison warden — a detail that speaks to both his linguistic ability and his social skill, two of the essential tools he would later use at scale.
In 1918, he married Rose Maria Gnecco, a Boston stenographer. He was 36 years old. He had a criminal record in two countries and, by most measures, no particular prospects. He was also, within two years, going to be the most famous man in Boston.
The mechanism Ponzi used was, in principle, real. International postal reply coupons existed. The price discrepancy he described was real — in some countries, particularly Italy, where the currency had weakened after the First World War, you could buy reply coupons cheaply in local currency and redeem them in the United States at a higher fixed face value. [SOURCE: Investopedia; widely documented from case record]
The arbitrage was legitimate in theory. Buy low in Italy. Redeem high in America. The spread is profit. Ponzi proposed to do this at scale, and to share the returns with investors: 50% profit in 45 days, or 100% profit in 90 days. Investors would give him money, he would run the arbitrage, and they would collect. The promise was almost irresistible.
The problem, identified quickly by investigators at the time and documented by Clarence Barron of the Boston News Bureau, was simple arithmetic. The volume of international postal reply coupons in actual existence across the world was nowhere near sufficient to generate the returns Ponzi was paying. If he had been genuinely doing the arbitrage at the scale his investor inflows required, he would have had to purchase essentially all the reply coupons in existence and then some. The mechanism was real. The mechanism at this scale was impossible. [SOURCE: Barron's investigation, documented in Boston Post exposé, August 2, 1920]
What he was actually doing: paying early investors with later investors' money. The returns were real, in the sense that people actually received them. But the returns were not generated by the arbitrage. They were funded by the deposits of the people who had invested after them. As long as new money was coming in faster than redemptions were going out, the scheme worked. When that balance reversed, it collapsed.
He knew this. The mechanism was the cover story, not the engine.
This must be stated directly because it is both true and important: Charles Ponzi did not invent the Ponzi scheme.
The structure he used — paying earlier investors with later investors' money, maintaining a cover story about legitimate returns, collapsing when inflows can no longer fund redemptions — was not his invention. It predates him. It had been used before him by multiple operators in multiple contexts.
The most directly relevant precedent is William W. Miller, a Brooklyn bookkeeper who in 1899 ran what newspapers called the 'Franklin Syndicate' — promising 520% annual returns and attracting approximately $1 million in deposits before the scheme collapsed. [SOURCE: case brief citing Wikipedia / WeTrust reference; flag: secondary sources — verify against primary before final publication] Miller became known in the press as '520% Miller.' He ran his scheme twenty years before Ponzi ran his.
Ponzi may have been inspired by Miller — the case brief flags this as 'may have been' rather than confirmed, and that is the correct framing. [SOURCE: case brief sourcing note] The connection is plausible given the timing and the press coverage Miller received, but the direct line of influence is not settled in the historical record.
Why does this matter to the series? Because the structure Ponzi made famous is the same structure that runs through every case in this collection. Madoff paid earlier investors with later investors' money. Ignatova sold coins that were numbers in a database funded by the deposits of people who came after the people being paid. Stanford paid CD returns from new investor capital. Holmes raised valuations built on investor money that was funding the lifestyle rather than the research. The mechanism is ancient. What changes is the wrapper.
Ponzi's name is on it not because he invented it but because he did it in one summer in one city with one promise, and the newspapers found it and documented it in a way that made it permanent. The Boston Post won its first Pulitzer Prize partly for this story. [SOURCE: case brief — verify Pulitzer attribution to primary before publication] The crime needed a name. He was there when the name was assigned.
In late 1919, Ponzi founded the Securities Exchange Company in Boston. He began accepting investor money on his promise of 50% returns in 45 days, backed by the international postal reply coupon arbitrage story.
He was good at this. The immigrants who had come to Boston as he had — Italian, Jewish, Irish, working class people who knew what it was to arrive with nothing and build toward something — were exactly the audience for a man who told a story of found opportunity. He did not pitch them as marks. He pitched them as insiders. He was letting them in on something that the wealthy already understood and that ordinary people could now access if they were smart enough to see it.
The money came in slowly at first, then faster. He paid his early investors — they received their returns on time, told their friends, and the friends came. By mid-1920 he was one of the most famous men in Boston, celebrated in the press as the financial wizard who had discovered a way to turn paper coupons into extraordinary profits, the immigrant who had cracked the system and was now sharing the discovery with his community.
On July 24, 1920, the Boston Post ran a favourable article about Ponzi. Investors poured in faster than ever. By some accounts he was taking in approximately $250,000 a day at the peak — the equivalent of several million dollars in contemporary terms. [SOURCE: case brief citing historical record; flag: this figure has not been independently verified to primary — treat as illustrative of scale, not as precise]
Two days later, on July 26, a bank run hit his office. Investors tried to withdraw simultaneously. He paid them. All of them. He stood in front of the crowd and paid everyone who came, and by the end of the day the bank run had dissolved into cheering. The man had held. The man had paid. The man must be legitimate.
He was not. He had paid the bank run from new investor deposits that had come in during the same days. He was paying old money with new money. The run had tested the scheme and the scheme had survived — but only because new inflows had happened to exceed the redemptions at exactly the right moment.
One week later, the structure was exposed.
On August 2, 1920, the Boston Post turned.
Clarence Barron of the Boston News Bureau had been investigating Ponzi's operation. The investigation was, in part, funded by the Post — which paid Ponzi's former publicity agent, William McMasters, $5,000 for his insider account of what he had seen. [SOURCE: case brief — flag: verify exact McMasters payment figure to primary before publication]
The story the Post published was based on Barron's arithmetic and McMasters's testimony. It was direct. Ponzi claimed approximately $7 million in liquid assets. The actual figure, investigators determined, was a deficit — he was at least $2 million in debt and possibly up to $4.5 million in the red. [SOURCE: case brief citing Boston Post exposé, August 2, 1920; Boston News Bureau]
The Massachusetts Attorney General, J. Weston Allen, moved immediately. The Hanover Trust bank, which had been processing Ponzi's transactions, was ordered to stop honoring his checks. State auditors descended. Involuntary bankruptcy was filed by a group of small investors.
On November 12, 1920, the federal bankruptcy court issued its ruling: In re Ponzi, 268 F. 997 (D. Mass.). [SOURCE: primary legal citation] The scheme was documented, the losses tabulated, the legal framework established.
On November 30, 1920, Charles Ponzi pleaded guilty to 22 counts of larceny in Suffolk County, Massachusetts. [SOURCE: ABA Journal; case brief citing Suffolk County record]
The Boston Post's investigation is one of the most consequential pieces of financial journalism in American history. The paper received the Pulitzer Prize. The story it broke gave the English language a new word for a specific category of crime. The story was better documented and more consequential than most financial journalism produced before or since — because the crime it exposed was so clean, so structurally legible, and so scalable that every subsequent fraud of the same kind would eventually be measured against it.
The criminal record of Charles Ponzi is long and runs across three countries.
Canadian prison, 1908–1911: three years for forgery, connected to his involvement with Banco Zarossi in Montreal. [SOURCE: case brief citing primary record]
US federal prison, 1920–1922: sentenced to five years for mail fraud in connection with the Securities Exchange Company scheme; served approximately three and a half years before being released to face state charges. [SOURCE: case brief]
Massachusetts state prison, 1927–1934: nine years for larceny. The state charges had been contested across several years of legal proceedings — during which he ran a land fraud scheme in Florida in 1925, for which he was separately prosecuted. He was, while fighting the Boston conviction on appeal, running another fraud. The Florida scheme collapsed when he was convicted in Massachusetts. [SOURCE: widely documented; Florida land scheme is part of the public record]
He was deported in 1934, after serving the state sentence. He went to Italy — then under Mussolini's government — and worked in various capacities including for the state airline. He eventually moved to Brazil. He taught English. He gave private lessons. He had, by his own later accounts, very little.
On January 18, 1949, Charles Ponzi died in a charity ward at the Hospital Umberto I in Rio de Janeiro. He was 66 years old. He had been partially paralyzed by a stroke. He had, by some accounts, approximately $75 in cash at the time of his death. [SOURCE: widely reported — verify to primary before publication]
His wife Rose had divorced him in 1937 after years of separation. She died in 1963, having rebuilt a life separate from his name.
Much of what people know about Charles Ponzi is repeated, not sourced.
The $2.50 figure comes from his own autobiography, The Rise of Mr. Ponzi, published in 1937. The book is self-serving and romanticising, and the specific details it contains should be treated as Ponzi's version of his own story rather than as verified historical record. He was, among other things, a man who understood the narrative value of an origin story. Whether he truly arrived with $2.50 or whether that number was chosen for its poetic quality is not definitively established.
The $250,000 per day figure — his peak intake — appears in historical accounts and is structurally plausible given the total documented losses and the time frame. It has not been independently verified to a primary financial document in the academic literature available at the time of this writing.
The William W. Miller connection — that Ponzi was inspired by or modelled on '520% Miller' — is plausible but not confirmed. The case brief correctly frames this as 'may have been.' It is included here because it is the most direct documented precedent and because the pattern similarity is exact: the promise, the mechanism-as-cover-story, the collapse. Whether Ponzi knew about Miller specifically or arrived at the same structure independently is a historical question that remains open.
What is not myth: the legal record. The federal bankruptcy ruling is a primary document. The guilty plea is a primary document. The Boston Post investigation was contemporaneous journalism that has been verified by subsequent historians. The charges, the convictions, the sentences — these are in the record.
Where this piece relies on secondary sources or contested figures, those are flagged. The appendix lists verification targets. Handle the myth carefully — the record is better than the legend.
Every case in this series descends from this one structure. Not from Charles Ponzi — from the structure he made famous.
: paid for his Instagram lifestyle with money from wire fraud. The lifestyle was the product. The money was a Ponzi, in the broad sense: the later victims funded what the earlier investment in his brand produced.
: 's operation was not a Ponzi in the classic sense — it was straightforward theft. But the spending spree that consumed $230 million in a month was funded in exactly the same way Ponzi's payments to early investors were funded: by taking real money and using it to demonstrate that the thing was working.
: 's algorithmic stablecoin was explicitly a Ponzi-adjacent structure. The yields paid through Anchor Protocol required continuous inflows to sustain. When the inflows stopped, the yields stopped. The mechanism that was supposed to be self-sustaining was funded by new capital.
: Madoff ran the cleanest Ponzi in this series — 48 years of fabricated statements, paying earlier investors from later investors' deposits. He is, of all the cases here, the direct descendant.
: 's FTX used customer deposits — new money — to cover Alameda's losses, which were in part the result of earlier speculative positions. The structure was a Ponzi on the assets of the exchange.
: Holmes's Theranos raised investor money to fund a lifestyle and a product development process that was not producing what investors were told. New money covered the gap between what existed and what was promised.
: Ignatova's OneCoin was Ponzi in structure and explicit in mechanism: new investor deposits paid earlier investors' 'returns' from a coin that had no underlying value.
Case 009 Stanford: certificates of deposit paying above-market returns, funded by later investor deposits rather than a legitimate investment portfolio.
Ponzi's scheme ran in Boston in 1920. He made it famous enough to name. Every case in this series is a version of the same thing, run with different wrappers, in different centuries, across different asset classes and geographies. The structure is the same. It survives while inflows exceed redemptions. It collapses when they don't.
He died in a charity ward in Rio de Janeiro on January 18, 1949. He was 66 years old. He was partially paralyzed. He had, by most accounts, next to nothing.
He had arrived in Boston in 1903 with $2.50 in his pocket — by his own telling. He died in Brazil with approximately $75. Between those two numbers: Montreal, Atlanta, Boston, Miami, Italy, Brazil. Three prisons. One wife. One divorce. One deportation. One summer in which he was the most famous man in Boston, and the rest of his life in which he was the man the summer was named after.
He had run his scheme for a little over a year. He had taken in approximately $20 million in 1920 dollars — roughly $237 million in 2024 purchasing power — from somewhere between ten thousand and forty thousand people who believed him. [SOURCE: case brief; exact victim count is contested] He had paid the early ones. He had not paid the rest.
He maintained, to the end, that the arbitrage had been real. That the scheme had worked in principle. That the problem was not the design but the execution, the publicity, the regulators who moved too fast. He was, among other things, a man who had told stories so long that some of them had become his own beliefs.
The English language absorbed his name. The legal system codified the structure. Every financial fraud prosecutor in the world now uses the phrase he made necessary. Every journalist covering the cases in this series reaches for it. Every investor who has ever been told that returns are generated by arbitrage or algorithm or technology has, somewhere in the back of their mind, the awareness that this has a name.
The name is his.
Myth distinguished from record throughout. Ponzi's autobiography is self-serving and used with care. Figures flagged for primary verification are labelled below. The Boston Post investigation is contemporaneous journalism verified by subsequent historians.
VERIFY BEFORE PUBLICATION McMasters exact payment (~$5,000) · Daily intake figure ($250,000/day at peak) · William W. Miller direct inspiration link · Pulitzer Prize attribution · Final assets at death (~$75)
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
KNOWN NETWORK & CO-CONSPIRATORS
DOCUMENTED SCHEMES
ASSETS SEIZED — DUBAI ARREST JUNE 2020
OPERATION FOX HUNT 2 — SEIZURE RECORD
CASE TIMELINE
HOW THE FRAUD WORKED
BEC METHODOLOGY -- FIVE STEPS
WHAT THIS CASE ESTABLISHED
THE FULL STORY — 17 CHAPTERS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE (5,700 WORDS)
On the eleventh of October, 2017, a man in Dubai posted a photo of a birthday cake on Instagram.
The cake was from Gucci. Iced in the house's signature green and red, the interlocking double-G logo rendered in fondant on the top tier. The caption: Happy Birthday Ramon.
Followers sent their birthday wishes. The FBI noticed something else.
Agents cross-referenced the name against a US visa application linked to a phone number connected to a co-conspirator in an active money laundering investigation. Date of birth: October 11, 1982. Name: Ramon Olorunwa Abbas. A public Instagram birthday post verified the identity of a man the bureau had been building a case around for months. The flex was the fingerprint.
This is that story. All seventeen chapters of it.
To understand what Ramon Abbas became, you have to understand the place that made him.
Bariga sits on the Lagos mainland — pressed between the lagoon and the grinding density of one of Africa's most chaotic and alive cities. Not the Lagos of Banana Island penthouses and gated Lekki estates. Bariga is the city that built those gates. Where the taxi drivers live. Where the market traders sleep. Where the generators run all night because the power grid is a suggestion rather than a service.
Ramon Olorunwa Abbas was born there on October 11, 1982. His father drove a taxi. His mother sold goods at the market. He would later repeat these facts himself — in interviews, in Instagram captions, in a handwritten letter to a federal judge — with the pride of a man who believed his origin story made everything that followed both understandable and, in some way, forgivable.
Lagos in the late 1980s and 1990s, when Abbas was coming of age, was a city of strangled potential. The oil revenue that should have built infrastructure and employment had been captured by successive governments. The young men of Bariga were educated enough to understand what the world offered. They were constrained enough to understand how little of it had their names on it.
The internet arrived through cafes in the late 1990s — small shops lined with terminals, paid by the hour, where you could reach anywhere on earth through a screen. For the young men of Bariga, this was not a convenience. It was a revelation. Through a screen, geography dissolved. The visa barriers and capital requirements that kept the world closed became, theoretically, irrelevant.
Before the fraud. Before Instagram. Before the Richard Mille and the Rolls and the Palazzo Versace — there was a car boot full of sneakers.
Abbas sourced premium branded clothing and shoes and sold them from the trunk of a car, moving through Lagos to wherever the buyers were. This requires genuine commercial intelligence: reading demand before it articulates itself, understanding the relationship between price and aspiration, knowing when a customer is considering and how to tip the scale. He expanded. The car boot became boutiques — physical retail locations where people moving up in Lagos could acquire the objects that announced arrival.
What the fashion business taught him — and this is the thing that would define everything that followed — is that people do not buy products. They buy the version of themselves they become when they own them.
Abbas understood this before he had ever seen a fashion week, before he had ever sat in a front row. He understood it the way some people understand mathematics — not as a learned skill but as intuition so natural it does not feel like understanding at all.
In 2011, Instagram launched. Abbas created an account. He called it Hushpuppi.
The name suggested quiet money — the dog that does not bark, the wealth that does not need to announce itself while announcing itself constantly. The irony was presumably intentional.
The early posts were modest. Fashion content. His own outfits assembled with real skill — the Lagos boutique owner applying genuine knowledge of what looks right, what signals correctly, what tells the right story. He was not yet posting borrowed luxury. He was posting what he had and presenting it well.
The account grew. The audience that found him were young Africans — in Nigeria, Ghana, Kenya, in the diaspora communities of London, Houston, Toronto — hungry for exactly what he was offering. Someone who looked like them, who came from where they came from, standing in rooms that were supposed to be closed to people like them.
He studied what worked. He refined constantly. The content became more expensive, more aspirational, more detailed in its documentation of a life at the absolute top. Every detail mattered — the angle of the watch, the way the bag sat against the car seat, the specific restaurant, the specific suite. He was not posting life. He was producing it.
In 2014, he left Nigeria. His destination: Kuala Lumpur, Malaysia.
The choice of Malaysia was strategic on multiple levels.
Kuala Lumpur in 2014 was modern, connected, and positioned as a hub between the financial systems of Southeast Asia, the Gulf, and the West. The international community was large enough that a Nigerian man living conspicuously well would not draw unusual scrutiny. The cost of luxury was lower than Dubai or London. And from KL, the banking networks that mattered for what the operation was becoming were accessible.
Abbas arrived and built. The Instagram accelerated dramatically. Daily posts, sometimes multiple per day, each one a production — composition, lighting, clothing, accessories arranged in the frame to tell a story of wealth so comprehensive it admitted no doubt. Malaysia was where the following broke past a million, then two million. Where the character became more real than the man.
And Malaysia was where, the court record shows, the criminal operation scaled from informal fraud into something organised, networked, and capable of moving tens of millions of dollars across continents.
Business Email Compromise requires infrastructure: knowledge of corporate payment processes, connections to money mule networks across multiple jurisdictions, the ability to coordinate across legal systems. Abbas had become the infrastructure. Not necessarily the man at the keyboard — what the FBI alleged, and what the record establishes, is that he operated as a coordinator. Providing accounts. Connecting operations. Moving money through the nodes of a transnational fraud network.
His Instagram was not separate from this business. It was part of it. The luxury displayed on his feed attracted two audiences simultaneously: the millions of followers who saw aspiration, and the operators in the fraud economy who saw proof of legitimacy. A man who lives that way has standing. He can be trusted with a large transaction.
He called himself the Gucci Master. It was not a casual title.
Abbas had studied the house — its heritage, its aesthetic codes, its position in the European luxury hierarchy. He wore Gucci the way a scholar wears citations: with authority, with reference, with the implication he understood something others did not. He wore the Disney x Gucci collaboration T-shirt — $650 — as casually as other men wore plain cotton. He stacked Gucci accessories, shoes, belts, bags. But he did not wear logos. He wore a language. The distinction matters: logos say I can afford this. Language says I belong here.
Gucci was the anchor. The portfolio diversified: Louis Vuitton, Fendi, Chanel, Dior, Balenciaga, Hermès. Each house has a specific cultural position in the luxury hierarchy and he positioned himself in relation to all of them simultaneously. He understood the grammar of these brands — which piece meant what, which collaboration carried weight, which bag signalled what level of spending to what kind of observer.
On his wrist: the Richard Mille RM11-03. Approximately $230,000. A watch so technically complex — its movement visible through the case back, its architecture borrowing from motorsport engineering — that it announced serious money even to people who did not know watches. The FBI's criminal affidavit noted specifically that this watch was purchased with money scammed from a Qatari businessman. On Instagram, it was just Tuesday.
The fashion weeks were the crowning content of the Hushpuppi brand. Paris most of all.
Paris Fashion Week is the apex of the global luxury calendar — the city and the season where Louis Vuitton, Dior, Givenchy, Chanel present the work that defines what the world aspires to. The shows happen in the Grand Palais, the Louvre, purpose-built architectural spaces that treat fashion as an event for the experience of something that exceeds the functional.
Abbas attended. He documented everything.
The Louis Vuitton shows were particular reference points. To be at LV in Paris was to be present at a cultural event with a guest list as curated as any in the world. The brands saw: ~2.5 million followers (BBC), product worn correctly, photographs beautifully composed. That was the currency of the front row. Abbas had it. The brands gave him the seat. He gave them the content.
The Paris posts were his most powerful. Hotel suites at the kind of addresses that charge per night what most Bariga households earn in a year. The private car to the venue. The front-row or near-front-row positioning. The photographs with other attendees who had their own visibility. The post-show dinner at the restaurant where the after-party and the real business happened simultaneously.
He captioned these posts with the authority of a man who belonged — not the excited fan, not the tourist who had somehow secured a seat, but the man for whom this was simply the routine of his life. The Gucci Master on his natural ground.
The private jet content is the most revealing window into how precisely the machine was calculated.
Private jets are the ultimate social media luxury signal. Not the car — too many people lease cars they cannot afford. Not the watch — high-quality fakes circulate convincingly on camera. But the interior of a private jet — the cream leather, the burled wood panels, the oval window view of clouds from a cabin that seats twelve — communicates a specific and very large quantity of money that is difficult to convincingly fake, and that an audience recognises as categorically different.
Abbas chartered jets. Private aviation companies in Dubai and Malaysia service a market of people who need aircraft for specific purposes without owning them. They are businesses; they take bookings. Abbas would charter, spend time aboard, and produce content systematically: boarding the aircraft, seated in the cabin, the window view at altitude, the food service on the fold-down table, the shoes off and feet on the cream leather footrest.
He posted these with the energy of a man for whom this was simply how travel worked. Not look at this extraordinary thing I have done — but here I am, on my way, as one does.
The calculation was precise. Per dollar spent on charter, private jet content generated higher returns in follower growth and brand consolidation than any other category. He was not taking these flights to get somewhere. He was taking them to be seen taking them. The destination was the content. The content was the credential.
When Abbas established himself in Dubai, both the persona and the operation were at their peak.
Dubai is a city built on the proposition that money from anywhere, earned by any means, can purchase any lifestyle if it arrives in sufficient quantity. The towers, hotels, malls, restaurants — designed to convert wealth into experience with maximum efficiency and minimum questioning.
He took an apartment at the Palazzo Versace Dubai. Not a hotel room. An apartment. A residence. Home.
The Palazzo Versace is a building that exists as a fashion statement made permanent — built in collaboration with the Versace house, the fabrics on the chairs matching runway patterns, the pool tiles printed with the Medusa head, the corridors designed to feel like walking through a collection. Everything in the building says this is not ordinary accommodation. This is a lifestyle sustained in architectural form.
Abbas lived there and documented all of it. The apartment interior. The views of the Dubai skyline and the Gulf beyond. The cars in the building's valet. The pool where the Medusa heads shimmered under the water. The lobby where staff knew him by name.
Every room. Every morning. Every evening. The Instagram grid became a catalogue of a life at a level most people had only seen in magazines — magazines always populated by Western celebrities, European heirs, people born into access. Here was a man from Bariga, from a taxi driver's household, in those rooms.
The law firm lost approximately $40 million.
One redirected wire. One fraudulent payment instruction that appeared to come from a trusted source, directing funds to accounts that emptied within hours. A single BEC operation producing tens of millions of dollars that moved through the banking system before anyone understood what had happened.
The foreign financial institution — Malta's Bank of Valletta, as Forbes's reporting linked the February 2019 operation — lost approximately $14.7 million. The FBI's affidavit traces Abbas to this specifically: he supplied two European bank accounts anticipating approximately $5.6 million each. The money moved through those accounts and onward through the US, UK, Czech Republic, and Hong Kong — a chain of jurisdictions designed to put maximum distance between crime and trace.
The English Premier League club was targeted for approximately £100 million. A player transfer fee — the specific mechanism whereby enormous sums move between football clubs through agents, solicitors, and banking instructions that travel by email. The amount was large enough to justify the operational risk. The attempt was intercepted.
800,000 emails of potential victims were found on Abbas's seized devices. Not his correspondence — the contact details and assessed vulnerabilities of people and organisations that had not yet been defrauded. Future targets, stored in categories on a hard drive next to the Gucci receipts.
This is where the story moves into territory that most Instagram influencers — even fraudulent ones — never approach.
US authorities alleged that Abbas was involved in laundering funds connected to North Korean state-sponsored hackers.
The — the cyberattack unit operating on behalf of the North Korean state, the organisation linked to the Sony Pictures hack, the Bangladesh Bank heist, the WannaCry ransomware attack, and the theft of hundreds of millions from cryptocurrency exchanges — needed to move money. Cryptocurrency stolen in sophisticated cyberattacks does not spend itself. It needs to be converted, cleaned, moved through a system that will accept it at the end without asking where it originated.
According to US Department of Justice allegations, Abbas was connected to a scheme involving laundering proceeds of North Korean cyber theft. A network built on Business Email Compromise was now allegedly operating as infrastructure for the financial operations of a sanctioned state's hacking program.
What the allegation suggests, if accurate: the man with the Richard Mille and the Gucci birthday cake was a node in a network that connected Lagos street-level fraud infrastructure to the cyber operations of the North Korean state. The front row at Louis Vuitton and the hacking for Pyongyang — connected through the same man's accounts.
If the North Korea connection is the most extraordinary dimension of the story, the Abba Kyari connection is the most revealing about what money and social access can construct.
Abba Kyari was not a minor figure. He was the Deputy Commissioner of Police, head of Nigeria's Intelligence Response Team, decorated for operations against kidnappers and armed groups, personally commended by the President. His arrest operations were covered by Nigerian newspapers as national news. He was, by public reputation, one of the most effective law enforcement commanders in the country.
He was also, according to the US Department of Justice, a friend of Ramon Abbas.
The DOJ charged Kyari in 2022 with conspiracy to commit wire fraud and money laundering in connection with a BEC scheme. Federal prosecutors alleged that Kyari had received bribes from Abbas in exchange for arresting individuals Abbas wanted targeted — using his position in Nigerian law enforcement to have people who were threatening or inconveniencing Abbas's operation detained.
On social media, Abbas had publicly celebrated Kyari. He had posted photographs with the police commander. He had spoken of him warmly. The decorated officer and the Instagram influencer, photographed together, both presenting as successful men at the top of their respective worlds.
The allegation, if proved, describes a specific and extraordinary arrangement: a senior police commander on the payroll of one of the most wanted money launderers in the world, using the power of Nigerian law enforcement as a private security service for a criminal enterprise. The case is unresolved. Kyari denied all charges.
Abbas did not operate alone. The court record names others.
Ridwan Abdulaziz Aliyu — known as Lade — was charged as a co-conspirator. Identified in the record as a participant in the network through which the fraud operated, involved in the management and movement of proceeds.
Kelly Chibuzor Vincent and Boye Emmanuel Oluwaseun were named in connection with the scheme to defraud the English Premier League club — the attempted £100 million transfer fee fraud. The record documents their roles in the attempted interception and redirection of the football club's payment.
Abdulrahman Juma appeared in the record in connection with the network's Gulf operations.
And there was a co-conspirator — unnamed in some filings — whose October 2019 arrest in an unrelated case was the moment the thread became visible. Their devices were opened. Their communications were examined. The chain of connections led, eventually, to Palazzo Versace Dubai and the man living in the apartment there.
The network was large enough to be operational across continents. It was also large enough that when one node was compromised, the connections running through it became legible to investigators who knew what they were reading.
Among the details in the case record: Abbas held a passport from St Kitts and Nevis.
St Kitts and Nevis offers citizenship by investment — a legal program through which foreign nationals obtain citizenship in exchange for qualifying investments. It is a program used by many people legitimately seeking a second passport. It is also, for certain purposes, strategically valuable.
Abbas's St Kitts passport was not obtained legitimately. According to the record, it was obtained through a sham marriage — a fraudulent arrangement designed to create the appearance of qualifying for citizenship that did not reflect a genuine relationship.
A second passport from a Caribbean nation, held by a Nigerian man operating across Dubai and Malaysia: the practical utility in the context of what the record describes requires no further elaboration. It represents another layer of constructed identity — the same impulse that built the Hushpuppi Instagram brand, applied to documentation.
In 2017, Timaya released a track. Featuring Olamide and Phyno.
These are not small names. Olamide is one of the most commercially successful and culturally respected artists in Nigerian music history. Phyno built his reputation on credibility and craft. Timaya had sustained a career across multiple eras of the industry. When these three made a record together, people listened carefully.
Telli Person was directed at Abbas. The accusations came in music's coded language — barely veiled to anyone paying attention. You are not what you claim. This will end. The warning was explicit enough to be unmistakeable.
Abbas heard it. He responded as he always responded to threats to the brand — loudly, publicly, with the fury of a man whose image is his most valuable asset. He contested the narrative. He doubled down. He posted more. He bought more. He wore more. When you cannot answer the accusation, you outspend it.
The feud ran for years. Nigerian social media divided — between those who read the Timaya record as truth and those who read it as jealousy. Between those who understood how the Yahoo boy economy worked at its highest levels and those who had decided that the front rows and the Richard Mille were proof enough of legitimacy.
The song was streaming in 2022 when Abbas was led into a federal courtroom in Los Angeles. The prophecy had found its fulfilment — not in music but in law. The music industry had said: this man is not what he claims. The court said: he is a money launderer. The gap between those two statements was narrower than five years of Instagram posts had made it appear.
In October 2019, a co-conspirator was arrested in a separate case. Their devices were opened. Their communications were examined.
Somewhere in the chain of messages and transactions, the thread led to Ramon Abbas.
Federal cases build quietly. Not the dramatic raids of television but the slow accumulation of subpoenas, financial records from banks in multiple countries, international cooperation across legal systems that do not always speak the same language. The Dubai Police were engaged. Interpol involvement was secured. The operation was named Fox Hunt 2.
On a night in June 2020, the team arrived at the Palazzo Versace. They came with the full apparatus of an international law enforcement operation that had been building for months.
Abbas was home.
Dubai Police produced a video. They took his own Instagram content — the cars, the watches, the fashion week photographs, the jet interiors, the birthday cake — and edited it against footage of the raid. Police entering the apartment. Evidence being catalogued. Cybercrime graphics overlaid on images he had chosen to define his public identity. The aesthetic tools he had spent nine years developing were turned against him by a police media department that understood exactly what it was doing.
The video went viral. Of course it did. He had built one of the most viral Instagram accounts in African history. The system he created for his own mythology was repurposed for his destruction.
He arrived in the United States on July 3, 2020. The country he had defrauded was waiting.
The federal case in the Central District of California proceeded over two years.
Abbas pleaded guilty to conspiracy to engage in money laundering. The government's case was comprehensive: financial records, digital evidence from 47 smartphones and 21 laptops, blockchain analysis, international banking records, the communications with co-conspirators across multiple jurisdictions, and the Instagram account itself — which functioned not only as lifestyle evidence but as a chronological record of movements, associations, purchases, and the specific timeline of an operation.
His attorney argued for leniency. The origin story was presented — Bariga, the taxi driver father, the market trader mother. Character letters were submitted. And Abbas himself wrote to the judge.
A handwritten letter, dated September 9, 2022, addressed to Judge Otis D. Wright II.
In the letter, he described the beginning. The car trunk. The sneakers. The boutiques. The boy from Bariga who had wanted something the world had decided was not available to him, who had found a way — the wrong way — to reach for it. He expressed remorse. He described himself as a businessman who had made catastrophically wrong choices.
The man who sat in the front rows of Paris fashion weeks, who drove Rolls-Royces through Dubai, who posted ~2.5 million followers (BBC) through the rooms of a life built on wire fraud and money laundering — he will be in his mid-fifties before he walks free. He is also wanted in Nigeria.
The uncomfortable truth at the centre of the Hushpuppi story is not simply that a criminal became famous.
It is that the fame was real. The access was real. He genuinely sat in those front rows. He genuinely wore those watches. The Palazzo Versace apartment was genuinely his home. The jets were genuinely in the air.
He got there. From Bariga, from a taxi driver's household, from the car-boot sneaker business — he got to the rooms that were supposed to be permanently closed to people from where he came from.
The cost was paid by the law firm that lost $40 million. By the Maltese bank. By the English football club targeted for £100 million. By the victims whose 800,000 emails were found in storage on his devices, waiting to be next.
That is the arithmetic of the story. The glamour was purchased on credit taken from people who never agreed to extend it.
The reaction in Nigeria was complicated in the way these things are always complicated in Nigeria.
There was condemnation. There was the told-you-so from those who had always questioned the source. There was the religious establishment's long-standing critique of the Yahoo boy culture's corruption of a generation. There was Telli Person finally, definitively, proven right.
And there was something else. A grief that was not for the fraudster but for the proposition he had represented. The idea that someone from Bariga could actually be in those rooms. Could actually belong in those rooms. Could sit where princes sat and be treated as an equal.
His life had appeared to prove it was possible. The conviction proved the version that existed was built on stolen money. The rooms were real. The key was stolen.
Prof. Adedeji Oyenuga of Lagos State University spent six years embedded among Yahoo boys for his doctoral research. Prof. Daniel Smith of Brown University has written on the structural drivers: unemployment, thwarted opportunity, a generation educated enough to understand what it was missing and constrained enough to understand how little of it could be reached through legitimate paths.
Abbas was not the cause of this system. He was its most famous product. And his fall was the system demonstrating, with the full weight of US federal law, that the shortcut he took had a price that was coming no matter how long you managed to avoid it.
The birthday cake was from Gucci. It sat on a table in a room in Dubai, lit beautifully, the double-G logo in fondant. The caption: Happy Birthday Ramon.
Two million people saw the fire emojis pile up. The praise. The tags. The messages from young men who looked at that cake and saw everything they wanted their own lives to become.
And somewhere, an FBI agent looked at the same post, matched the name to a file, confirmed the date of birth, and added it to a case.
He told the world who he was. Post by post by post. For nine years. The watch and the car and the jet and the Paris front row and the Palazzo Versace apartment. The Louis Vuitton shows and the private charters and the Gucci birthday cake. He told them everything.
He just did not tell them where the money came from.
When the court told that part of the story, it took eleven years to tell it back.
Every claim in this piece traces to a named source below. Allegations are framed as allegations. Estimates labelled.
KEY FACTS
FULL PROFILE
IDENTITY
CASE RECORD
THE DOCUMENTED CRIMES
THE MOVIE & THE LEGEND
THE DEBUNKERS
THE RECORD VS HIS ACCOUNT
IN HIS WORDS
CASE TIMELINE
HOW IT WORKED
WHAT HE ACTUALLY DID — AND WHAT HE SAID
KNOWN NETWORK & CONNECTED CASES
WHAT THIS CASE ESTABLISHED
THE FULL STORY — 4 PARTS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE LEGEND (2,200 WORDS)
() sent a spoofed email and a wire moved. () sent a fake invoice and Google and Facebook paid $122 million. Neither of them broke into a building, cracked a safe, or wrote a line of code. Both of them exploited the same vulnerability: institutions verify surfaces, not substance.
Frank Abagnale Jr. is in this series because he documented that vulnerability four decades before email existed. In the 1960s, without a computer, he forged cheques and — by his account — impersonated people the system already trusted: an airline pilot, a physician, a lawyer. The surface was a uniform, a badge, a printed credential, a confident voice. The institution saw the surface and verified him by sight.
That is the same failure mode. The mechanism is identical. The medium changed — from a face in a uniform to a spoofed domain — but the exploit is the same one: trust built on appearance rather than verification.
Case 019 is the field guide entry, not the hagiography. The story Abagnale told — and sold — has been substantially contradicted by investigative research. A journalist named Alan C. Logan published a book in 2020 called The Greatest Hoax on Earth documenting those contradictions from court records, prison documents, and contemporary newspaper archives. [SOURCE: Logan, 2020; The Irish World interview with Logan]
The documented crime is real: check forgery, conviction, prison. The famous version — the years-long FBI chase, the serial impersonations at scale, the multiple prison escapes — is not supported by the primary record. What Abagnale did after prison was turn that distinction into a 40-year career. He is a living private individual and this piece reports the record, both the documented parts and the disputed parts.
The man whose fraud was impersonation ended up impersonating his own history. The biggest con he ever pulled was convincing the world his story was true — and then selling that conviction as fraud expertise for four decades.
Frank William Abagnale Jr. was born on April 27, 1948, in the Bronx, New York City. He grew up in Bronxville, then Mount Vernon, New York. His parents separated when he was 12 and divorced when he was 15.
Between approximately 1965 and 1974, Abagnale was in and out of prison and involved in check fraud. What the documentary record shows: he was a convicted check forger with multiple arrests. Prison records placed him at institutions during periods when, by his own account, he was flying as a Pan Am pilot or practicing medicine in Georgia. [SOURCE: Alan C. Logan, The Greatest Hoax on Earth, 2020 — citing court records and prison documents]
What Logan's research found, and what he documented from primary sources: between ages 17 and 20, Abagnale was incarcerated — not impersonating pilots. The FBI task force he described did not exist as described in his memoir. The prison escapes did not occur as described; he was never at Atlanta Federal Penitentiary and never escaped from it. He was arrested multiple times, not once as he claimed at a 2017 Google talk. [SOURCE: Logan, 2020; attrition.org documentation]
What is documented and not in serious dispute: a brief period in 1970 when Abagnale wore a Pan Am pilot uniform — approximately three months. The FBI pursuit was real but brief — approximately three months, not the years-long chase of the memoir and film. He was arrested in France in 1969. He served time in French and US prisons. He was released on condition that he assist federal authorities. He did some consulting work. [SOURCE: Logan, 2020; San Francisco Chronicle, October 6, 1978]
The San Francisco Chronicle article from October 6, 1978 — published two years before his memoir — was titled 'Johnny is conned. A convict who makes up crimes.' It was the first major exposé questioning his claims. It was cited in subsequent reporting. His claims were questioned for over 40 years by at least a dozen journalists before Logan's comprehensive 2020 book. [SOURCE: attrition.org compilation; Chronicle citation]
In 1980, Frank Abagnale Jr. published a memoir co-written with Stan Redding. The book was called Catch Me If You Can.
The book claimed: from approximately ages 16 to 21, Abagnale impersonated a Pan American World Airways pilot, logging over two million air miles. He practiced law in Louisiana without a degree. He worked as a supervising resident at a Georgia hospital. He cashed over $2.5 million in fraudulent cheques across 26 countries. He escaped from prison twice. He was chased by the FBI for years.
Each of these claims has been substantially disputed or refuted by Logan's primary-source research. Pan Am records do not support the pilot impersonation at the claimed scale. No Louisiana bar records support the attorney claim. Georgia hospital records do not support the physician claim. Prison records do not support the escape claims from the institutions he named. The FBI pursuit was approximately three months, not years. [SOURCE: Logan, The Greatest Hoax on Earth, 2020]
The memoir is self-reported. It is a claim, not a source. It is used here as a cultural document, not as evidence.
In 2002, Steven Spielberg made the book into a film. Leonardo DiCaprio played Abagnale. Tom Hanks played the FBI agent pursuing him. The film grossed over $350 million. It received two Academy Award nominations. It entered the cultural record as a true story of a charming genius-level con man.
That cultural entry is real even if the details are not. The film taught a generation what social engineering looks like. It gave the term 'con artist' a face. It made check fraud glamorous. The myth became the lesson whether the myth was accurate or not.
In 2002, Abagnale acknowledged on his website that some facts had been 'over-dramatized or exaggerated' without being specific about which ones. [SOURCE: Wikipedia citing archived website statement] This is not a full retraction. It is a partial acknowledgement. The disputed details continue to be repeated in speaking engagements and media appearances.
After his release, Frank Abagnale built a career as a fraud-prevention consultant. He founded Abagnale and Associates in 1976. He lectured at the FBI Academy. He consulted for banks, corporations, and government agencies on check fraud, forgery, and social engineering. [SOURCE: public record; Abagnale Inc. materials — self-reported]
The product he sold was his story. Banks hired him because he claimed to have defeated their systems. The FBI brought him in because he claimed to have evaded them for years. The consulting engagement required the legend — a watered-down resume would not have commanded the same fees or the same platform.
This is the mechanism that Logan documents: the fabricated criminal biography was not just a memoir, it was a commercial product. The grander and more spectacular the crimes, the more valuable the expert who had supposedly committed them. The fraud and the fraud prevention were the same business.
In 2020, when Logan's book was published, Abagnale continued to maintain his account in speaking appearances. He told a 2017 Google audience he had been arrested only once. Prison records cited by Logan document otherwise. [SOURCE: Logan, 2020; attrition.org]
He remains a living private individual. He is now 78 years old. This piece does not speculate about his current circumstances beyond the documented public record of his career.
DOCUMENTED RECORD vs ABAGNALE'S ACCOUNT
Check forgery / conviction
DOCUMENTED — court record confirms. This is real. [SOURCE: court record]
~5 years total prison time
DOCUMENTED — prison records confirm incarceration periods. [SOURCE: Logan, 2020]
Brief Pan Am uniform use (1970)
DOCUMENTED — approximately 3 months confirmed. [SOURCE: Logan, 2020]
FBI pursuit of ~3 months
DOCUMENTED — the FBI pursuit was real. The duration is confirmed as approximately 3 months. [SOURCE: Logan]
Years as pilot / doctor / lawyer
DISPUTED — no primary records support the claimed scale. Abagnale account; contradicted by Logan's primary-source research. [SOURCE: Logan, 2020]
Prison escapes
DISPUTED — records show he was not at Atlanta Federal Penitentiary; escapes as described not supported by prison documents. [SOURCE: Logan, 2020]
Years-long FBI chase
DISPUTED — FBI task force as described did not exist in the form claimed. Pursuit approximately 3 months. [SOURCE: Logan, 2020]
$2.5M in cheques, 26 countries
SELF-REPORTED — from memoir and speaking engagements. Not independently confirmed from court record. Attribute as his account. [SOURCE: Abagnale memoir, 1980]
The disputed details do not cancel the lesson. They sharpen it.
When verification is built on appearances, the fraud only needs to reproduce the appearance. That principle predates Abagnale, is documented through him, and runs through every non-technical case in this series.
() sent a spoofed email. The payment process saw the right domain and paid. () registered a company with the same name as a legitimate vendor, generated matching paperwork, and Google and Facebook paid $122 million. Morgan () built a public persona eccentric enough that law enforcement did not look at what was underneath it.
Every one of these cases exploits the same vulnerability: the institution verifies the surface. The email domain. The invoice format. The uniform. The confident voice. The artist brand. Not the underlying reality.
Abagnale's contribution to this catalogue — whatever the accurate scope of his crimes — is that he documented the principle clearly enough that it became a cultural reference. The film made it famous. The consulting career made it curriculum. Banks and corporations hired him to teach them how the surface exploit works because understanding the exploit is the beginning of defending against it.
That teaching function is real even if the biography is inflated. The modern KYC (know your customer) framework, enhanced vendor verification processes, and corporate anti-social-engineering training all address the same vulnerability Abagnale described. The defenses were built, at least in part, because the story made the vulnerability visible.
The fraudulent biography does not undermine the lesson — it doubles it. A man whose documented crime was impersonating people the system trusted went on to impersonate a more impressive version of himself and was trusted for four decades. That is not a contradiction of the principle. It is a demonstration of it.
He was never the greatest forger. He was the greatest salesman of the idea that trust is a surface. The cheques are long gone. The lesson is still being taught — by every scam email that says it's from someone you already trust.
VERIFIED SOURCES AND DISPUTE RECORD
Living private individual — report the record only. Self-reported figures attributed throughout. The dispute is presented from both sides as sourced. Do not present either the legend or the debunking as settled fact beyond what the primary sources confirm.
[1] US federal court records — conviction and supervised release. The court record establishes: check forgery, conviction, prison time. [VERIFY exact case numbers and docket before publication]
[2] French court records — 1969 arrest, Montpellier. [VERIFY exact sentence term and prison locations from primary French records before publication]
[3] Alan C. Logan — The Greatest Hoax on Earth (2020). The primary debunking source. Drawing on court records, prison documents, and newspaper archives. SOURCE for: incarceration between ages 17-20; no escapes from Atlanta FP (was never there); FBI pursuit ~3 months; multiple arrests contradicting his '1 arrest' claim. THIS SOURCE MUST BE NAMED AND ATTRIBUTED — do not present Logan's findings as established fact without attribution; present as his documented research.
[4] San Francisco Chronicle, October 6, 1978 — 'Johnny is conned. A convict who makes up crimes.' Written by Stephen S. Hall. The first major published exposé, predating the memoir. Cited in attrition.org documentation and by Logan.
[5] Attrition.org — 'He has been debunked before' — compilation of 12+ articles questioning Abagnale from 1978 to 2020. Establishes the pattern of repeated debunking across four decades.
[6] The Irish World — interview with Alan C. Logan. Key finding stated: 'between the ages of 17 and 20, Abagnale was incarcerated' — not flying internationally. 'The real FBI chase was just three months long.'
[7] Frank Abagnale with Stan Redding — Catch Me If You Can (memoir, 1980). SELF-REPORTED. Treated throughout as a claim, not a source of fact. The figures ($2.5M, 26 countries) come substantially from this document.
[8] Abagnale Inc. / Abagnale and Associates — his own consultancy materials. Self-reported. Founded 1976 per public record.
[9] Wikipedia — Frank Abagnale (aggregator). Source for 2002 website statement acknowledging 'over-dramatized or exaggerated' facts — verify this to the archived website before publication.
TO VERIFY Exact loss figure and its source (court record vs memoir); precise prison timeline and institutions; whether any impersonations are court-documented vs entirely self-reported; exact nature of the federal consulting arrangement post-release; birth date (April 27, 1948 — widely cited, verify to primary)