Sports Cars, Private Jets, Mansions: How a $240 Million Bitcoin Theft Ended in Arrests

A group of crypto criminals stole $240 million in Bitcoin from a single victim, then spent the money so openly that investigators had little trouble following the trail.

ThreatVectr Newsdesk· 3 min read
Aerial 16:9 view looking straight down at a large outdoor stadium at dusk, floodlights illuminating the pitch, surrounding city lights fading into the distance,
Share

Key points

  • Criminals stole $240 million worth of Bitcoin from one victim in a single theft.
  • The suspects spent the proceeds on sports cars, private jet flights, hired security guards, and rented mansions in Miami and the Hamptons.
  • The spending spree was so visible it effectively handed investigators a roadmap.
  • The case illustrates how cryptocurrency theft, despite the technical complexity, often unravels through old-fashioned conspicuous consumption.

Some heists end in silence. This one ended in a driveway full of sports cars.

A group of criminals managed to steal $240 million in Bitcoin, which is a digital currency that exists only as computer code and can be transferred between people without a bank in the middle, from a single victim. The sum is large enough to rank among the biggest individual cryptocurrency thefts on record. What happened next was less sophisticated.

How did the criminals get caught?

They spent the money in plain sight. According to reporting first flagged by SecurityWeek, the group bought fleets of sports cars, chartered private jets, hired personal security guards, and rented luxury mansions in Miami and the Hamptons. That kind of spending leaves records, witnesses, and receipts.

Law enforcement agencies investigating large cryptocurrency thefts now work routinely with blockchain analytics firms, which are companies that trace the movement of digital currency across public transaction records the same way an accountant might follow bank statements. Bitcoin is often described as anonymous, but it is more accurate to call it pseudonymous: every transaction is written permanently into a public ledger called the blockchain, and tracing where money goes is frequently straightforward once investigators know which accounts to examine.

Coupling that on-chain trail with the unmissable offline spending gave investigators two parallel roads to the same destination.

The actual method used to steal the Bitcoin has not been fully detailed in public filings at the time of writing. Large individual cryptocurrency thefts typically involve social engineering, which means manipulating a person into handing over access credentials, or SIM-swapping, where criminals bribe or trick a mobile carrier into reassigning a victim's phone number to a device they control, cutting off two-factor authentication codes. Neither technique requires deep technical skill. Both rely on human error.

Should ordinary people worry about this?

Directly, no. This theft targeted a single high-value individual, not a bank or a platform holding many customers' funds. But the mechanics are a useful reminder for anyone who holds cryptocurrency, even modest amounts.

If your mobile phone number is linked to any financial account, ask your carrier to add a PIN or passphrase that must be spoken before your number can be moved. Use an authentication app rather than SMS text messages for login codes wherever possible, because SIM-swapping cannot intercept an app-based code. And be sceptical of any unsolicited contact, by phone, email, or message, asking you to confirm account details.

For the defendants, the party is over. For investigators, the case was almost too easy.

© 2026 Threat Vectr