A $300 Million Chip-Smuggling Indictment Is a Case Study in Every Red Flag Export Compliance Teams Are Told to Watch

The Justice Department unsealed an indictment on October 2 charging the CEO of a California technology company with orchestrating one of the largest alleged diversions of advanced U.S. computing chips to China to date. According to prosecutors, Greg Lui, who runs Earthmade Computer, arranged the purchase and shipment of more than $300 million worth of export-controlled servers containing advanced Nvidia processors, routing them through Malaysia and Singapore on their way to a buyer in Hangzhou, China. As with every indictment, these are allegations, and Lui is presumed innocent unless and until proven guilty. But the facts alleged are so detailed, and so closely track the red flags regulators have been warning about, that the case deserves close study by anyone who manufactures, sells, ships, or finances advanced technology.
The Charges and the Stakes
Lui faces three counts: conspiracy to violate the Export Control Reform Act and the Export Administration Regulations, conspiracy to commit money laundering, and outbound smuggling. The conspiracy and money laundering counts each carry a maximum of 20 years in prison, and the smuggling count carries a maximum of 10. Prosecutors also say they will seek forfeiture of all proceeds of the scheme. According to the government, Earthmade received more than $176 million from two Malaysian shipping companies between January and October 2024 for brokering the sales.
Why the Destination Mattered
The chips at issue include Nvidia A100 and H100 processors and consumer-grade GeForce RTX 4090 and 5090 cards, all of which the government says fall under Export Control Classification Number 4A090.a. The structure of the alleged scheme turns on a simple regulatory fact: those items require an export license for China, but not for Malaysia or Singapore. That gap is exactly what the indictment says Lui exploited. Ship the servers to a country where no license is needed, then move them onward to the real customer. The indictment says he continued shipping controlled items as recently as August of this year, including items classified under ECCNs 4A090.a, 5A002.z, and 5A992.z.
Prosecutors allege Lui knew the true end users were in China, and that he worked with transshipment companies in Malaysia to hide the actual destination and to give U.S. manufacturers false information so that they would conclude no license was needed.
How the Scheme Allegedly Worked
The indictment lays out a sequence of transactions that reads like a playbook of evasion techniques.

In January 2024, emails allegedly show Lui planning with an international broker, who was posing as the chief technology officer of a Malaysian company whose business was mostly in the lumber industry, to buy export-controlled servers. The emails included a plan to purchase 70 servers with controlled chips and a compliance form showing the Malaysian company knew the servers required export licenses. Days later, Lui allegedly ordered 27 servers with H100 chips from an American manufacturer for about $7.6 million, and the next day a freight forwarder exported them from Los Angeles to the Malaysian company. The packing list, according to prosecutors, identified the H100 chips. Less than two weeks later, the Malaysian company’s CEO allegedly emailed a Malaysian government official that the servers had been transshipped to an industrial company in Hangzhou.
In April, a sales manager at a U.S. manufacturer allegedly quoted Lui 512 controlled servers. By June, 92 were ready, and prosecutors say Lui arranged to fly them from San Francisco to Malaysia on a commercial passenger airline, and from there to Hong Kong, with a Malaysian front company listed as the shipper and the Chinese buyer in Hangzhou listed as the consignee.
In July, Lui allegedly bought 100 more H100 servers, worth more than $22 million, from a different manufacturer. The indictment says he used a U.S.-based front company, Topmost, incorporated in California in February 2024 by a co-conspirator, to make the purchase, and had a representative tell the manufacturer that Topmost would be the buyer and the servers would go to Malaysia. To close the deal, Lui allegedly supplied fraudulent documents naming a person as Topmost’s CEO. According to the indictment, he had bought that individual’s identifying documents back in 2021 and used the identity in the scheme.
Prosecutors also say Lui caused false information to be filed in Electronic Export Information submissions through the Automated Export System and used accounts at Bank of America and JPMorgan Chase to run what they call a smuggling business. John Eisenberg, who heads the Justice Department’s National Security Division, said Lui also staged dummy servers to mislead inspectors. The FBI’s Roman Rozhavsky said the chips were allegedly sold to the Chinese government.
The Red Flags, One by One
For compliance professionals, the value of this indictment is that nearly every classic red flag appears in it. A buyer whose stated line of business, lumber, has nothing to do with high-performance computing. A newly incorporated U.S. company, formed only months before it placed a $22 million order. Identity documents that allegedly belonged to someone else. Shipments routed through transshipment hubs, in this case Malaysia, Singapore, and Hong Kong, that have become familiar waypoints in the joint DOJ, Commerce, and Treasury guidance on evasion. A shipper listed as a front company and a consignee in China on the same movement. Multiple freight forwarders used to break up the path. A compliance form signed by a customer that acknowledged license requirements for the very products it was buying. And a pattern of large, repeated orders for exactly the highest-performance products in the controlled category.
If you work at a server manufacturer, a distributor, or a freight forwarder, ask yourself which of these signals your onboarding and order-screening processes would actually have caught. The alleged scheme depended on manufacturers accepting a customer’s statement about where the goods were going. It also depended on shipping records being filed with false information, and on inspection processes that could be defeated with dummy equipment.

What Compliance Teams Should Take Away
First, a destination that doesn’t require a license is not the same as an end user that doesn’t require one. Screening that stops at the country of the first consignee is blind to transshipment. Know your customer, know what they do, and ask why a lumber company wants 70 servers with the most advanced AI processors on the market.
Second, treat new entities and unusual corporate profiles with skepticism, particularly when large orders follow quickly after incorporation. Verify beneficial ownership and the identity of the people signing for the company.
Third, license determinations should rest on diligence, not on a buyer’s assurance. When the buyer’s own paperwork acknowledges a license requirement, as the indictment alleges, the seller needs a very good explanation for why it no longer applies.
Fourth, freight forwarders and logistics providers file Electronic Export Information and carry real responsibility for its accuracy. Packing lists that name controlled chips, routed to a country where the stated customer has no obvious need for them, are a red flag in their own right.
Fifth, financial institutions have a role. Accounts through which more than $176 million allegedly flowed from foreign shipping companies to a U.S. technology broker in under a year should trigger monitoring and review.
Finally, this case reflects a broader enforcement environment in which export controls on advanced computing are a national security priority and in which prosecutors are charging individuals with serious offenses, including money laundering and smuggling, that carry decades in prison. That is a reminder that the exposure for these schemes does not stop at the company level.
The government has the burden of proof here, and the defense has not yet been heard. But whatever the outcome, the indictment gives every company in the advanced technology supply chain a detailed checklist of how a diversion scheme is alleged to work, and a prompt to test whether its own controls would stop it.











