Share with your CTO/CIO
A California hardware company owner allegedly moved over $300 million in Nvidia AI chip-laden servers to China by routing shipments through Malaysia and Singapore with falsified end-user documentation. Greg Lui, 38, of Earthmade Computer Inc., faces charges of export control violations, smuggling, and money-laundering conspiracy. His company received more than $176 million from two Malaysian intermediaries between January and October 2024 alone. The case sits squarely inside the October 2022 US Commerce Department controls on advanced computing chips, controls that were tightened twice more through April 2024.
What this means for your business
If your organization sources Nvidia H100s, A100s, or comparable restricted hardware through any channel that isn’t a direct, documented relationship with Nvidia or an authorized US distributor, this arrest is a live compliance stress test. The recurring failure mode here isn’t rogue actors operating in obvious shadows. It’s procurement chains that look legitimate at one hop and then route through a Malaysia or Singapore intermediary that nobody on your legal team ever reviewed. The question to ask isn’t whether you broke the rules. It’s whether you’d know if a supplier two steps upstream did.
The scale of the alleged scheme is worth sitting with. $300 million in server hardware, moved in under ten months, through companies that passed enough scrutiny to receive wire transfers. That’s not a gap in enforcement. That’s a gap in supply chain visibility (the ability to trace exactly who handled your hardware and where it was before it reached you) that enterprises running their own AI infrastructure almost certainly share. The Commerce Department has already shown it extends liability to foreign-produced equipment that incorporates US technology, so “we bought it abroad” is not a clean defense.
Enforcement is now clearly moving faster than compliance programs at most organizations. The tightening cadence, October 2022, October 2023, April 2024, means that a procurement process designed around last year’s controls is already behind. The vendor or reseller relationship worth reexamining isn’t the one that looks obviously risky. It’s the one that’s been running smoothly and quietly for two years without anyone asking how the hardware actually gets from factory to data center. That’s where the exposure lives.
Based on reporting from California Man Charged in $300 Million Nvidia AI Chip Smuggling Case, originally published 2026-10-03 09:32:00.

