U.S. officials are investigating allegations that tens of millions of dollars in seized cryptocurrency may have been improperly moved from government-linked wallets through insider access. Public statements cited in the report indicate that the U.S. Marshals Service, or USMS, has acknowledged an active investigation into claims that more than $40 million in confiscated digital assets was siphoned from wallets associated with the government.
The controversy centers on Command Services & Support, better known as CMDSS, a Virginia-based technology contractor. The company had been hired by the USMS to help manage and dispose of certain categories of seized crypto assets. According to blockchain investigator ZachXBT, John “Lick” Daghita, the son of CMDSS president and chief executive Dean Daghita, allegedly obtained unauthorized access to wallets containing government-seized digital assets and diverted funds for personal use.
ZachXBT said he reported the suspected activity to authorities and linked multiple wallet addresses to assets controlled by, or associated with, the U.S. Marshals Service. Brady McCarron, chief of public affairs for the USMS, told CoinDesk that the agency could not provide further comment because the matter is under investigation. That leaves many of the details unconfirmed by officials, but the scale of the allegations has already pushed the issue into the center of public debate about state custody of crypto.
How the alleged digital asset theft came to light
The allegations did not begin with a formal government disclosure. Instead, they appear to have emerged after a dispute inside a private Telegram chat was recorded and later circulated online. ZachXBT said the individual identified as “Lick” appeared to share his screen, show a wallet containing millions of dollars in crypto, and demonstrate an ability to move funds in real time.
From there, on-chain analysis reportedly connected those wallets to addresses known to hold government-seized assets, including funds linked to prior high-profile law-enforcement seizures. Over the weekend, ZachXBT wrote on X that John “Lick” had been caught showing off a wallet address holding $23 million and that the address was directly tied to more than $90 million in suspected thefts from the U.S. government in 2024, as well as other unidentified victims between November 2025 and December 2025.
ZachXBT later identified the individual as John Daghita and alleged that he is the son of CMDSS’s president. He also pointed out that CMDSS currently holds an active federal IT contract. Public reporting says the company was awarded a contract in October 2024 to help the USMS manage and dispose of seized and forfeited digital assets, including crypto assets not supported by major exchanges and funds tied to complex criminal cases.
Those holdings reportedly include assets seized from the 2016 Bitfinex hack, one of the largest cryptocurrency thefts ever recorded. That detail matters because it suggests the wallets in question may have held especially sensitive assets from major enforcement actions, raising the stakes for any lapse in access control, internal oversight, or contractor security procedures.
ZachXBT has also said that it remains unclear how John Daghita allegedly obtained access to the wallets. At this stage, it is not known whether the access was facilitated through his father, through CMDSS’s internal systems, or by some other means. In practical terms, the case is not only about whether funds moved, but also about how wallet permissions may have been exposed in the first place.
On the asset side, ZachXBT said one wallet he attributed to Daghita held 12,540 ETH, worth roughly $36 million at recent prices. He further alleged that Daghita sent him 0.6767 ETH, which he said he intended to forward to a U.S. government seizure address. That claim, if accurate, could provide investigators with an additional evidentiary trail tied directly to wallet activity.
ZachXBT also claimed that transaction records suggest around $20 million was removed from USMS-linked wallets in October 2024. Most of that amount was allegedly returned within a day, but roughly $700,000 that was routed through instant exchanges was not recovered. In later posts, he estimated that the total suspected thefts could exceed $90 million across various crypto assets once other wallet activity observed in late 2025 is taken into account. Some of those assets, he said, may still remain in compromised wallets.
Why US government bitcoin custody is now under pressure
The allegations have drawn major attention because the U.S. government is one of the largest known holders of seized digital assets, especially bitcoin. Estimates in the report suggest federal authorities may control somewhere between roughly 198,000 BTC and more than 300,000 BTC. At current market valuations, that puts the government’s crypto stockpile in the tens of billions of dollars.
According to bitcointreasuries.net, the U.S. government holds 328,372 BTC, worth about $29 billion. When assets of that size are held under public authority, even a limited breakdown in internal controls, contractor oversight, key management, or audit procedures can turn into a major institutional credibility issue. The concern is no longer just about one disputed wallet; it is about whether the custody framework itself is robust enough for crypto-native risks.
The timing of the controversy adds to the pressure. Earlier this year, questions had already been raised about how seized bitcoin was being handled after reports suggested that forfeited assets tied to the Samourai Wallet case may have been improperly sold, despite executive orders directing that seized bitcoin should be retained as part of a U.S. Strategic Bitcoin Reserve.
Although U.S. officials later denied that any sale had taken place, the public was not given on-chain evidence sufficient to settle the issue for skeptics. As a result, this latest allegation involving USMS-linked wallets has intensified concerns that transparency, custody discipline, and public accountability remain weaker than many market participants would like to see.
More broadly, the case highlights a familiar truth in crypto: large balances do not become safe simply because they are held by a government agency. Whether assets are controlled by individuals, exchanges, custodians, or state institutions, security still depends on private key protection, access segregation, internal review, and verifiable operational controls. Because the U.S. government now sits on such a large stockpile of bitcoin and other digital assets, every lapse or suspected lapse will be judged by a much higher standard.

