US Marshals Probe Alleged $40 Million Diversion of Seized Crypto Linked to Federal Contractor Family

US Marshals Probe Alleged $40 Million Diversion of Seized Crypto Linked to Federal Contractor Family

N
News Editor 01
2026-07-04 01:00:14
U.S. authorities are examining allegations that more than $40 million in seized cryptocurrency was improperly moved from government-linked wallets through insider access connected to a federal contractor. The U.S. Marshals Service confirmed that it is investigating claims involving wallets associated with confiscated digital assets. At the center of the controversy is Command Services & Support (CMDSS), a Virginia-based technology firm hired by the USMS in October 2024 to manage and dispose of certain categories of seized and forfeited crypto assets, including tokens not supported by major exchanges and assets tied to complex criminal matters. Blockchain investigator ZachXBT has accused John “Lick” Daghita, identified as the son of CMDSS president and CEO Dean Daghita, of obtaining unauthorized access to wallets holding government-seized funds. The allegations include a wallet containing 12,540 ETH, worth about $36 million, a 0.6767 ETH transfer allegedly sent to ZachXBT, and on-chain traces suggesting around $20 million left USMS-linked wallets in October 2024, with roughly $700,000 not recovered. ZachXBT further estimated that suspicious activity observed into late 2025 could push total suspected thefts above $90 million. The case has intensified scrutiny of how the U.S. government secures its vast crypto holdings, which various estimates place between 198,000 BTC and more than 328,372 BTC, potentially worth around $29 billion.
U.S. Marshals ServiceSeized CryptoZachXBTCMDSSBitcoin ReservesOn-Chain InvestigationGovernment Wallet Security

U.S. officials are investigating allegations that a large amount of cryptocurrency previously seized by law enforcement may have been diverted from government-linked wallets through insider access. Public statements indicate that the U.S. Marshals Service, or USMS, is reviewing claims that more than $40 million in confiscated digital assets was siphoned away. The issue has drawn wide attention not only because of the scale involved, but also because it appears to touch on contractor access, custody controls, and the broader security architecture used to manage government-held crypto.

The central company in the allegations is Command Services & Support (CMDSS), a Virginia-based technology contractor that works with the USMS on managing and disposing of certain categories of seized and forfeited digital assets. Blockchain investigator ZachXBT alleged that John “Lick” Daghita, the son of CMDSS president and chief executive Dean Daghita, obtained unauthorized access to wallets containing government-seized cryptocurrency and redirected funds for personal use. ZachXBT said he reported the activity to authorities and linked several wallet addresses to assets controlled by, or otherwise associated with, the USMS.

Brady McCarron, chief of public affairs for the USMS, told CoinDesk that the agency could not provide further comment because the matter was under investigation. Even with limited official detail, the case has already become highly significant. If the allegations are confirmed, the event would represent not just a theft, but a major breakdown in the custody controls surrounding one of the largest state-held pools of crypto assets in the world.

How the alleged digital asset theft came to light

The allegations first surfaced after a dispute in a private Telegram chat was recorded and later circulated online. According to ZachXBT, the individual known as “Lick” appeared to screen-share a wallet containing millions of dollars in cryptocurrency and demonstrated the ability to move funds in real time. In crypto investigations, that kind of behavior can be especially revealing, because it creates timestamps, wallet clues, and behavioral links that may later be matched with on-chain evidence.

Follow-up blockchain analysis reportedly connected those wallets to addresses known to hold government-seized assets, including funds associated with previous high-profile law enforcement seizures. Over the weekend, ZachXBT wrote on X: “Meet the threat actor John (Lick), who was caught flexing $23M in a wallet address directly tied to $90M+ in suspected thefts from the US Government in 2024 and multiple other unidentified victims from Nov 2025 to Dec 2025.” That framing expanded the scope of the controversy well beyond a single incident and suggested a broader pattern of suspicious activity.

ZachXBT later identified “Lick” as John Daghita and alleged that he is the son of CMDSS’s president. He also said CMDSS currently holds an active federal IT contract. Public reporting indicates that CMDSS received a contract in October 2024 to help the USMS manage and dispose of seized and forfeited digital assets. The work reportedly included crypto assets not supported by major exchanges, as well as assets connected to complicated criminal cases. That matters because the more specialized the assets are, the more operational discretion and technical access the service provider may need.

According to the allegations, the assets under management also included funds seized from the 2016 Bitfinex hack, one of the largest cryptocurrency thefts ever recorded. That connection significantly raises the stakes. Any unexplained movement involving wallets tied to a case of that magnitude would attract intense scrutiny from investigators, the crypto industry, and the public. At the same time, ZachXBT said it remains unclear exactly how John Daghita allegedly obtained access to the wallets, including whether that access was enabled through his father, through CMDSS internal systems, or through some other channel.

ZachXBT also provided specific wallet-level claims. He said one wallet attributed to Daghita held 12,540 ETH, worth roughly $36 million at recent prices. He further alleged that Daghita sent him 0.6767 ETH, which the investigator said he intended to forward to a U.S. government seizure address. Small transfers like that can play an outsized role in blockchain investigations because they may help establish wallet attribution, interaction patterns, and evidentiary links between parties.

Additional transaction analysis allegedly showed that about $20 million was removed from USMS-linked wallets in October 2024. Most of that amount was reportedly returned within a day, but around $700,000 that passed through instant exchanges was not recovered. In later posts, ZachXBT estimated that total suspected thefts could exceed $90 million when incorporating other wallet activity observed between late 2025 periods, some of which he said remained in compromised wallets. If true, the full impact would be substantially larger than the initially highlighted $40 million figure.

Why the case raises broader questions about U.S. crypto custody

The allegations have triggered renewed concern about how the U.S. government secures its growing stockpile of bitcoin and other digital assets. The federal government may control anywhere from about 198,000 BTC to more than 300,000 BTC, depending on the source and methodology used. At current market prices, that places the value in the tens of billions of dollars. According to bitcointreasuries.net, the U.S. government holds 328,372 BTC, worth roughly $29 billion. Regardless of the exact count, the government is clearly one of the most significant sovereign holders of bitcoin in the world.

This context makes any wallet security lapse far more serious than an ordinary loss event. The issue is not only whether funds were stolen, but whether the systems used to store, authorize, track, and dispose of seized crypto are robust enough for holdings of this scale. Government-managed wallets may contain assets from high-profile criminal cases, dormant token positions, or coins recovered years earlier, all of which require careful operational controls. That includes key management, access segregation, approval workflows, and independent auditing of all transfers.

The controversy also arrives at a sensitive moment. Earlier this year, questions were raised over whether forfeited assets connected to the Samourai Wallet case had been improperly sold, despite executive orders directing that seized bitcoin be retained as part of a U.S. Strategic Bitcoin Reserve. That earlier dispute had already elevated scrutiny around government handling of digital assets. It highlighted the gap that can emerge between policy announcements, custody practice, and what outside observers are able to verify on-chain.

Although U.S. officials later denied that any sale had taken place, the absence of publicly presented on-chain evidence continued to fuel skepticism. The current allegations add a new layer to that distrust. Market participants and investigators are now likely to ask who exactly holds signing authority, how much operational access contractors receive, whether multisignature controls are used consistently, whether cold storage is properly segmented, and how quickly anomalies are detected and contained when suspicious transfers occur.

From an industry perspective, the government faces many of the same risks as exchanges, custodians, and institutions. Private key management, hot wallet exposure, internal permissions, third-party service providers, and transaction monitoring all remain critical points of failure. The difference is scale and public consequence. When a government agency controls seized assets worth tens of billions of dollars, even a brief breakdown in access control can have major legal, financial, and reputational consequences.

That is why this episode matters beyond the headline number. Even if the final investigation narrows or revises some of the claims, the case already functions as a stress test for sovereign crypto custody. It forces attention onto a basic question: are traditional contractor models and legacy IT control structures enough for the era of large-scale state-held digital assets? As governments around the world accumulate more crypto through seizures, enforcement actions, and reserve strategies, that question will only become more pressing.

What investigators and the market will watch next

The next phase of the story will likely focus on three issues. First, investigators will need to determine whether John Daghita can be directly tied to the relevant wallets, transfers, devices, or access records. Second, the public will want greater clarity on the practical scope of CMDSS’s role in the USMS digital asset custody chain. A contractor may have technical responsibilities without having unfettered transfer authority, and the distinction will matter greatly in evaluating both accountability and control failures.

Third, pressure will grow on officials to release more complete forensic findings, audit trails, or on-chain explanations. Without that, skepticism may continue, especially given the earlier controversy around the treatment of seized bitcoin. For the crypto sector, the case is already a reminder that blockchain transparency does not automatically eliminate custody risk. Funds can still move through compromised access, internal abuse, or weak operational safeguards, and recovery becomes much harder once assets are routed through fast-moving exchange services.

Ultimately, this case is becoming a landmark example in the debate over public-sector crypto security. It combines large seized holdings, outsourced technical management, alleged family-linked insider access, and public blockchain evidence into one high-stakes controversy. Until authorities provide clearer answers, it will remain central to discussions about how governments should secure, audit, and publicly account for digital assets under their control.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.