ZachXBT Alleges John Daghita Tied to Multi-Million Theft From US-Linked Crypto Wallets

ZachXBT Alleges John Daghita Tied to Multi-Million Theft From US-Linked Crypto Wallets

N
News Editor 01
2026-07-23 14:00:16
ZachXBT says online figure “Lick,” identified as John Daghita, siphoned tens of millions from wallets linked to the US government and seized Bitfinex assets, putting federal crypto custody practices back under scrutiny.
ZachXBTUS government walletsCMDSSBitfinexcrypto custody

Blockchain investigator ZachXBT has accused John Daghita, whom he linked to the online identity “Lick,” of siphoning tens of millions of dollars in crypto from wallets connected to the U.S. government. The allegation has not been tested in court, but it has already drawn attention to how seized digital assets are stored and controlled by federal contractors.

Allegation centers on wallets tied to seized Bitfinex funds

In a public thread laying out his findings, ZachXBT said the funds in question were connected to assets seized from the 2016 Bitfinex hack. One address cited in the investigation allegedly received $24.9 million from a wallet controlled by the U.S. government in March 2024.

He also identified John Daghita as the son of Dean Daghita, president and chief executive of Command Services & Support, or CMDSS, a Virginia-based firm contracted by the U.S. Marshals Service to safeguard seized digital assets classified as “Class 2–4” tokens that require specialized custody arrangements. The latest claims build on an earlier probe published on January 23, which linked the “Lick” persona to more than $90 million in suspected illicit crypto flows moving through addresses associated with government-linked wallets.

Telegram dispute became a key turning point

According to the report, the investigation accelerated after a heated Telegram “band-for-band” exchange in which two individuals tried to outdo each other by displaying control over large balances. ZachXBT said “Lick” shared an Exodus wallet on screen, showing a Tron address holding roughly $2.3 million.

During the same exchange, “Lick” allegedly executed a live transfer of about $6.7 million in ether and later consolidated around $23 million into a single wallet. ZachXBT said that wallet could be traced back to a U.S. government address, giving the investigation a direct on-chain link to federal-controlled funds.

CMDSS faces renewed scrutiny over custody controls

CMDSS had already faced questions when it received the appointment. Rival firm Wave Digital Assets filed a protest with the Government Accountability Office, arguing that CMDSS lacked important registrations and warning about potential conflicts tied to a former Marshals Service official. The GAO later denied that protest.

Separate reporting from CoinDesk in 2025 added another layer of concern, saying the U.S. Marshals Service had struggled to reconcile its digital asset holdings. The article also noted that illicit addresses received a record $154 billion in 2025, keeping attention on federal custody procedures, internal controls, and reconciliation practices.

Crypto market reaction remains muted

Despite the seriousness of the allegation, the broader market appeared to stay focused on macro trading conditions rather than this single custody case. At the time cited in the report, Bitcoin was trading around $87,700 to $87,900, down roughly 1% over 24 hours, with daily volume in the mid-$40 billion range.

Ethereum changed hands near €3,150 to €3,200, up about 3% on the day, while Solana traded close to €151 after slipping roughly 2%. Those price moves suggested that traders were not treating the alleged breach as the main driver of market direction.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.