FBI arrests suspect in $46M U.S. Marshals crypto theft case

ambcryptoPublicado em 2026-03-05Última atualização em 2026-03-05

Resumo

FBI Director Kash Patel announced the arrest of John Daghita, a U.S. government contractor, in Saint Martin by French authorities. Daghita is accused of stealing over $46 million in cryptocurrency from wallets managed by the U.S. Marshals Service, which handles seized digital assets in criminal cases. The theft was initially flagged by blockchain investigator ZachXBT in January, who identified suspicious transactions linked to an individual named "John." Following the allegations, U.S. agencies began reviewing the incident. The case highlights ongoing concerns about crypto custody risks as government-held digital assets grow. Authorities have not confirmed if any stolen funds were recovered.

A suspect accused of stealing tens of millions of dollars in cryptocurrency from wallets tied to the U.S. Marshals Service has been arrested in an international operation involving U.S. and French authorities.

According to a statement posted on X by FBI Director Kash Patel, John Daghita, described as a U.S. government contractor, was arrested on the island of Saint Martin by the French Gendarmerie’s elite tactical unit in a joint operation with the FBI.

Patel said Daghita allegedly stole more than $46 million in cryptocurrency from the U.S. Marshals Service, the federal agency responsible for managing assets seized in criminal investigations.

The operation involved cooperation with the International Cooperation Team Serious Crime Unit of the French Gendarmerie in Saint Martin and the Groupe d’intervention de la Gendarmerie nationale of Guadeloupe, Patel added.

Authorities have not yet released additional details about the specific charges or the mechanism through which the alleged theft occurred.

Alleged link to U.S. government crypto seizure wallets

The case appears connected to earlier allegations that funds had been improperly moved from wallets associated with U.S. government crypto seizures.

The U.S. Marshals Service is responsible for custody and liquidation of digital assets confiscated in federal criminal cases. This role has become increasingly significant as law enforcement agencies accumulate large crypto holdings from seizures and forfeitures.

In recent years, the agency has relied on external contractors to help manage technical aspects of digital asset storage and disposition.

While authorities have not publicly detailed the operational link between the suspect and the seized funds, Patel’s statement described Daghita as a government contractor, suggesting potential access through government-related infrastructure.

Earlier on-chain investigation drew attention to suspected theft

The alleged theft first drew attention in January after blockchain investigator ZachXBT published a series of posts examining suspicious wallet activity tied to a person identified as “John.”

According to the investigation, several wallets linked to the individual had moved tens of millions of dollars in cryptocurrency. It included transactions involving thousands of ETH.

ZachXBT alleged that some of the funds could be traced to addresses associated with U.S. government seizure wallets. However, the claims were not independently confirmed at the time.

The investigator also suggested that the individual might be John Daghita, but said additional verification was needed.

In subsequent updates, ZachXBT said the suspect continued interacting on Telegram. Also, he even transferred a small amount of cryptocurrency to the investigator’s public wallet address.

Government agencies began reviewing the incident

Following the public allegations, U.S. officials acknowledged they were examining the matter.

ZachXBT later reported that the U.S. Marshals Service and officials connected to the White House’s digital asset advisory group were reviewing the claims.

Today’s arrest marks the first confirmation from law enforcement that authorities were pursuing a case linked to the suspected theft.

Crypto custody risks remain under scrutiny

Unlike traditional assets, crypto holdings require specialized custody infrastructure, including private key management and blockchain transaction monitoring.

As governments accumulate larger crypto reserves through seizures and forfeitures, the systems used to safeguard those assets have become a critical security concern.

Authorities have not yet confirmed whether any of the allegedly stolen funds have been recovered.


Final Summary

  • The FBI confirmed the arrest of John Daghita in Saint Martin in connection with an alleged $46M cryptocurrency theft from the U.S. Marshals Service.
  • The case follows earlier on-chain investigations that flagged suspicious wallet activity tied to funds believed to originate from government seizure addresses.

Perguntas relacionadas

QWho was arrested in connection with the $46 million cryptocurrency theft from the U.S. Marshals Service?

AJohn Daghita, a U.S. government contractor, was arrested.

QWhich agencies were involved in the international operation leading to the arrest?

AThe FBI and the French Gendarmerie's elite tactical unit were involved in the operation.

QHow did the alleged theft first come to public attention?

ABlockchain investigator ZachXBT published a series of posts in January examining suspicious wallet activity tied to a person identified as 'John'.

QWhat role does the U.S. Marshals Service play in relation to cryptocurrency?

AThe U.S. Marshals Service is responsible for the custody and liquidation of digital assets confiscated in federal criminal cases.

QHas it been confirmed whether any of the stolen funds have been recovered?

AAuthorities have not yet confirmed whether any of the allegedly stolen funds have been recovered.

Leituras Relacionadas

Bitcoin Withdrawals Continue: 8 Years of Storage in a Coldcard Cold Wallet Ended in Zero

Coldcard Hardware Wallet Hacked: Losses Mount Due to Vulnerable Seed Generation A critical vulnerability in Coldcard hardware wallets has led to a continued wave of fund thefts. According to Galaxy Research, the total stolen has reached 1,367.05 BTC (approx. $88.6 million) from 4,585 addresses, a significant increase from the initial 594.5 BTC reported on July 30, 2026. Most of the stolen funds remain on the attackers' addresses. The issue is not with the current firmware, which Coinkite has updated, but with seed phrases generated on vulnerable devices between March 2021 and the release of fixed firmware versions. Due to a programmer error, devices switched from using a hardware random number generator to the software-based Yasmarang generator, which was initialized with publicly accessible data like the chip's serial number. This made the seed phrases predictable through offline brute-force attacks, meaning wallets remain at risk until funds are moved to a new wallet generated with the patched firmware. Affected devices include Mk2/Mk3 with firmware 4.0.1–4.1.9 (and up to 5.0.3), Mk4/Mk5 up to version 5.6.0, and Q models up to 1.5.0Q. The only exceptions are seeds created with a high-entropy method like at least 50 independent dice rolls or a strong unique BIP-39 passphrase. All other owners must generate a new seed on the fixed firmware and transfer their assets. A case highlighting the human impact involves a 39-year-old long-term investor who lost 2 BTC (approx. $130,000) in minutes. He had accumulated the Bitcoin over eight years through physical labor, viewing it as a financial lifeline and a retirement plan in a country suffering from hyperinflation. His story underscores that even conservative "buy and hold in cold storage" strategies can be compromised by such underlying technical flaws. From a technical perspective, this incident echoes historical failures where weak random number generators undermined cryptographic security, challenging the assumption that offline storage is automatically foolproof.

cryptonews.ruHá 46m

Bitcoin Withdrawals Continue: 8 Years of Storage in a Coldcard Cold Wallet Ended in Zero

cryptonews.ruHá 46m

Trading

Spot
活动图片