$40 Million+ US Govt Crypto Heist Leads To Contractor Exec’s Son: ZachXBT

bitcoinistОпубликовано 2026-01-26Обновлено 2026-01-26

Введение

On-chain investigator ZachXBT alleges that over $40 million was stolen from US government cryptocurrency seizure wallets, tracing the theft to John Daghita, also known as "Lick." The investigation suggests a connection to Daghita’s father, who owns Command Services & Support (CMDSS), a company with an active US government contract to assist the US Marshals Service in managing seized crypto assets. ZachXBT’s findings are based on recorded Telegram chats and wallet transactions, including a public dispute where Daghita displayed control over wallets containing millions in crypto. The funds are linked to earlier government seizures, including assets from the Bitfinex hack. Following the allegations, CMDSS’s online presence was deactivated. The incident has raised significant concerns among commentators, calling it a national security crisis and urging legislative action.

On-chain investigator ZachXBT says a $40 million-plus theft from US government crypto seizure wallets may trace back to John Daghita, an alleged threat actor who goes by “Lick,” and a contractor relationship tied to Daghita’s family.

The $40 Million+ Govt Crypto Wallet Robbery

In a Jan. 25 post, ZachXBT pointed to Command Services & Support (CMDSS), describing it as a firm with “an active IT government contract in Virginia,” and alleging it was “awarded a contract to assist the USMS in managing/disposing of seized/forfeited crypto assets.” ZachXBT added: “It still remains unclear at this point how John obtained access from his dad.”

The allegation lands against a backdrop of earlier tracing work published Jan. 23, where ZachXBT linked wallet activity and recorded chats to the same persona. “Meet the threat actor John (Lick), who was caught flexing $23M in a wallet address directly tied to $90M+ in suspected thefts from the US Government in 2024 and multiple other unidentified victims from Nov 2025 to Dec 2025,” ZachXBT wrote.

ZachXBT’s thread centers on a dispute in a Telegram group chat between “John” and another threat actor, Dritan Kapplani Jr., in what the community calls “band for band (b4b)”, an on-the-spot contest to prove who controls more funds. ZachXBT said the interaction was “fully recorded,” and claims the footage includes screen-shared wallet balances and contemporaneous transfers that help establish control.

According to the thread, the recording shows John screen-sharing an Exodus wallet displaying a Tron address holding $2.3 million. In a second segment, ZachXBT said “another $6.7M worth of ETH” moved into an Ethereum address while the argument continued.

ZachXBT framed the key evidentiary point as ownership continuity across addresses: “The recording captures that John clearly controls both addresses. Additional addresses can likely be found in the recordings. I then began tracing backwards to verify the source of funds.”

That tracing, ZachXBT said, connects the cluster to a March 2024 transfer of $24.9 million from a US government address tied to the Bitfinex crypto hack seizure. He also claimed $18.5 million “currently sits” at a cited address.

Beyond that 2024 linkage, ZachXBT asserted the primary address he tracked was tied to “$63M+ inflows from suspected victims and government seizure addresses in Q4 2025,” listing multiple transactions and chains, and separately flagged an additional 4.17K ETH ($12.4 million) flow from MEXC into the same cluster.

The Jan. 25 post attempts to explain a potential access path: if CMDSS was involved in US Marshals Service crypto asset management, the question becomes whether contractor-side systems, credentials, or processes provided an opening, intentionally or otherwise. ZachXBT stressed that the exact mechanism remains unknown.

Shortly after the post, ZachXBT said CMDSS’s X account, website, and LinkedIn “were all just deactivated,” and claimed Daghita “began trolling again on Telegram.”

On X, the claims drew sharp reactions from prominent Bitcoin commentators. Nakamoto Inc. CEO David Bailey wrote: “The son of the CEO of the company hired by the US Marshalls to safeguard the nation’s Bitcoin, stole $40m from it and now appears to be running. Treasury must secure the private keys from the Justice Department ASAP before more is stolen.”

Prominent Bitcoin advocate and co-founder of the Satoshi Nakamoto Institute Pierre Rochard framed the situation in national-security terms, posting, “This is a national security crisis,” and urging Congress to pass the BITCOIN Act.

At press time, Bitcoin traded at $87,847.

Bitcoin remains between the 0.618 and 0.786 Fib, 1-week chart | Source: BTCUSDT on TradingView.com

Связанные с этим вопросы

QWho is alleged to be responsible for the $40 million-plus theft from US government crypto seizure wallets?

AJohn Daghita, an alleged threat actor who goes by 'Lick'.

QWhich company, with a government contract, is alleged to be connected to the theft and is owned by John Daghita's father?

ACommand Services & Support (CMDSS).

QWhat key piece of evidence did ZachXBT use to link John Daghita to the stolen funds?

AA recorded Telegram group chat where John screen-shared wallet balances and made contemporaneous transfers, proving control of the addresses holding the funds.

QFrom which specific US government seizure were a significant portion of the stolen funds ($24.9M) traced back to?

AThe Bitfinex crypto hack seizure.

QHow did prominent Bitcoin commentator Pierre Rochard describe the situation?

AHe framed it as a 'national security crisis' and urged Congress to pass the BITCOIN Act.

Похожее

From Theft to Re-entry: How Was $292 Million "Laundered"?

A sophisticated crypto laundering operation was executed following the $292 million hack of Kelp DAO on April 18. The attack, attributed to the North Korean Lazarus group, began with anonymous infrastructure preparation using Tornado Cash to fund wallets untraceably. The hacker exploited a vulnerability in Kelp’s cross-chain bridge, stealing 116,500 rsETH. To avoid crashing the market, the attacker used Aave and Compound as laundering tools—depositing the stolen rsETH as collateral to borrow $190 million in clean, liquid ETH. This move triggered a bank run on Aave, causing an $8 billion drop in TVL. After consolidating funds, the attacker fragmented them across hundreds of wallets to evade detection. A major breakpoint was THORChain, where over $460 million in volume—30 times its usual activity—was processed in 24 hours, converting ETH into Bitcoin. This shift to Bitcoin’s UTXO model exponentially increased tracing complexity by shattering funds into countless untraceable fragments. The final destination was Tron-based USDT, the primary channel for illicit crypto flows. From there, funds were cashed out via OTC brokers in China and Southeast Asia, using unlicensed underground banks and UnionPay networks outside Western sanctions scope. Ultimately, the laundered money supports North Korea’s weapons programs, which rely heavily on crypto hacking for foreign currency. The incident underscores structural challenges in DeFi: its openness, composability, and lack of central control make such laundering not just possible, but inherently difficult to prevent.

marsbit58 мин. назад

From Theft to Re-entry: How Was $292 Million "Laundered"?

marsbit58 мин. назад

Google and Amazon Simultaneously Invest Heavily in a Competitor: The Most Absurd Business Logic of the AI Era Is Becoming Reality

In a span of four days, Amazon announced an additional $25 billion investment, and Google pledged up to $40 billion—both direct competitors pouring over $65 billion into the same AI startup, Anthropic. Rather than a typical venture capital move, this signals the latest escalation in the cloud wars. The core of the deal is not equity but compute pre-orders: Anthropic must spend the majority of these funds on AWS and Google Cloud services and chips, effectively locking in massive future compute consumption. This reflects a shift in cloud market dynamics—enterprises now choose cloud providers based on which hosts the best AI models, not just price or stability. With OpenAI deeply tied to Microsoft, Anthropic’s Claude has become the only viable strategic asset for Google and Amazon to remain competitive. Anthropic’s annualized revenue has surged to $30 billion, and it is expanding into verticals like biotech, positioning itself as a cross-industry AI infrastructure layer. However, this funding comes with constraints: Anthropic’s independence is challenged as it balances two rival investors, its safety-first narrative faces pressure from regulatory scrutiny, and its path to IPO introduces new financial pressures. Globally, this accelerates a "tri-polar" closed-loop structure in AI infrastructure, with Microsoft-OpenAI, Google-Anthropic, and Amazon-Anthropic forming exclusive model-cloud alliances. In contrast, China’s landscape differs—investments like Alibaba and Tencent backing open-source model firm DeepSeek reflect a more decoupled approach, though closed-source models from major cloud providers still dominate. The $65 billion bet is ultimately about securing a seat at the table in an AI-defined future—where missing the model layer means losing the cloud war.

marsbit7 ч. назад

Google and Amazon Simultaneously Invest Heavily in a Competitor: The Most Absurd Business Logic of the AI Era Is Becoming Reality

marsbit7 ч. назад

Торговля

Спот
Фьючерсы

Популярные статьи

Как купить S

Добро пожаловать на HTX.com! Мы сделали приобретение Sonic (S) простым и удобным. Следуйте нашему пошаговому руководству и отправляйтесь в свое крипто-путешествие.Шаг 1: Создайте аккаунт на HTXИспользуйте свой адрес электронной почты или номер телефона, чтобы зарегистрироваться и бесплатно создать аккаунт на HTX. Пройдите удобную регистрацию и откройте для себя весь функционал.Создать аккаунтШаг 2: Перейдите в Купить криптовалюту и выберите свой способ оплатыКредитная/Дебетовая Карта: Используйте свою карту Visa или Mastercard для мгновенной покупки Sonic (S).Баланс: Используйте средства с баланса вашего аккаунта HTX для простой торговли.Третьи Лица: Мы добавили популярные способы оплаты, такие как Google Pay и Apple Pay, для повышения удобства.P2P: Торгуйте напрямую с другими пользователями на HTX.Внебиржевая Торговля (OTC): Мы предлагаем индивидуальные услуги и конкурентоспособные обменные курсы для трейдеров.Шаг 3: Хранение Sonic (S)После приобретения вами Sonic (S) храните их в своем аккаунте на HTX. В качестве альтернативы вы можете отправить их куда-либо с помощью перевода в блокчейне или использовать для торговли с другими криптовалютами.Шаг 4: Торговля Sonic (S)С легкостью торгуйте Sonic (S) на спотовом рынке HTX. Просто зайдите в свой аккаунт, выберите торговую пару, совершайте сделки и следите за ними в режиме реального времени. Мы предлагаем удобный интерфейс как для начинающих, так и для опытных трейдеров.

1.2k просмотров всегоОпубликовано 2025.01.15Обновлено 2025.03.21

Как купить S

Sonic: Обновления под руководством Андре Кронье – новая звезда Layer-1 на фоне спада рынка

Он решает проблемы масштабируемости, совместимости между блокчейнами и стимулов для разработчиков с помощью технологических инноваций.

2.2k просмотров всегоОпубликовано 2025.04.09Обновлено 2025.04.09

Sonic: Обновления под руководством Андре Кронье – новая звезда Layer-1 на фоне спада рынка

HTX Learn: Пройдите обучение по "Sonic" и разделите 1000 USDT

HTX Learn — ваш проводник в мир перспективных проектов, и мы запускаем специальное мероприятие "Учитесь и Зарабатывайте", посвящённое этим проектам. Наше новое направление .

1.8k просмотров всегоОпубликовано 2025.04.10Обновлено 2025.04.10

HTX Learn: Пройдите обучение по "Sonic" и разделите 1000 USDT

Обсуждения

Добро пожаловать в Сообщество HTX. Здесь вы сможете быть в курсе последних новостей о развитии платформы и получить доступ к профессиональной аналитической информации о рынке. Мнения пользователей о цене на S (S) представлены ниже.

活动图片