A new investigation by prominent on-chain analyst ZachXBT has exposed what could be one of the most serious insider-related crypto security breaches involving UA new investigation by prominent on-chain analyst ZachXBT has exposed what could be one of the most serious insider-related crypto security breaches involving U

ZachXBT Alleges $40 Million Crypto Theft From U.S. Government Wallets

2026/01/26 00:57
5 min read

A new investigation by prominent on-chain analyst ZachXBT has exposed what could be one of the most serious insider-related crypto security breaches involving U.S. government-controlled wallets.

According to the findings, an individual identified as John Daghita is accused of siphoning over $40 million in various cryptocurrencies from digital wallets managed on behalf of the U.S. government. These wallets reportedly held seized assets tied to criminal investigations, funds meant to be securely stored under federal custody.

ZachXBT’s on-chain tracing reveals that the assets were not taken in a single transaction but drained gradually over several months, suggesting deliberate planning rather than a technical exploit. The stolen crypto was then routed through decentralized protocols and privacy mixers in anju apparent effort to conceal the money trail.

The full investigation was publicly detailed by ZachXBT in a thread shared here:

The revelations are now fueling serious concerns about how seized digital assets are being managed and protected by government contractors.

Family Connection Raises Insider Access Concerns

What makes the case especially alarming is the alleged family link to the firm responsible for safeguarding the seized funds.

ZachXBT reports that John Daghita is the son of the CEO of Cyber Management & Digital Security Services (CMDSS), a cybersecurity company that recently secured a federal contract involving digital asset custody.

CMDSS is not a peripheral service provider. The firm plays a direct role in managing and securing cryptocurrencies confiscated by U.S. authorities during criminal seizures. This places the company in control of wallets holding millions of dollars across multiple blockchains.

The relationship has sparked widespread concern that the alleged theft may not have resulted from hacking in the traditional sense, but rather from insider access, one of the most difficult security risks to prevent.

While no official confirmation has yet emerged from federal agencies, the connection alone has intensified calls for greater oversight in government crypto custody.

Federal Contract Put CMDSS At The Center Of Asset Custody

CMDSS was awarded a high-profile contract to assist the U.S. Marshals Service (USMS) in managing and disposing of seized and forfeited crypto assets.

The responsibilities reportedly include:

• Securing government-controlled wallets

• Managing transfers and liquidations

• Handling custody infrastructure

• Supporting digital asset forfeiture processes

In effect, CMDSS acts as a technical custodian for cryptocurrency confiscated during law enforcement operations.

These wallets may contain assets recovered from major hacks, fraud schemes, darknet marketplaces, and ransomware cases, making them highly sensitive targets.

The scale of funds under custody means even a small breach could lead to massive losses, placing extraordinary trust in the systems and personnel controlling access.

Alleged Systematic Draining And Laundering Operation

According to ZachXBT’s blockchain analysis, the theft unfolded slowly rather than through a sudden exploit.

The funds were allegedly:

• Removed in stages across months

• Moved through decentralized exchanges

• Routed via cross-chain bridges

• Laundered using privacy mixers and protocols

This pattern is consistent with techniques used by sophisticated threat actors to reduce traceability and avoid triggering automated monitoring systems.

ZachXBT claims transaction flows directly connect government seizure wallets to addresses controlled by Daghita, forming a consistent and traceable pattern of unauthorized withdrawals.

The gradual nature of the transfers suggests a calculated operation rather than an accidental exposure of private keys.

Unclear How Access Was Obtained

One of the most critical unanswered questions remains how John Daghita gained control over wallets holding government assets.

What is currently known:

• His father owns CMDSS

• CMDSS holds an active government IT contract in Virginia

• The company assists in managing seized crypto for the USMS

What remains unclear:

• Whether access was granted intentionally

• Whether internal security protocols failed

• Whether credentials were shared or compromised

• Whether proper multi-signature systems were in place

So far, no public explanation has been issued by CMDSS or U.S. authorities.

This lack of clarity has only intensified scrutiny around contractor oversight and internal security practices.

A Wake-Up Call For Government Crypto Security

If confirmed, the incident would represent one of the largest alleged insider crypto thefts tied to government-held funds.

It also highlights a growing challenge as law enforcement agencies accumulate massive crypto reserves through seizures.

Unlike traditional bank assets, cryptocurrencies rely entirely on private key security. Anyone with access can move funds instantly, with no central authority able to reverse transactions.

As governments increasingly outsource custody to private firms, risks expand to include:

• Insider abuse

• Weak access controls

• Poor audit systems

• Lack of real-time monitoring

• Human security failures

The case may push agencies to accelerate adoption of:

• Multi-signature custody wallets

• Segmented access permissions

• Independent security audits

• Continuous on-chain surveillance

For the crypto industry, it reinforces a long-standing reality: custody remains the weakest link in digital finance.

Even the most secure blockchain becomes vulnerable when access control breaks down.

As investigations continue, this case could become a turning point for how seized digital assets are managed worldwide, forcing tighter controls, greater transparency, and stronger accountability across both government agencies and private contractors.

For now, the blockchain evidence uncovered by ZachXBT has already sparked a serious conversation about insider risk in the era of government crypto custody, one likely to shape policy long after the dust settles.

Disclosure: This is not trading or investment advice. Always do your research before buying any cryptocurrency or investing in any services.

Follow us on Twitter @nulltxnews to stay updated with the latest Crypto, NFT, AI, Cybersecurity, Distributed Computing, and Metaverse news!

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Recovery extends to $88.20, momentum improves

Recovery extends to $88.20, momentum improves

The post Recovery extends to $88.20, momentum improves appeared on BitcoinEthereumNews.com. Silver price extended its recovery for the second straight day, up by
Share
BitcoinEthereumNews2026/02/05 07:34
Fed Decides On Interest Rates Today—Here’s What To Watch For

Fed Decides On Interest Rates Today—Here’s What To Watch For

The post Fed Decides On Interest Rates Today—Here’s What To Watch For appeared on BitcoinEthereumNews.com. Topline The Federal Reserve on Wednesday will conclude a two-day policymaking meeting and release a decision on whether to lower interest rates—following months of pressure and criticism from President Donald Trump—and potentially signal whether additional cuts are on the way. President Donald Trump has urged the central bank to “CUT INTEREST RATES, NOW, AND BIGGER” than they might plan to. Getty Images Key Facts The central bank is poised to cut interest rates by at least a quarter-point, down from the 4.25% to 4.5% range where they have been held since December to between 4% and 4.25%, as Wall Street has placed 100% odds of a rate cut, according to CME’s FedWatch, with higher odds (94%) on a quarter-point cut than a half-point (6%) reduction. Fed governors Christopher Waller and Michelle Bowman, both Trump appointees, voted in July for a quarter-point reduction to rates, and they may dissent again in favor of a large cut alongside Stephen Miran, Trump’s Council of Economic Advisers’ chair, who was sworn in at the meeting’s start on Tuesday. It’s unclear whether other policymakers, including Kansas City Fed President Jeffrey Schmid and St. Louis Fed President Alberto Musalem, will favor larger cuts or opt for no reduction. Fed Chair Jerome Powell said in his Jackson Hole, Wyoming, address last month the central bank would likely consider a looser monetary policy, noting the “shifting balance of risks” on the U.S. economy “may warrant adjusting our policy stance.” David Mericle, an economist for Goldman Sachs, wrote in a note the “key question” for the Fed’s meeting is whether policymakers signal “this is likely the first in a series of consecutive cuts” as the central bank is anticipated to “acknowledge the softening in the labor market,” though they may not “nod to an October cut.” Mericle said he…
Share
BitcoinEthereumNews2025/09/18 00:23
Wormhole launches reserve tying protocol revenue to token

Wormhole launches reserve tying protocol revenue to token

The post Wormhole launches reserve tying protocol revenue to token appeared on BitcoinEthereumNews.com. Wormhole is changing how its W token works by creating a new reserve designed to hold value for the long term. Announced on Wednesday, the Wormhole Reserve will collect onchain and offchain revenues and other value generated across the protocol and its applications (including Portal) and accumulate them into W, locking the tokens within the reserve. The reserve is part of a broader update called W 2.0. Other changes include a 4% targeted base yield for tokenholders who stake and take part in governance. While staking rewards will vary, Wormhole said active users of ecosystem apps can earn boosted yields through features like Portal Earn. The team stressed that no new tokens are being minted; rewards come from existing supply and protocol revenues, keeping the cap fixed at 10 billion. Wormhole is also overhauling its token release schedule. Instead of releasing large amounts of W at once under the old “cliff” model, the network will shift to steady, bi-weekly unlocks starting October 3, 2025. The aim is to avoid sharp periods of selling pressure and create a more predictable environment for investors. Lockups for some groups, including validators and investors, will extend an additional six months, until October 2028. Core contributor tokens remain under longer contractual time locks. Wormhole launched in 2020 as a cross-chain bridge and now connects more than 40 blockchains. The W token powers governance and staking, with a capped supply of 10 billion. By redirecting fees and revenues into the new reserve, Wormhole is betting that its token can maintain value as demand for moving assets and data between chains grows. This is a developing story. This article was generated with the assistance of AI and reviewed by editor Jeffrey Albus before publication. Get the news in your inbox. Explore Blockworks newsletters: Source: https://blockworks.co/news/wormhole-launches-reserve
Share
BitcoinEthereumNews2025/09/18 01:55