US authorities arrested John Daghita (online handle “Lick”) in Saint Martin for allegedly stealing more than $46 million in cryptocurrency tied to the U.S. Marshals Service (USMS). The arrest was conducted in a joint operation between the FBI and France’s Groupe d’Intervention de la Gendarmerie Nationale (GIGN), and reportedly involved the seizure of cash, hard drives, and security keys. Reporting links Daghita to a USMS digital-asset management contractor (CMDSS), and notes that blockchain investigator ZachXBT publicly traced USMS-linked wallet movements to addresses he associated with Daghita, helping bring attention to the alleged theft.
Separately, South Korea’s National Tax Service reportedly lost roughly $5 million in seized cryptocurrency after officials circulated a press release that exposed a wallet’s mnemonic recovery phrase/password, enabling an unknown party to drain the funds. The incident was described as part of a broader pattern of crypto custody lapses in South Korean law enforcement, with additional cases cited involving missing seized bitcoin and investigations tied to potential phishing and internal control failures. Together, the incidents underscore that government-held digital assets remain a high-value target and that operational security failures (credential exposure, weak key management, and inadequate redaction/review processes) can directly translate into rapid, irreversible losses.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
U.S. and French authorities arrested John Daghita in Saint Martin in a joint operation involving the FBI and France's GIGN. Officers reportedly seized cash, hard drives, and security keys during the operation.
After ZachXBT published his findings, the U.S. Marshals Service and Patrick Witt of the President’s Council of Advisors for Digital Assets said they would investigate the alleged theft. The Register also reported that CMDSS's online presence subsequently disappeared.
Blockchain investigator ZachXBT publicly linked wallet movements from USMS-associated addresses to John Daghita, citing transaction analysis and a recorded Telegram dispute. ZachXBT also reported that Daghita later sent small 'dust' transfers from the allegedly stolen funds to taunt him.
More than $46 million in cryptocurrency belonging to the U.S. Marshals Service was allegedly moved out of government-controlled wallets. Reporting says some of the assets were tied to seizures related to the 2016 Bitfinex hack, including a reported October 2024 theft.
Command Services & Support (CMDSS), led by Dean Daghita, began work under a U.S. government contract tied to the U.S. Marshals Service's management and disposal of seized digital assets. Later reporting connected this contractor relationship to the alleged theft case.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourcebleepingcomputer.com
Open sourcearstechnica.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.