US authorities arrested John Daghita, a U.S. government contractor, on allegations he stole more than $46 million in cryptocurrency tied to wallets associated with the U.S. Marshals Service (USMS). The apprehension occurred on the Caribbean island of Saint Martin in a coordinated operation involving the FBI and French law enforcement units (including the French Gendarmerie), and was publicly confirmed by FBI Director Kash Patel, who also shared images of seized items reportedly including hardware wallets and cash.
Reporting and blockchain-tracing details indicate the theft activity was linked to a persona using the handles “John” / “Lick,” with on-chain movements drawing attention after a public “band-for-band” social media exchange; after attribution, the actor allegedly attempted to launder remaining proceeds via mixers and cross-chain transfers. The case has been highlighted as a high-impact insider threat scenario involving access to or association with a firm responsible for safeguarding seized digital assets, underscoring the need for strong access controls, contractor oversight, and monitoring around government-controlled cryptocurrency custody.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
On March 5, 2026, FBI Director Kash Patel publicly confirmed the arrest and said it reflected the bureau's commitment to pursuing fraud against U.S. taxpayers. The case was presented as a major insider-theft investigation involving government-controlled digital assets.
On March 4, 2026, U.S. government contractor John Daghita was arrested on the Caribbean island of Saint Martin for allegedly stealing cryptocurrency tied to the U.S. Marshals Service. The arrest was carried out through international coordination between the FBI and French Gendarmerie units, including GIGN.
Following the January 2026 attribution, the actor allegedly moved funds through mixers and across blockchains in an attempt to obscure their origin. Investigators continued tracing the transactions despite those laundering efforts.
In January 2026, blockchain investigator ZachXBT publicly connected the online personas 'John' and 'Lick' to wallets moving funds associated with the earlier government-wallet theft. The attribution followed observation of a Telegram 'band-for-band' exchange in which the actor screen-shared wallet activity and consolidated large balances.
In October 2024, attackers allegedly stole more than $20 million in cryptocurrency from a wallet controlled by the U.S. government and associated with the U.S. Marshals Service. The theft highlighted insider-risk concerns around custody of seized digital assets.
After the October 2024 theft, FBI outreach helped recover most of the stolen cryptocurrency, though some assets remained unrecovered. The exact recovery date was not specified in the references.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcetrmlabs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.