{"id":69291,"date":"2026-01-26T07:16:34","date_gmt":"2026-01-26T07:16:34","guid":{"rendered":"https:\/\/dogewisperer.com\/?p=69291"},"modified":"2026-01-26T07:16:34","modified_gmt":"2026-01-26T07:16:34","slug":"40-million-us-govt-crypto-heist-leads-to-contractor-execs-son-zachxbt","status":"publish","type":"post","link":"https:\/\/dogewisperer.com\/?p=69291","title":{"rendered":"$40 Million+ US Govt Crypto Heist Leads To Contractor Exec\u2019s Son: ZachXBT"},"content":{"rendered":"<div>\n<p>On-chain investigator ZachXBT says a $40 million-plus theft from US government crypto seizure wallets may trace back to John Daghita, an alleged threat actor who goes by \u201cLick,\u201d and a contractor relationship tied to Daghita\u2019s family.<\/p>\n<h2>The $40 Million+ Govt Crypto Wallet Robbery<\/h2>\n<p>In a Jan. 25 post, ZachXBT pointed to Command Services &amp; Support (CMDSS), describing it as a firm with \u201can active IT government contract in Virginia,\u201d and alleging it was \u201cawarded a contract to assist the USMS in managing\/disposing of seized\/forfeited crypto assets.\u201d ZachXBT added: \u201cIt still remains unclear at this point how John obtained access from his dad.\u201d<\/p>\n<blockquote class=\"twitter-tweet\">\n<p dir=\"ltr\" lang=\"en\">In case you are curious how John Daghita (Lick) was able to steal $40M+ from US government seizure addresses.<\/p>\n<p>John\u2019s dad owns CMDSS, which currently has an active IT government contract in Virginia.<\/p>\n<p>CMMDS was awarded a contract to assist the USMS in managing\/disposing of\u2026 <a href=\"https:\/\/t.co\/lzR2a1aidA\" rel=\"nofollow\">https:\/\/t.co\/lzR2a1aidA<\/a> <a href=\"https:\/\/t.co\/PV0IkSuhVy\" rel=\"nofollow\">pic.twitter.com\/PV0IkSuhVy<\/a><\/p>\n<p>\u2014 ZachXBT (@zachxbt) <a href=\"https:\/\/twitter.com\/zachxbt\/status\/2015430549846777964?ref_src=twsrc%5Etfw\" rel=\"nofollow noopener\" target=\"_blank\">January 25, 2026<\/a><\/p>\n<\/blockquote>\n<p>The allegation lands against a backdrop of earlier tracing work published Jan. 23, where ZachXBT linked wallet activity and recorded chats to the same persona. \u201cMeet the threat actor John (Lick), who was caught flexing $23M in a wallet address directly tied to $90M+ in suspected thefts from the US Government in 2024 and multiple other unidentified victims from Nov 2025 to Dec 2025,\u201d ZachXBT wrote.<\/p>\n<p>ZachXBT\u2019s thread centers on a dispute in a Telegram group chat between \u201cJohn\u201d and another threat actor, Dritan Kapplani Jr., in what the community calls \u201cband for band (b4b)\u201d, an on-the-spot contest to prove who controls more funds. ZachXBT said the interaction was \u201cfully recorded,\u201d and claims the footage includes screen-shared wallet balances and contemporaneous transfers that help establish control.<\/p>\n<p>According to the thread, the recording shows John screen-sharing an Exodus wallet displaying a Tron address holding $2.3 million. In a second segment, ZachXBT said \u201canother $6.7M worth of ETH\u201d moved into an Ethereum address while the argument continued.<\/p>\n<blockquote class=\"twitter-tweet\" data-conversation=\"none\">\n<p dir=\"ltr\" lang=\"en\">3\/ In part 1 of the recording Dritan mocks John however John screenshares Exodus Wallet which shows the Tron address below with $2.3M:<br \/>\nTMrWCLMS3ibDbKLcnNYhLggohRuLUSoHJg <a href=\"https:\/\/t.co\/jvcjIVEpaE\" rel=\"nofollow\">pic.twitter.com\/jvcjIVEpaE<\/a><\/p>\n<p>\u2014 ZachXBT (@zachxbt) <a href=\"https:\/\/twitter.com\/zachxbt\/status\/2014685270868660288?ref_src=twsrc%5Etfw\" rel=\"nofollow noopener\" target=\"_blank\">January 23, 2026<\/a><\/p>\n<\/blockquote>\n<p>ZachXBT framed the key evidentiary point as ownership continuity across addresses: \u201cThe recording captures that John clearly controls both addresses. Additional addresses can likely be found in the recordings. I then began tracing backwards to verify the source of funds.\u201d<\/p>\n<p>That tracing, ZachXBT said, connects the cluster to a March 2024 transfer of $24.9 million from a US government address tied to the <a href=\"https:\/\/bitcoinist.com\/bitfinex-mastermind-released-early-trump-law\/\" target=\"_blank\" rel=\"noopener \">Bitfinex crypto hack seizure<\/a>. He also claimed $18.5 million \u201ccurrently sits\u201d at a cited address.<\/p>\n<p>Beyond that 2024 linkage, ZachXBT asserted the primary address he tracked was tied to \u201c$63M+ inflows from suspected victims and government seizure addresses in Q4 2025,\u201d listing multiple transactions and chains, and separately flagged an additional 4.17K ETH ($12.4 million) flow from MEXC into the same cluster.<\/p>\n<p>The Jan. 25 post attempts to explain a potential access path: if CMDSS was involved in US Marshals Service crypto asset management, the question becomes whether contractor-side systems, credentials, or processes provided an opening, intentionally or otherwise. ZachXBT stressed that the exact mechanism remains unknown.<\/p>\n<p>Shortly after the post, ZachXBT said CMDSS\u2019s X account, website, and LinkedIn \u201cwere all just deactivated,\u201d and claimed Daghita \u201cbegan trolling again on Telegram.\u201d<\/p>\n<p>On X, the claims drew sharp reactions from prominent Bitcoin commentators. Nakamoto Inc. CEO David Bailey wrote: \u201cThe son of the CEO of the company hired by the <a href=\"https:\/\/bitcoinist.com\/us-marshalls-85-less-bitcoin-than-believed-foia\/\" target=\"_blank\" rel=\"noopener \">US Marshalls<\/a> to safeguard the nation\u2019s Bitcoin, stole $40m from it and now appears to be running. Treasury must secure the private keys from the Justice Department ASAP before more is stolen.\u201d<\/p>\n<p>Prominent Bitcoin advocate and co-founder of the Satoshi Nakamoto Institute Pierre Rochard framed the situation in national-security terms, posting, \u201cThis is a national security crisis,\u201d and urging Congress to pass the BITCOIN Act.<\/p>\n<p>At press time, Bitcoin traded at $87,847.<\/p>\n<p><img data-recalc-dims=\"1\" fetchpriority=\"high\" decoding=\"async\" class=\"size-full wp-image-658996\" src=\"https:\/\/bitcoinist.com\/wp-content\/uploads\/2026\/01\/BTCUSDT_2026-01-26_08-01-51.png?resize=1024%2C499\" alt=\"Bitcoin price chart\" width=\"1024\" height=\"499\" srcset=\"https:\/\/bitcoinist.com\/wp-content\/uploads\/2026\/01\/BTCUSDT_2026-01-26_08-01-51.png?w=3628 3628w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2026\/01\/BTCUSDT_2026-01-26_08-01-51.png?w=640 640w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2026\/01\/BTCUSDT_2026-01-26_08-01-51.png?w=768 768w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2026\/01\/BTCUSDT_2026-01-26_08-01-51.png?w=980 980w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2026\/01\/BTCUSDT_2026-01-26_08-01-51.png?w=130 130w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2026\/01\/BTCUSDT_2026-01-26_08-01-51.png?w=1536 1536w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2026\/01\/BTCUSDT_2026-01-26_08-01-51.png?w=2048 2048w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2026\/01\/BTCUSDT_2026-01-26_08-01-51.png?w=750 750w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2026\/01\/BTCUSDT_2026-01-26_08-01-51.png?w=1140 1140w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2026\/01\/BTCUSDT_2026-01-26_08-01-51.png?w=3000 3000w\" sizes=\"(max-width: 1000px) 100vw, 1000px\"><\/div>\n","protected":false},"excerpt":{"rendered":"<p>On-chain investigator ZachXBT says a $40 million-plus theft from US government crypto seizure wallets may trace back to John Daghita, an alleged threat actor who goes by \u201cLick,\u201d and a contractor relationship tied to Daghita\u2019s family. The $40 Million+ Govt Crypto Wallet Robbery In a Jan. 25 post, ZachXBT pointed to Command Services &amp; Support [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"iawp_total_views":0,"footnotes":""},"categories":[2],"tags":[3,4,5],"class_list":["post-69291","post","type-post","status-publish","format-standard","hentry","category-news","tag-crypto","tag-doge","tag-news"],"_links":{"self":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts\/69291","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=69291"}],"version-history":[{"count":0,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts\/69291\/revisions"}],"wp:attachment":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=69291"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=69291"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=69291"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}