The US government has been trying to execute a historic pivot with its Bitcoin holdings, shifting from a messy, case-by-case inventory of seized crypto into a strategicThe US government has been trying to execute a historic pivot with its Bitcoin holdings, shifting from a messy, case-by-case inventory of seized crypto into a strategic

Security of the US government’s $28B Bitcoin reserve threatened after weekend theft reveals flaw

7 min read

The US government has been trying to execute a historic pivot with its Bitcoin holdings, shifting from a messy, case-by-case inventory of seized crypto into a strategic national reserve for almost a year now.

That ambition, often framed as a “digital Fort Knox,” is now facing a credibility test after allegations that roughly $40 million in crypto was siphoned from government-linked seizure wallets.

Even if the reported loss is small relative to the roughly $28 billion in Bitcoin the US is widely believed to control, the episode cuts at the core premise of the new posture. It raises doubts about whether Washington can manage a sovereign-scale Bitcoin balance sheet with reserve-grade security and auditable controls.

The alleged insider breach

Over the weekend, blockchain investigator ZachXBT alleged that more than $40 million in crypto was siphoned from US government-linked seizure wallets.

ZachXBT linked the alleged theft to John Daghita, popularly known as Licks, who he said maintains family ties to the executive leadership of Command Services & Support (CMDSS), a private firm contracted to support US Marshals Service (USMS) crypto seizure operations.

Corporate filings indicate that Dean Daghita serves as president of CMDSS. The firm is based in Haymarket, Virginia, and is contracted by the USMS to manage and dispose of specific categories of seized cryptocurrency.

ZachXBT said he was able to connect John Daghita to the alleged theft after what he described as a “band-for-band” argument on Telegram, a dispute in which two individuals attempted to prove their wealth by comparing wallet balances.

The dispute allegedly culminated in a persona identified as “Lick” screen-sharing an Exodus wallet and moving large sums in real time.

That screen-shared activity provided a trail ZachXBT said he used to trace a cluster of addresses that is linked to more than $90 million in suspected illicit flows. Of this, roughly $24.9 million moved from a US-controlled wallet in March 2024.

This scenario spotlights a vulnerability that has less to do with sophisticated protocol exploits and more with custody governance, contractor access, and the kinds of human failure modes that tend to scale poorly when real money and real operational complexity collide.

Meanwhile, this is also not the first time federal crypto custody operations have faced scrutiny. In October 2024, a wallet linked to the Bitfinex hack proceeds was drained of approximately $20 million, though the funds were largely recovered.

Related Reading

US government-linked address likely exploited for over $20 million in crypto

The US-government controlled wallet held significant amounts of seized crypto linked to the Bitfinex hack in 2016.

Oct 25, 2024 · Gino Matos

Fragmentation creates risk

In popular imagination, the US government's roughly $28 billion Bitcoin position sounds like a single stockpile sitting behind a single set of controls.

US Government Bitcoin HoldingsUS Government Bitcoin Holdings (Source: Bitcoin Treasuries)

However, the operational reality for these assets is far more fragmented.

Custody arrangements for seized crypto are a patchwork of agencies, legal statuses, and storage solutions. Funds can sit at different points in the forfeiture pipeline, and “US holdings” is not a single ledger entry but rather a complex operational system.

That variance matters because security in a multi-agency mesh depends on process discipline, consistent standards, and the rapid migration of funds from temporary seizure wallets into long-term cold storage.

This is because a single custodian can be defended with fortress-like protocols.

However, a system involving multiple vendors and handoffs behaves differently. It relies on the consistency of controls across every node in the network, including the people and contractors who touch the process.

So, the ambiguity around which agency holds which keys and when expands the attack surface.

Thus, oversight can slip in the gaps between organizations, between temporary wallets and long-term storage, and between policy ambition and day-to-day operational reality.

In that context, the significance of this reported $40 million loss becomes bigger as it implies a process failure.

Such custody failure suggests unknown exposure elsewhere, especially if the weakness is rooted in vendor governance or insider access rather than a one-off technical exploit.

The contractor's “hard tail” vulnerability

Contractors like CMDSS are central to understanding this risk profile because they sit where the government’s custody system becomes most complicated.

A Government Accountability Office (GAO) decision from March 2025 confirmed that the USMS awarded CMDSS a contract to manage “Class 2–4 cryptocurrencies.”

The GAO document draws a distinction between asset classes that helps explain why contractors matter.

Class 1 assets are generally liquid and can be readily supported by standard cold storage. Class 2–4 assets, by contrast, are described as “less popular” and require specialized handling, often involving bespoke software or hardware wallets.

That is the hard tail of crypto custody, the long list of assets that are not simply Bitcoin and a handful of other liquid tokens, but the messy inventory that arrives through seizures. Managing those assets can require navigating different blockchains, unfamiliar signing flows, and complex liquidation requirements.

Related Reading

US Marshals Service picks Coinbase Prime to custody ‘Class 1' digital assets

Coinbase Prime will implement storage and liquidation techniques in compliance with both DOJ and USMS policies.

Jul 1, 2024 · Assad Jafri

In practical terms, it creates a reliance on external expertise to manage the most challenging aspects of custody. Under this model, the government effectively outsources the messiest corner of crypto operations.

The GAO notes that contractors are strictly prohibited from using government assets for staking, borrowing, or investing.

But contractual prohibitions are not physical controls. They cannot, on their own, prevent misuse of a private key if human controls are bypassed.

That is why the allegations, framed as contractor ecosystem risk and social engineering rather than protocol failure, carry weight beyond the specific theft claim. If the system’s resilience depends on discipline across every vendor and handoff, then the weakest node becomes the most attractive target.

Notably, warnings about custody gaps are not new. A 2025 report highlighted that the USMS could not provide even a rough estimate of its BTC holdings and had previously relied on spreadsheets lacking adequate inventory controls. A 2022 Department of Justice Office of Inspector General audit explicitly warned that gaps like these could result in the loss of assets.

Is the US prepared to hodl?

The stakes of these operational gaps have risen because US policy is shifting.

The White House has moved to establish a Strategic Bitcoin Reserve and a separate Digital Asset Stockpile, with directives for the Treasury to administer custodial accounts where Bitcoin “shall not be sold.”

That policy change shifts the government’s role from a temporary custodian, historically associated with auctions and evidence disposal, to a long-term holder.

For years, the crypto markets treated the US government’s stash as a potential supply overhang, a source of latent selling pressure if seized coins were liquidated.

Related Reading

US government has now lost $21 billion selling seized Bitcoin we once fought to freeze

Bitcoiners once wanted to freeze gov coins, now they cheer hoarding seized assets.

Jun 2, 2025 · Liam 'Akiba' Wright

However, the strategic reserve framing shifts the lens, as the central question becomes custody credibility.

If Bitcoin is to be treated as a reserve asset analogous to gold, the standard investors will implicitly demand is vault-grade security, clear custodianship, consistent controls, and auditable procedures.

So, this alleged $40 million theft draws attention back to whether the infrastructure supporting this ambition still resembles an ad hoc evidence workflow or is being scaled for long-term stewardship.

This is because a large, well-known government Bitcoin hoard could become a prime target for malicious actors seeking to exploit a porous system. Crypto analyst Murtuza Merchant said:

The post Security of the US government’s $28B Bitcoin reserve threatened after weekend theft reveals flaw appeared first on CryptoSlate.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Three dormant wallets, suspected to belong to the same entity, purchased 5,970 ETH eight hours ago.

Three dormant wallets, suspected to belong to the same entity, purchased 5,970 ETH eight hours ago.

PANews reported on February 4 that, according to Lookonchain monitoring, three wallets that had been dormant for four years (likely controlled by the same entity
Share
PANews2026/02/04 11:36
NVIDIA Stock Price Analysis as OpenAI Issues Concerns About its Chips

NVIDIA Stock Price Analysis as OpenAI Issues Concerns About its Chips

Key Insights NVIDIA stock started the week in the red. It crashed by over 2%. Meanwhile, the S&P 500, Dow Jones, and Nasdaq 100 moved close to their all-time highs
Share
Themarketperiodical2026/02/04 11:27
Ondo Finance Launches USDY Yieldcoin on Stellar, Bringing Tokenized U.S. Treasuries to Users

Ondo Finance Launches USDY Yieldcoin on Stellar, Bringing Tokenized U.S. Treasuries to Users

Ondo Finance, a U.S.-based digital asset firm specializing in bringing traditional financial products on-chain through tokenization, is expanding its yieldcoin USDY to the Stellar network. This lates update marks a step forward in merging tokenized real-world assets with a global payments infrastructure, unlocking new opportunities for users worldwide. The announcement was made at the Stellar Meridian event in Copacabana, Rio de Janeiro, on September 17. USDY Joins the Stellar Ecosystem Ondo Finance, a recognized leader in tokenized real-world assets, announced the deployment of United States Dollar Yield (USDY) on Stellar, the payments-focused blockchain known for speed and low transaction costs. USDY is the most widely available “yieldcoin,” offering investors access to onchain assets backed by U.S. Treasuries. This launch allows Stellar’s global user base to tap into permissionless, yield-bearing assets tied to one of the safest financial instruments in the world. It also aligns with Stellar’s mission of driving fast, affordable cross-border payments. Combining Yield with Payments Infrastructure “Stablecoins unlocked global access to the U.S. dollar. With USDY, we’re taking the next step by bringing U.S. Treasuries onchain in a form that combines stability, liquidity, and yield,” said Ian De Bode, Chief Strategy Officer at Ondo Finance. “Fast, affordable cross-border payments are at the center of what Stellar was designed to do. The global reach of the Stellar ecosystem combined with a yield-bearing asset like USDY levels up what is possible onchain, allowing wallets and businesses to offer yield opportunities to their users,” said Denelle Dixon, CEO of the Stellar Development Foundation. Ondo claims by pairing USDY with Stellar’s infrastructure, new possibilities open up in treasury management, collateralization, and everyday financial applications. Unlocking Institutional and Retail Use Cases USDY currently manages over $650 million in total value locked (TVL) across nine blockchains and offers a 5.3% APY. By launching on Stellar, Ondo Finance extends these benefits to global retail and institutional users. The firm explains balances on Stellar can now become productive, supporting use cases such as onchain savings, institutional treasury strategies, cost-efficient collateral for DeFi protocols, and remittance flows that carry yield rather than remaining static. A Milestone for Tokenized Treasuries With the integration of USDY, Stellar users gain more than just access to stable-value assets—they gain access to institutional-grade yield. For investors outside the U.S., the launch represents a new way to combine the safety of Treasuries with the accessibility of blockchain technology. As tokenization accelerates globally, Ondo Finance’s decision to deploy USDY on Stellar reinforces the narrative that blockchain is not just about speculation, but about reimagining the global financial system through secure, yield-bearing digital assets
Share
CryptoNews2025/09/18 00:46