Skip to main content
Sign in

John Daghita (aka Lick) — US Marshals Crypto Theft

avoid.net/john-daghita-aka-lick-us-marshals-crypto-theft0/100·95% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Summary

John Daghita, a 21-year-old Virginia resident known online as 'John' or 'Lick,' was arrested in March 2026 on the Caribbean island of Saint Martin and subsequently indicted on 15 federal counts including wire fraud, theft of government property, and money laundering. He is alleged to have stolen more than $46 million in cryptocurrency from U.S. Marshals Service seizure wallets between December 2025 and January 2026, exploiting access derived from his father Dean Daghita's role as president of CMDSS, a government contractor holding a $4 million USMS custody contract. The case was initially surfaced not by federal investigators but by blockchain investigator ZachXBT after Daghita allegedly exposed his wallet holdings during an online 'band-for-band' dispute.

Have evidence about John Daghita (aka Lick) — US Marshals Crypto Theft?

Timeline(12 events)

2024-03-01

Wallet address 0xc7a2 allegedly received $24.9 million from a U.S. government address tied to the 2016 Bitfinex hack seizure, per ZachXBT on-chain analysis.

CoinDesk — A crypto flex gone wrong

2024-10-01

CMDSS (Command Services & Support), owned by Dean Daghita, awarded a ~$4 million U.S. Marshals Service contract for custody and disposal of Class 2-4 seized digital assets.

CoinDesk / Forbes

2025-12-15

John Daghita allegedly initiates three transfers totaling approximately $5 million from USMS-controlled wallets to wallets he personally controlled — the first alleged theft transactions per the indictment.

Mike Levine on X / Decrypt

2026-01-22

USMS instructs CMDSS to return approximately $2 million in virtual currency to a USMS-owned address. Approximately 20 minutes later, Daghita allegedly diverts the assets to a non-USMS address instead.

Mike Levine on X

2026-01-23

During an online 'band-for-band' exchange, a participant using the handle 'John' or 'Lick' screen-shares wallet balances and moves approximately $23 million live; ZachXBT observes the recorded session and traces the wallets to U.S. government seizure addresses. An additional $41 million in transfers alleged to have occurred on January 22-23.

CoinDesk

2026-01-26

ZachXBT publishes findings publicly identifying the 'John/Lick' persona as John Daghita and alleging the son of a USMS contractor executive stole more than $40 million in government cryptocurrency. U.S. Marshals Service confirms investigation.

CoinDesk

2026-01-01

Wallet linked to the alleged theft deploys $LICK meme coin on Pump.fun (Solana). The token collapses approximately 97% within 24 hours. Pump.fun removes the ticker.

Yahoo Finance / CryptoPotato

2026-03-04

John Daghita arrested at Villa Sun Reset on the island of Saint Martin by French Gendarmerie elite tactical unit in collaboration with the FBI Washington Field Office. Seized items include $239,348 in cash, a Rolex GMT Master, and multiple hardware wallets.

FBI Washington Field Office / Fox News

2026-03-05

FBI Director Kash Patel publicly announces arrest via X and shares photos of Daghita in custody and the seized suitcase of cash and hardware wallets.

FBI Washington Field Office on X

2026-03-26

Federal grand jury in Alexandria, Virginia, returns a 15-count indictment against John Daghita in the Eastern District of Virginia, charging wire fraud, theft of public money, money laundering, and unlawful monetary transactions.

Mike Levine on X / Decrypt

2026-05-21

Daghita appears before the indictment chamber of the Court of Appeal in Basse-Terre, Guadeloupe. He reportedly requests his own extradition to the United States, stating he wants to explain himself in U.S. courts. Magistrates reserve decision until May 28.

Dark Web Informer on X / Phemex News

2026-05-28

Basse-Terre Court of Appeal approves extradition of John Daghita to the United States.

CryptoAdventure
Provenance & Audit Trail
18 Wayback Archives

Decision Log

  • #1publish⛓ pending8/1/2026, 5:05:29 PM
    hash: 4FqVogcExXFKcRfEMfDTLiMsYVKn4LvpoBSRU5ArVi6g

18 of 21 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 8/1/2026, 5:04:59 PM

last updated: 8/1/2026, 6:52:21 PM

avoid.net — verified advice for a post-truth world