FBI Agent Stole $1M in Crypto Using Bureau's Own Intelligence Files, Court Documents Show
An insider with top-secret clearance exploited FBI surveillance databases to drain a target's cryptocurrency wallets, exposing critical vulnerabilities in how U.S. law enforcement handles sensitive cryptographic intelligence and raising serious questions about the separately troubled system for securing government-held seized digital assets.
Patrick Steven Yaroch, an FBI special agent based in Ashburn, Virginia, was fired and arrested on July 31, 2026, after federal investigators determined he had stolen approximately $1 million in cryptocurrency from a surveillance target. According to a court affidavit, Yaroch used his legitimate access to FBI investigative databases to retrieve access credentials used to unlock cryptocurrency wallets belonging to an individual from a country "the U.S. considers to be an adversary." He then transferred those funds into wallets he controlled through 10 to 12 separate transactions conducted between late 2024 and mid-2026. Agents recovered $925,426.07 from his accounts during a search of his home, a recovery rate of roughly 92.5%.
Yaroch had been assigned to a national security squad at the FBI's Boston field office. Court documents say he told investigators he had grown "frustrated at not being able to disrupt the target's cryptocurrency use" through legal channels, suggesting the scheme started as vigilantism before becoming straightforward theft. He confessed to a colleague on July 28, 2026, three days before his termination. He now faces federal charges for interstate transportation and receipt of stolen goods, securities, and monies. The Department of Justice did not respond to a request for comment by the time of publication.
ChatGPT as a Paper Trail
Investigators found that Yaroch had turned to ChatGPT for exit planning. In May 2026, he asked the AI chatbot: "If I had a million dollars, how would you suggest investing it/spending it to maximize profit and return." On June 4, he followed up with: "If you had a bucket of money (around $1 million) and you wanted to leave the USA and become a resident or citizen of an EU country, what would you do?" ChatGPT repeatedly recommended Portugal. Yaroch subsequently booked flights to Portugal for himself, his wife, and child in September 2026, obtained power of attorney documents from two Portuguese lawyers, and began the process of establishing a Portuguese tax identification number. Portugal's Non-Habitual Resident residency program and Grenada's citizenship-by-investment scheme are well known in cryptocurrency circles for welcoming large-capital relocations, and law enforcement agencies are equally aware of their appeal to individuals seeking rapid offshore establishment. Additional queries in June covered visa requirements for Americans transiting through Turkey and drafting a job inquiry for a position in Greece. Court records also show three unreported overseas trips to Germany, Portugal, and Grenada. The AI chat logs now form part of the evidentiary record in the case, which appears to have been filed in the Eastern District of Virginia.
The Yaroch case highlights a broader forensic development: AI platform data retention policies and cross-border legal data requests have become an active front in criminal investigation. For users in jurisdictions with limited data sovereignty protections, AI chat logs can be retrieved and admitted as evidence, in some contexts without a warrant, making popular chatbot platforms a significant and underappreciated source of investigative material.
A Pattern, Not an Anomaly
The Yaroch case is the third significant insider theft from U.S. government crypto holdings in roughly 20 months. In December 2025, John Dean Daghita, son of the CEO of CMDSS (the contractor managing seized crypto for the U.S. Marshals Service), allegedly transferred approximately $5 million in government-held digital assets to wallets he controlled. Before that, in October 2024, about $20 million was drained from U.S. Marshals wallets; most was recovered quickly, but around $700,000 routed through instant exchanges was never recovered.
These incidents sit against a troubling backdrop. The U.S. government currently holds approximately $28 billion in Bitcoin and other seized digital assets under fragmented custodial arrangements. Executive Order 14233, signed March 6, 2025, requires all forfeited Bitcoin to be held in a Strategic Bitcoin Reserve rather than auctioned, concentrating those holdings further. Security researchers at Chainalysis and other firms have consistently flagged the absence of multi-signature wallet controls (arrangements requiring multiple authorized parties to approve any transaction), independent audits, and real-time blockchain monitoring as structural gaps. Blockchain transparency worked in the government's favor this time: Yaroch's on-chain transfers were traceable, and most of the funds were recovered. He apparently made no effort to obscure the trail through mixing services or cross-chain transfers, which more sophisticated actors routinely use. The type of cryptocurrency involved has not been specified in court documents.
What This Means Outside the United States
For crypto users and regulators in South Asia and Africa, this case is more than a cautionary tale about a rogue federal employee. The affidavit's reference to an "adversarial nation" target, combined with the Boston field office's national security focus, suggests to analysts that wallet credentials and blockchain activity tied to U.S. surveillance investigations may already exist in government databases. Those databases have now proven vulnerable to insiders. Users in jurisdictions subject to U.S. sanctions monitoring face a compounded risk: not only can their activity be surveilled, but the records of that surveillance can be exploited.
India is a notable case in point. The country remains in a regulatory grey zone, with the Reserve Bank of India opposing legalization while the Securities and Exchange Board of India pushes a securities-based framework. In January 2026, India's Financial Intelligence Unit (FIU-IND) updated its anti-money laundering and counter-terrorism financing guidelines to include stricter know-your-customer requirements, along with a ban on mixer protocols and anonymous tokens. Given India's scale as one of the world's largest retail crypto markets, the question of how Indian regulators store and secure cryptographic intelligence carries significant weight for tens of millions of users.
Pakistan launched a dedicated FIA Cryptocurrency Investigation Unit in July 2026, the same month as Yaroch's arrest, as part of its broader Virtual Assets Act 2026. Africa's on-chain economy grew 52% year-on-year to reach $205 billion in 2026, with Nigeria's 25.9 million crypto users leading the continent's adoption surge. The Africa angle carries an additional dimension: OpenAI has shut down Cambodia-linked ChatGPT accounts used in cryptocurrency investment scams targeting African and Asian users, a development that ties the AI forensic thread directly to the concerns of African readers and reinforces the point that AI platform data is now central to crypto crime investigation worldwide. Both regions are building regulatory frameworks for government seizure and custody of digital assets. The Yaroch and Daghita cases make one thing clear: the weakest point in crypto custody is not the cryptography. It is the people and institutions sitting above it. Any national custody regime that does not embed multi-party controls and independent audit trails from the start is building toward the same failure.
Global illicit crypto flows reached $154 billion in 2025, up 162% year-on-year according to Chainalysis's 2026 Crypto Crime Report. Stablecoins now account for 84% of those transactions. Chainalysis data shows that 85% of U.S. law enforcement agencies now use blockchain analytics tools, reflecting the considerable institutional investment the country has made in pursuing illicit crypto activity. North Korea-linked actors alone stole more than $2 billion in cryptocurrency in 2025, illustrating the scale and sophistication of the adversarial threat that U.S. surveillance infrastructure is built to counter. The Yaroch case shows that the intelligence gathered in pursuit of those threats is itself a target.