FBI Crypto Theft Charges: $1M Case and Key Facts
Key Verified Facts

  • The FBI crypto theft charges were filed against Patrick Steven Yaroch, 41, a former FBI Supervisory Special Agent, in a criminal complaint filed July 31, 2026, in the U.S. District Court for the Eastern District of Virginia (Alexandria Division), Case No. 1:26-MJ-300.
  • Yaroch is charged with interstate transportation of stolen goods, securities, and monies (18 U.S.C. § 2314) and receipt of stolen goods, securities, and monies (18 U.S.C. § 2315).
  • Prosecutors allege he used FBI system access to obtain cryptocurrency seed phrases tied to wallets connected to an FBI counterintelligence investigation, then made roughly 10 to 12 transfers into a personal wallet beginning in late 2024 or early 2025.
  • The total value is described in court records as approximately $1 million, though the affidavit notes the funds were commingled with Yaroch’s personal assets, so the exact stolen amount is not precisely established.
  • The FBI recovered and transferred approximately $925,426.07 in cryptocurrency and cash-equivalent holdings into government-controlled accounts on July 31, 2026, after Yaroch signed a consent-to-seize form.
  • Yaroch self-reported to a Department of Justice colleague on July 28, 2026, was placed on administrative leave July 29, fired July 31, and arrested the same day.
  • This is a criminal complaint, not an indictment or a conviction. Yaroch has not entered a plea as of this writing, and he is presumed innocent unless and until proven guilty in court.

Introduction

The FBI crypto theft charges filed against former FBI Supervisory Special Agent Patrick Steven Yaroch have drawn attention across the cryptocurrency world this week. Prosecutors allege Yaroch used his access to FBI systems to obtain seed phrases for cryptocurrency wallets tied to a federal counterintelligence investigation.

According to a criminal complaint, Yaroch then transferred roughly $1 million in digital assets into a wallet he controlled.

Authorities say Yaroch self-reported his conduct to a Justice Department colleague before he was arrested. He now faces two federal charges tied to stolen property.

This case matters to crypto users well beyond the headlines. It touches on seed phrase security, insider access risk, and how law enforcement actually traces and recovers stolen digital assets — even when the person accused once worked inside the system meant to catch that kind of theft.


Table of Contents

  1. What Are the FBI Crypto Theft Charges?
  2. Who Is the Former FBI Agent?
  3. What Do Prosecutors Allege Happened?
  4. How Much Cryptocurrency Was Involved?
  5. How Were the Wallets Allegedly Accessed?
  6. What Is a Crypto Seed Phrase?
  7. Where Did the Cryptocurrency Go?
  8. How Can Stolen Crypto Be Traced?
  9. What the Case Means for Crypto Custody
  10. Security Lessons for Crypto Users
  11. Case Timeline
  12. Frequently Asked Questions

What Are the FBI Crypto Theft Charges?

The FBI crypto theft charges center on two federal statutes.

Yaroch is charged with interstate transportation of stolen goods, securities, and monies, under 18 U.S.C. § 2314. This law addresses moving stolen property, including money and financial instruments, across state lines.

He also faces a charge of receipt of stolen goods, securities, and monies, under 18 U.S.C. § 2315. This statute covers knowingly receiving or possessing property that was unlawfully taken.

Both charges were brought by criminal complaint, not a grand jury indictment. A complaint is an initial charging document supported by a sworn affidavit that establishes probable cause for arrest.

It’s an earlier procedural stage than an indictment. Prosecutors can still seek a formal indictment from a grand jury, and additional charges have been publicly discussed as possible but not yet filed.

Each charge carries a statutory maximum of up to 10 years in prison. That maximum does not predict any actual sentence, which would depend on a conviction or plea, sentencing guidelines, and a judge’s findings.


Who Is the Former FBI Agent?

Patrick Steven Yaroch, 41, worked at the FBI from approximately 2017 until his termination on July 31, 2026.

From 2017 to 2025, he was assigned to the FBI’s Boston Division, where he worked on a national security squad investigating an individual connected to a foreign adversarial nation.

Starting around February 2025, Yaroch became a Supervisory Special Agent at FBI Headquarters in the Counterintelligence and Espionage Division. He also worked as a detailee within the broader U.S. Intelligence Community.

He held a Top Secret security clearance with sensitive compartmented information (SCI) access since May 2017 — a high level of clearance tied to classified national security work.

Yaroch lived in Ashburn, Virginia. He was placed on administrative leave July 29, 2026, and the FBI terminated his employment two days later, on the same day he was arrested.

An FBI spokesperson said the agency “holds its employees to the highest ethical standards” and that the conduct alleged “is not tolerated at the FBI.” The bureau said it is conducting a thorough investigation and, as an ongoing matter, would have no further comment.

A federal public defender representing Yaroch has declined to comment publicly on the case.


What Do Prosecutors Allege Happened?

According to the criminal complaint, the case traces back to Yaroch’s counterintelligence work in Boston.

Alleged early exposure. Around November 2024, while investigating a subject tied to an adversarial foreign nation, Yaroch was allegedly exposed to that individual’s cryptocurrency accounts. Court records describe him telling colleagues he became “frustrated” that the FBI “could not or would not act” against those accounts.

Alleged access and transfers. Prosecutors allege that starting in late 2024 or early 2025, Yaroch searched FBI holdings for information on the adversarial cryptocurrency accounts and memorized their seed phrases. He then allegedly created a personal wallet and transferred funds from the monitored accounts into it, roughly 10 to 12 times.

Alleged self-report. On July 28, 2026, Yaroch contacted a Department of Justice National Security Division employee over Signal, requesting a private meeting. According to the affidavit, when they met the next day at FBI Headquarters, Yaroch became emotional and admitted to what he described as “very poor decisions related to cryptocurrency wallets.”

Investigation and arrest. FBI agents searched Yaroch’s Ashburn residence on July 31, 2026, under a warrant. He was arrested that day and taken to the Alexandria Detention Center.

It’s important to underscore that these remain allegations. Yaroch has not been convicted of any crime, and under the U.S. legal system he is presumed innocent unless proven guilty in court.


How Much Cryptocurrency Was Involved?

Court records describe the value of the wallet Yaroch allegedly controlled as approximately $1 million.

The affidavit is explicit that this figure isn’t precise: Yaroch told investigators he didn’t know the exact amount, because the allegedly stolen funds were commingled with his own personal assets, including capital gains from other investments.

The affidavit also notes that all dollar figures cited are “subject to change as the market price for cryptocurrency fluctuates,” since crypto values move constantly.

On July 31, 2026, after Yaroch signed a consent-to-seize form, the FBI’s cryptocurrency team transferred funds out of accounts under his control. The total value of everything transferred into government-controlled wallets that day was approximately $925,426.07.

Separately, about $165,582.49 in U.S. dollars remained in Yaroch’s Kraken account because it was cash, not cryptocurrency, and couldn’t be moved into a government-controlled crypto wallet using the same process.

Prosecutors have not alleged that the recovered figure represents the complete amount originally taken — only what was located and seized at the time of the search.


How Were the Crypto Wallets Allegedly Accessed?

At a high level, court records describe an insider-access scenario rather than a technical hack of any blockchain or exchange.

Yaroch, in his role investigating a foreign intelligence target, allegedly had access to FBI case holdings that included cryptocurrency wallet recovery information connected to that investigation.

According to the affidavit, he researched how cryptocurrency wallets work, learned that a recovery phrase is needed to move funds out of an account, and then allegedly memorized recovery phrases associated with the monitored accounts rather than writing them down at the time.

He then, prosecutors allege, created his own wallet and used that memorized information to move funds into it over multiple separate transfers.

This article does not detail the specific technical steps described in the complaint beyond this level, because doing so would not add legitimate educational value and could be misused. The relevant lesson for crypto users is about who has access to recovery information and how that access is controlled — covered further below.


What Is a Crypto Seed Phrase?

A seed phrase (sometimes called a recovery phrase) is a series of words — typically 12, 15, 20, or 24 — generated when a cryptocurrency wallet is created.

It functions as the master key to that wallet. Anyone who has the seed phrase can restore full access to the wallet’s funds on any compatible device, regardless of who currently holds the device the wallet was originally set up on.

That’s precisely why seed phrase security is treated as the single most important safeguard in personal crypto custody.

A few essentials:

  • A seed phrase is different from a password. It can’t be reset or recovered through customer support if lost, and it can’t be changed if exposed — funds typically must be moved to a brand-new wallet instead.
  • Anyone with your seed phrase has your funds. There’s no additional identity check once someone has entered a valid seed phrase into compatible wallet software.
  • Legitimate platforms never ask for it. No real exchange, wallet provider, or support representative will ever legitimately request a seed phrase over chat, email, or phone. Any message asking for one is a scam attempt.
  • A passphrase is a separate, additional feature. Some wallets support an optional extra passphrase on top of the seed phrase, which derives a completely different set of addresses. It adds a layer of protection but is not the same thing as the seed phrase itself.

The affidavit in this case specifically notes that Yaroch used the term “passphrase” imprecisely, and that investigators believe he was actually referring to seed phrases throughout.


Where Did the Cryptocurrency Reportedly Go?

Court records describe funds moving through two platforms: Kraken, a centralized cryptocurrency exchange, and Suilend, a decentralized finance (DeFi) lending protocol built on the Sui blockchain, accessed through a wallet application called Slush.

Kraken is a long-established, U.S.-registered centralized exchange that requires identity verification (KYC) for account holders. Investigators located Yaroch’s Kraken account, which held a mix of U.S. dollars, USD Coin (USDC), a small amount of Bitcoin, and other token balances.

Suilend is a DeFi lending protocol on the Sui blockchain, which lets users deposit crypto assets to earn yield. Access to a DeFi protocol like Suilend is generally handled entirely through a self-custody wallet — in this case, Slush — rather than through an exchange account.

It’s worth stating clearly: the fact that funds allegedly passed through Kraken or Suilend does not imply either platform did anything wrong. Both are legitimate, widely used services. Court records describe Yaroch using them the way any user would — Kraken as a regular exchange account, and Suilend as a place to deposit and earn yield on funds he already controlled. Neither platform is accused of facilitating theft or failing to follow its own procedures.


How Can Stolen Cryptocurrency Be Traced?

Cryptocurrency is often described as anonymous, but that’s a misconception. Most major blockchains, including Bitcoin, Ethereum, and Sui, are pseudonymous and fully public — every transaction is permanently recorded and viewable by anyone.

This is the foundation of blockchain tracing, sometimes called on-chain forensics or blockchain investigation.

Key elements investigators and blockchain analytics firms use:

  • Public wallet addresses. Every transaction is tied to sender and receiver addresses that anyone can view on a block explorer.
  • Transaction timestamps. Every transfer is timestamped and permanently recorded, creating an exact chronological record.
  • Address clustering. Analytics tools can often group addresses that behave as though they’re controlled by the same person or entity, based on transaction patterns.
  • Exchange KYC records. When funds move onto a regulated, KYC-compliant exchange like Kraken, that exchange holds identity information tied to the receiving account — which is exactly how this case became traceable once funds reached Yaroch’s own accounts.
  • Blockchain analytics platforms. Specialized firms build tools that map transaction flows across many addresses and blockchains, often used by law enforcement and compliance teams.

In this particular case, court records indicate the investigation did not begin with blockchain analytics identifying suspicious activity. It began with Yaroch’s own decision to self-report. But once his accounts were identified, agents were able to review his Kraken and Suilend holdings directly and calculate their value.

The broader lesson stands regardless: pseudonymous does not mean untraceable. Funds that move through any KYC-compliant exchange create an identity-linked record, and even funds that stay in self-custody remain permanently visible on a public ledger.


What the Case Means for Government and Institutional Crypto Custody

This case raises real questions about how sensitive cryptocurrency holdings — whether held by a government agency, a company, or any organization — should be secured against insider risk, not just outside hackers.

It’s important to be precise here: publicly available court records in this case do not specify exactly what internal controls the FBI had in place for evidence-linked cryptocurrency wallets, or which of those controls may or may not have functioned as intended. This article does not claim the FBI lacked any specific safeguard — only that the case illustrates why these controls matter broadly across institutional crypto custody.

Common institutional safeguards include:

  • Multi-signature wallets, which require multiple independent approvals before any transaction can be sent, so no single person can move funds alone.
  • Segregation of duties, ensuring the person who can view sensitive wallet information isn’t the same person able to authorize transfers.
  • Access logging, creating an audit trail of exactly who viewed sensitive credential information and when.
  • Withdrawal allowlists, restricting outgoing transfers to a pre-approved list of destination addresses.
  • Offline credential storage, keeping seed phrases and private keys away from systems that any single employee can access digitally.
  • Blockchain monitoring and alerts, flagging unexpected outbound transactions in near real time.

A case like this doesn’t necessarily mean any particular organization’s controls failed — it’s a reminder that any entity holding cryptocurrency on behalf of others, including a government evidence function, benefits from layered, multi-person controls rather than relying on any single individual’s access and integrity alone.


What Crypto Users Can Learn From the Case

Most crypto users will never face insider-access risk from a federal investigator. But the underlying lesson — that whoever holds the seed phrase controls the funds — applies to everyone.

  • Treat your seed phrase like the only key to a vault that can never be re-keyed. If it’s exposed, funds should be moved to a new wallet as soon as possible.
  • Never store a seed phrase digitally in plain text — not in a phone note, email, cloud photo, or password manager screenshot, unless that manager is specifically built and encrypted for this purpose.
  • Use a hardware wallet for significant holdings. It keeps private keys isolated from an internet-connected device.
  • Be skeptical of anyone claiming institutional authority who asks for wallet access. In this case, Yaroch had legitimate authorized access to sensitive FBI systems — a reminder that credentials and authority alone don’t guarantee good-faith use.
  • Monitor wallet and exchange activity regularly. Catching unauthorized transactions quickly limits potential losses.
  • Separate everyday spending wallets from long-term holdings, so a compromise of one doesn’t expose everything.

Case Timeline

  • 2017–2025: Yaroch works at the FBI’s Boston Division on a national security squad investigating an individual tied to an adversarial foreign nation.
  • November 2024: According to court records, Yaroch is exposed to adversarial cryptocurrency accounts during his investigative work.
  • Late 2024 / Early 2025: Prosecutors allege Yaroch begins transferring funds from monitored accounts into a personal wallet, eventually totaling roughly 10 to 12 transfers.
  • February 2025: Yaroch becomes a Supervisory Special Agent at FBI Headquarters’ Counterintelligence and Espionage Division.
  • May 28, 2026: Records show Yaroch asked ChatGPT how he might invest or spend approximately $1 million.
  • June 4, 2026: Records show Yaroch asked ChatGPT about relocating to an EU country with about $1 million, receiving a response referencing Portugal.
  • June 15, 2026: Power-of-attorney documents involving Portuguese legal representation are dated this day, according to the complaint.
  • July 28, 2026: Yaroch contacts a DOJ National Security Division employee via Signal, requesting a meeting.
  • July 29, 2026: Yaroch meets the DOJ employee at FBI Headquarters and allegedly admits to “very poor decisions related to cryptocurrency wallets.” He is placed on administrative leave the same day.
  • July 30, 2026: A magistrate judge authorizes search warrants for Yaroch’s person, residence, and vehicle.
  • July 31, 2026: FBI agents execute the search warrants at Yaroch’s Ashburn, Virginia home. He signs a consent-to-seize form; the FBI transfers approximately $925,426.07 in cryptocurrency and related holdings to government-controlled accounts. Yaroch is arrested and his employment is terminated the same day.
  • August 1, 2026: The criminal complaint and supporting affidavit are filed with the U.S. District Court for the Eastern District of Virginia.
  • August 4, 2026: A detention and preliminary hearing is scheduled in Alexandria, Virginia.
  • Ongoing: The case remains in its early procedural stages. Prosecutors have indicated additional charges are possible but have not specified what they might involve.

Frequently Asked Questions

What are the FBI crypto theft charges? The FBI crypto theft charges are two federal counts against former FBI Supervisory Special Agent Patrick Steven Yaroch: interstate transportation of stolen goods, securities, and monies, and receipt of stolen goods, securities, and monies, filed by criminal complaint in the Eastern District of Virginia.

Who was charged? Patrick Steven Yaroch, 41, a former FBI Supervisory Special Agent who worked in the bureau’s Counterintelligence and Espionage Division and previously in its Boston Division.

How much cryptocurrency was allegedly involved? Court records describe the value as approximately $1 million, though the exact figure is uncertain because the funds were reportedly commingled with Yaroch’s personal assets. The FBI recovered and transferred approximately $925,426.07 into government-controlled accounts.

What charges were filed? Interstate transportation of stolen goods, securities, and monies (18 U.S.C. § 2314) and receipt of stolen goods, securities, and monies (18 U.S.C. § 2315), each carrying a statutory maximum of up to 10 years in prison.

Was Bitcoin involved? Court records mention a small Bitcoin balance in Yaroch’s Kraken account, but the bulk of the funds described involve other cryptocurrencies and stablecoins, along with U.S. dollar holdings.

What is a crypto seed phrase? A seed phrase is a set of words generated by a cryptocurrency wallet that acts as its master recovery key. Anyone who has it can fully control the associated funds, which is why it must never be shared or stored insecurely.

Can stolen crypto be traced? Yes. Public blockchains record every transaction permanently, and funds that move onto a regulated, identity-verified exchange create a traceable link between an account and its holder. Pseudonymous does not mean untraceable.

Was the cryptocurrency recovered? Authorities recovered and transferred approximately $925,426.07 into government-controlled accounts on July 31, 2026, with an additional $165,582.49 in U.S. dollars remaining in a Kraken account. Prosecutors have not said this represents the full amount originally alleged to have been taken.

Why does crypto custody security matter? Because whoever controls a wallet’s seed phrase or private keys controls its funds, regardless of who owns them on paper. This case shows why institutions holding cryptocurrency need layered controls — not reliance on any single person’s access.

What happens next in the case? Yaroch had a detention and preliminary hearing scheduled for August 4, 2026. The case may proceed toward a grand jury indictment, additional charges, or a negotiated resolution. As of this writing, no plea has been entered, and Yaroch remains presumed innocent unless proven guilty in court.


Security-Control Table

Security ControlWhat It Protects AgainstIndividual UseInstitutional Use
Offline seed storageCredential theftYesYes
Hardware walletOnline compromiseYesUseful
Multi-signature walletSingle-person controlOptionalImportant
Access loggingInsider misuseLimitedImportant
Withdrawal allowlistUnauthorized transfersUsefulImportant
Multiple approvalsInsider riskOptionalImportant
Blockchain monitoringUnexpected transactionsUsefulImportant

For an individual crypto holder, offline seed storage and a hardware wallet cover most realistic threats. For an institution safeguarding assets on behalf of others — including a government agency, exchange, or fund — the controls that limit any single person’s unilateral access (multi-signature approval, access logging, segregation of duties) become far more important, precisely because insider risk can’t be solved by device security alone.


Crypto Asset-Flow Table

StageReported EventApproximate ValueVerification Source
Original monitored walletsSeed phrases allegedly obtained and used to transfer funds~$1 million (approximate, per affidavit)Criminal complaint affidavit
Personal wallet~10–12 alleged transfers beginning late 2024/early 2025~$1 millionCriminal complaint affidavit
Kraken accountBalance found during July 31, 2026 search~$188,570.58Criminal complaint affidavit
Suilend (via Slush wallet, Sui blockchain)DeFi account balance found during search~$933,756.73Criminal complaint affidavit
Recovered/transferred to U.S. government walletsConsent-based seizure, July 31, 2026~$925,426.07Criminal complaint affidavit
Remaining in Kraken (USD, not transferable to crypto wallet)Cash balance left in exchange account~$165,582.49Criminal complaint affidavit

Crypto Wallet Security Checklist

  1. Never disclose your seed phrase.
  2. Store recovery information offline.
  3. Use a reputable hardware wallet for significant holdings.
  4. Enable strong two-factor authentication on exchanges.
  5. Avoid SMS authentication where stronger methods are available.
  6. Use withdrawal address allowlisting where supported.
  7. Review wallet transactions regularly.
  8. Treat unsolicited wallet-support messages as suspicious.
  9. Never enter a seed phrase into a website reached through an ad or unsolicited message.
  10. Separate long-term holdings from everyday transaction wallets.
  11. Use multi-signature custody for large organizational holdings where appropriate.
  12. Monitor unexpected transactions quickly.

This article is for informational and educational purposes only and does not constitute legal advice. All individuals mentioned are presumed innocent unless and until proven guilty in a court of law. This article will be updated as the case develops.


External Sources and Further Reading

  • Criminal complaint and supporting affidavit, United States v. Patrick Steven Yaroch, Case No. 1:26-MJ-300, U.S. District Court for the Eastern District of Virginia — filed August 1, 2026 — https://storage.courtlistener.com/recap/gov.uscourts.vaed.602203/gov.uscourts.vaed.602203.2.0.pdf
  • CoinDesk — “U.S. FBI intelligence agent arrested in connection with theft of $1 million in crypto” — published August 3, 2026 — https://www.coindesk.com/policy/2026/08/03/u-s-fbi-intelligence-agent-arrested-in-connection-with-theft-of-usd1-million-in-crypto
  • Decrypt — “Former FBI Agent Charged With Stealing Nearly $1 Million in Crypto and Using ChatGPT for Investment Advice” — published August 2026 — https://decrypt.co/374871/former-fbi-agent-charged-stealing-crypto-using-chatgpt-advice
  • NBC News — “Feds charge ‘frustrated’ FBI agent they say stole nearly $1 million in crypto from Russia” — published August 2026 — https://www.nbcnews.com/politics/justice-department/feds-charge-fbi-agent-say-stole-nearly-one-million-crypto-russia-rcna590674
  • AMBCrypto — “FBI crypto theft charges: Former agent accused of stealing nearly $1 million from investigation-linked wallets” — updated August 3, 2026 — https://ambcrypto.com/fbi-crypto-theft-charges-former-agent-accused-of-stealing-nearly-1-million-from-investigation-linked-wallets/

a