Skip to content

Independent intelligence on digital money in motion

Monday, August 24, 2026

Latest SBI Leads Fasset Series C as Stablecoin Banking Plans Expand
Regulation

Former FBI Supervisor Charged in Alleged $1M Crypto Wallet Theft

A federal complaint alleges an FBI supervisor used wallet credentials found in internal systems to move roughly $1 million in digital assets.

A former FBI supervisory special agent has been charged with transporting and receiving stolen property after investigators alleged that he used cryptocurrency wallet credentials found in internal government systems to move digital assets into wallets he controlled.

A criminal complaint filed August 1 in the US District Court for the Eastern District of Virginia identifies the defendant as Patrick Steven Yaroch. The supporting FBI affidavit says Yaroch told colleagues that he had made approximately 10 transfers beginning in late 2024 or early 2025 and that the value of the wallet involved was about $1 million.

The case is at the allegation stage. The filing establishes the government’s probable-cause theory; it is not a conviction or guilty plea. Yaroch is charged under federal statutes covering interstate transportation and receipt of stolen goods, securities and money. The adversarial country associated with the source wallets is not named in the public affidavit.

What the complaint alleges

According to the affidavit, Yaroch previously worked on counterintelligence matters involving the unnamed state. Investigators allege that he searched FBI holdings for information about cryptocurrency accounts, memorized seed phrases and used them to transfer assets from wallets associated with that state into a personal wallet.

The affidavit says Yaroch disclosed the conduct to a Justice Department employee and FBI personnel on July 29. He was placed on administrative leave that day, terminated on July 31 and arrested later on July 31 after agents executed search warrants at his Virginia residence.

During the search, agents recovered devices, a hardware wallet and a handwritten seed phrase. The filing says investigators reviewed a Kraken account and a Suilend position accessed through the Slush wallet application. With Yaroch’s written consent, the FBI transferred approximately $925,426 in digital assets from accounts he controlled to US government wallets.

The affidavit also says approximately $165,582 in US dollars remained in the Kraken account because fiat currency could not be transferred to a government-controlled cryptocurrency wallet. Investigators said personal and allegedly stolen assets had been commingled, so the account balances and recovered amount should not be read as a final calculation of criminal proceeds.

Nothing in the reviewed filing alleges wrongdoing by Kraken, Suilend, Slush or the maker of the hardware wallet. Their services appear in the affidavit as locations or tools investigators say were used to hold or access the assets.

The payments-control lesson is privileged access

For payment companies and digital-asset custodians, the central operational issue is not the particular wallet applications named in the complaint. It is the allegation that one trusted insider could obtain high-value wallet secrets from internal systems and use them outside the authorized investigative process.

That fact pattern highlights why seed phrases and private keys require controls comparable to, and often stricter than, credentials for high-value payment systems. Access should be narrowly scoped, logged and reviewed, while recovery or transfer actions should require independent authorization. Where operationally possible, institutions can reduce single-person control through hardware security modules, multiparty computation, transaction policies and dual approval.

On-chain visibility can help after funds move, but it does not replace preventive controls. Monitoring programs need to connect wallet activity with employee access logs, case authorization and approved destination addresses. Alerts are more useful when investigators can determine not only that a transfer occurred, but whether the person accessing the underlying secret had a current business need and whether a second authorized party approved the action.

The recovery described in the affidavit also illustrates a boundary between crypto and conventional money controls. Agents could transfer digital assets to government wallets, while US-dollar balances remained at the exchange. Incident plans therefore need coordinated procedures for blockchain transfers, custodial account restrictions, fiat holds and preservation of evidence across multiple service providers.

What remains unresolved

The complaint does not provide a final accounting that separates Yaroch’s personal assets from the allegedly stolen assets. It also does not identify the source country, list every token transferred or resolve the case’s legal outcome. Those questions will depend on later court filings and evidence.

For the industry, the immediate takeaway is narrower: organizations that handle wallet secrets on behalf of customers, governments or counterparties need controls designed for misuse by authorized insiders, not only theft by outside attackers. The allegations show how credential access, personal custody tools and cross-platform movement can combine into one incident-response problem.