A former supervisory FBI agent, Patrick Steven Yaroch, has been charged after prosecutors said he used internal agency systems to obtain credentials for cryptocurrency wallets linked to an adversarial country and then routed funds to his own accounts. The case, detailed in a U.S. federal court filing, highlights how quickly sensitive access credentials can become a direct vector for financial theft in the crypto era.
According to the filing referenced in court documents, Yaroch admitted to 10 unauthorized transfers carried out between late 2024 and early 2025, involving an estimated total of about $1 million in digital assets. Prosecutors said some of the stolen funds were deposited into Suilend to generate yield.
Key takeaways
- Prosecutors allege Yaroch used FBI internal systems to obtain wallet credentials tied to an adversarial country.
- Yaroch admitted to 10 unauthorized crypto transfers between late 2024 and early 2025, totaling roughly $1 million.
- Authorities reportedly recovered devices, seed phrases, and a Trezor wallet used to access accounts on Suilend and on the Kraken exchange.
- Roughly $925,000 was transferred to government-controlled wallets with Yaroch’s cooperation.
- The filing also describes Yaroch using ChatGPT for investment-related advice in May, underscoring the role of opportunistic decision-making amid ongoing access misuse.
Unauthorized wallet access and yield strategy
The court filing says Yaroch’s actions centered on obtaining the ability to access cryptocurrency wallets associated with an adversarial state and using those credentials to move funds to his own crypto wallets. The alleged scheme did not stop at transferring assets—prosecutors say he also placed at least some of the proceeds into Suilend to earn yield.
By admitting to the transfers, Yaroch effectively confirmed that the conduct was not limited to a one-time theft. The admissions, which prosecutors characterize as a sequence of unauthorized moves spanning several months, indicate he maintained control long enough to interact with decentralized finance infrastructure rather than simply cashing out immediately.
The court documents also describe that after Yaroch self-reported the incident, he was placed on administrative leave, later terminated, and then arrested within days.
How investigators say the scheme was executed
Authorities reportedly retrieved multiple items from Yaroch’s Virginia residence, including devices, seed phrases, and a Trezor wallet. Prosecutors said these materials were used to access accounts on Suilend and a crypto exchange, Kraken.
In the course of the case, investigators moved roughly $925,000 in funds into government-controlled wallets with Yaroch’s cooperation. That figure is important for investors and builders to understand: when access to wallet infrastructure and recovery material exists, the “blast radius” can be quickly reduced if authorities can act fast and gain control of the relevant custody or recovery pathways.
While the filing provides the core mechanics of access and recovery, it also implicitly underscores a broader risk for crypto systems: credential theft can be as damaging as direct hacking. If internal credentials are compromised—whether by insiders or those who obtain privileged access—the attacker’s path to funds can be short and highly efficient.
ChatGPT appears in the timeline
Prosecutors say that in May, Yaroch used ChatGPT for advice after posing a scenario about having “a million dollars” and asking how to invest or spend to maximize profit and return. The filing attributes a specific response to ChatGPT about “building a slower-living vineyard/agricultural lifestyle in places like Cilento or Portugal’s Dão region.”
Even though the exchange itself is not a prosecution theory of how the theft occurred, its inclusion in the court filing paints a picture of decision-making during a period when Yaroch had already—or soon after—secured access to assets he could control. For readers, the key takeaway is not the AI recommendation; it is the fact that illicit access can coexist with attempts to rationalize next steps using whatever tools are available.
A pattern of agent-linked crypto theft
This case adds to a small but notable series of prosecutions in which federal officials and agents are accused of misusing crypto access for personal gain.
Earlier, in 2015, former DEA special agent Carl M. Force diverted about $700,000 in Bitcoin before pleading guilty and receiving a six-and-a-half-year prison sentence, according to a DOJ statement referenced in the coverage. That case was linked to the investigation involving the dark net marketplace Silk Road.
The DOJ similarly reported that former U.S. Secret Service special agent Shaun W. Bridges stole about $350,000 in BTC in 2015, then pleaded guilty and was sentenced to six years in prison. Like the Force case, it was tied to the Silk Road investigation.
In this context, the Yaroch matter appears less like an isolated “crypto crime” and more like a recurrence of a specific vulnerability: when law-enforcement-linked access overlaps with crypto custody mechanisms—wallets, seeds, exchange accounts, and yield platforms—there is an opportunity for misuse that can be difficult to detect until after damage is done.
Earlier coverage from Cointelegraph highlighted “fake police raid” tactics connected to a $1M Bitcoin transfer, illustrating how both insider and external coercion routes have been used to move large crypto balances. Taken together, these stories suggest that crypto theft continues to evolve along two parallel tracks: technical attacks and social/credential abuse, sometimes involving high-access individuals.
What to watch next
With the alleged transfers spanning late 2024 through early 2025 and authorities already moving a large portion of funds into government control, the immediate focus will likely shift to how the court evaluates Yaroch’s admissions, the role of credential misuse, and the extent of any additional assets or counterparties involved. For crypto market participants, the practical lesson remains clear: insider credential access and wallet recovery material can convert administrative or investigative power into direct custody of funds, making rapid investigation and wallet-level response essential.





Be the first to comment