A supervisory FBI counterintelligence agent has been charged with a crypto theft worth close to $1 million, pulled from wallets tied to a nation the United States considers adversarial, according to a federal affidavit reported by The New York Times on Aug. 3, 2026.
Patrick Yaroch used passphrases obtained during an active investigation to move the funds across a dozen transfers starting in late 2024, then turned to ChatGPT to plan a new life in Europe. He was fired and arrested the day agents searched his Virginia home, and now faces federal charges for interstate transportation and receipt of stolen goods.
The Passphrases Yaroch Pulled From FBI Systems
Yaroch worked counterintelligence out of the FBI’s Boston division, tracking cryptocurrency wallets linked to the adversarial nation, The New York Times reported. Frustrated that the bureau would not let him disrupt the wallets, he used his top-secret clearance to memorize the passphrases and made 10 to 12 transfers into a personal wallet between late 2024 and early 2025, moving close to $1 million he told agents he never spent.
A search of his phone turned up months of ChatGPT conversations about investing the money and relocating to Portugal, Greece or Turkey, echoing how Decrypt has tracked chatbots surfacing in other crypto cases this year.
Yaroch had booked a round-trip flight to Portugal for September and signed power-of-attorney paperwork for two Portuguese lawyers before confessing to a Justice Department employee on July 28, saying the theft was “eating him up inside.”
What This Case Exposes About Seized Crypto Custody
U.S. agencies now custody billions in seized digital assets, and unlike a frozen bank account, a single passphrase can be enough to move everything out, a custody gap that keeps turning up across our main news feed as agencies expand their crypto holdings.
The Precedent Prosecutors May Point To
Yaroch is not the first person tied to U.S. crypto custody to face this kind of charge. In March 2026, CoinDesk reported that the son of a contractor managing seized crypto for the U.S. Marshals was arrested in France over an alleged $46 million theft from government wallets, prompting a review of seizure-key access.
Yaroch tapped a version of the same weakness: legitimate access turned to unauthorized ends. Kraken disclosed in April 2026 that support staff had misused internal credentials to view client data in a similar insider-access breakdown.
What This Means for You
If a federal agent can drain a monitored wallet with nothing more than a passphrase, the safety of crypto held by a third party comes down to that party’s internal controls, not the blockchain itself.
Assets on an exchange or in a custodial wallet are only as safe as the key management behind them. Cases like this are part of why many new holders eventually move toward self-custody, where fewer people ever touch the keys.
This article is for informational purposes only and does not constitute financial advice. Do your own research before making any investment decisions.


