A supervisory FBI special agent with top-secret security clearance allegedly stole approximately $1 million in cryptocurrency from wallets the agency had investigated, then confessed to colleagues before being fired and arrested. Patrick Steven Yarmoch, who worked in counterintelligence at FBI headquarters in Washington, allegedly made as many as a dozen transfers to himself from accounts tied to foreign nationals he’d investigated, according to an August 1 filing with the U.S. District Court for the Eastern District of Virginia.
The court documents paint an unusual picture: a senior intelligence officer who’d spent years investigating an unnamed “adversary nation” apparently decided to dig through FBI systems for private keys, move the crypto to his own accounts, and then, shortly before getting caught, ask an AI chatbot how best to flee the country with a million dollars.
Yarmoch was suspended for two days, fired on July 31, and immediately arrested. He’s currently being held in detention in Alexandria, Virginia.
A Counterintelligence Career Ends With an AI Query About Portugal
Yarmoch’s resume reads like exactly the kind of person you’d trust with sensitive national security work. He’d held a top-secret clearance. He worked as a supervisory special agent in the FBI’s counterintelligence and espionage division at the agency’s Washington headquarters. Before that, he spent years in a Boston field office running national-security investigations focused on a specific adversary nation (which the court filing doesn’t name, though the framing suggests either China or Russia given the counterintelligence focus).
That career ended badly. According to the court filing, Yarmoch turned himself in to colleagues, admitting he’d extracted cryptocurrency keys from FBI systems and used them to transfer funds into accounts he controlled. The targets weren’t random. They were foreign individuals Yarmoch himself had investigated, people whose digital assets had presumably come under FBI scrutiny as part of counterintelligence operations.
The crypto moved through Kraken, one of the largest US exchanges, and through Suilend, a decentralized lending protocol on the Sui blockchain. Yarmoch allegedly accessed Suilend via a Slush wallet. The choice of infrastructure is notable: mixing a regulated, KYC-compliant exchange like Kraken with a permissionless DeFi protocol suggests either poor operational security for someone supposedly trained in covert work, or perhaps a misunderstanding of how traceable these systems actually are.
The most damning detail from the court filing involves Yarmoch’s computer and phone records. FBI investigators found recent queries to AI applications, including one that read: “If you had a bucket of money (around $1 million) and you wanted to leave the USA and become a resident or citizen of an EU country, what would you do?”
The AI apparently recommended Portugal. Investigators then discovered that Yarmoch had booked travel to Portugal for himself and his family for the following month. They also found records of recent trips to Germany, Portugal, and Grenada that Yarmoch hadn’t reported internally, a violation of FBI rules requiring agents to disclose foreign travel.
The Problem of Insider Access to Seized Crypto
This case highlights a growing tension in how law enforcement agencies handle seized or investigated cryptocurrency. When federal agents have access to private keys, wallet files, or seed phrases as part of their investigative work, the temptation to misuse that access exists in a way it simply doesn’t with traditional seized assets. You can’t slip a seized car into your garage and hope nobody notices. But digital assets are designed to be bearer instruments, and the same cryptographic properties that make them useful for legitimate holders make them vulnerable to anyone with key access.
The FBI hasn’t disclosed how Yarmoch allegedly obtained the private keys. The court filing refers to him digging them out of “FBI systems,” which suggests either poor compartmentalization of sensitive evidence, inadequate access controls, or perhaps that agents working on crypto-related cases simply have more access than they should.
For context, the FBI has been involved in major cryptocurrency seizures for years. The bureau played a central role in recovering Bitcoin from the Colonial Pipeline ransomware attackers in 2021. It’s been involved in countless dark-web marketplace takedowns where significant crypto holdings were seized. The Silk Road coins, the Bitfinex hack recovery, multiple North Korean theft recoveries, and these are just the headline cases. Less prominent investigations generate their own streams of seized or investigated digital assets.
If an agent with legitimate access to these systems could allegedly steal a million dollars before anyone noticed, it raises uncomfortable questions about custody controls. The court filing suggests Yarmoch made “as many as a dozen transfers” before turning himself in. That’s not a one-time lapse in judgment. It’s a pattern of behavior that apparently went undetected until he confessed.
North Korean hackers have extracted far larger sums from DeFi protocols this year, with over $500 million drained in April alone from Drift and Kelp exploits. The industry response has focused on improving protocol security and information sharing. But insider threats at the agencies tasked with investigating those hacks represent a different class of problem, one that better smart contract audits won’t solve.
What Happens Next, and What It Means for Agency Crypto Handling
Yarmoch faces federal charges in the Eastern District of Virginia, a jurisdiction with a reputation for moving cases quickly (it’s sometimes called the “rocket docket”). The court filing released August 1 establishes the initial charges, though additional counts could follow as investigators review the full scope of the transfers.

The legal exposure here is substantial. Theft of government property, wire fraud, and potentially violations of the Computer Fraud and Abuse Act could all apply. The national security angle adds another layer. When someone with top-secret clearance who worked in counterintelligence against foreign adversaries suddenly starts stealing assets and planning trips to non-extradition-friendly destinations (Grenada has no extradition treaty with the US), investigators will want to know whether the million dollars was the whole story or just what Yarmoch decided to confess.
The AI chatbot detail will likely become fodder for courtroom arguments about intent and flight risk. Asking an AI how to leave the country with a million dollars isn’t a crime in itself, but it’s exactly the kind of evidence prosecutors use to argue a defendant shouldn’t be released pending trial. The Portugal travel bookings amplify that argument. So does the pattern of unreported foreign travel.
For the broader crypto industry, this case lands at an awkward moment. The sector has spent years arguing that digital assets can coexist with regulatory frameworks, that exchanges like Kraken implement robust compliance measures, that blockchain’s transparency actually makes illicit activity harder than with cash. And those arguments have merit. But when an FBI agent allegedly steals crypto and routes it through both a regulated exchange and a DeFi protocol, it demonstrates that technical compliance at the platform level doesn’t prevent misuse by individuals with privileged access.
Kraken, for its part, maintains standard law enforcement cooperation procedures. The exchange presumably provided records that helped trace Yarmoch’s activity. Suilend, as a decentralized protocol on Sui, doesn’t have a compliance department to subpoena, though on-chain transactions are permanently visible to anyone who knows which addresses to look at.
The FBI will likely face internal scrutiny over how this happened. Access controls, audit logging, separation of duties for evidence handling, all of these will be reviewed. The bureau’s Office of Professional Responsibility investigates agent misconduct, and a case this embarrassing will generate thorough examination of whether systemic failures enabled Yarmoch’s alleged theft.
The court filing notes Yarmoch was an Ashburn, Virginia resident, a suburb in the Dulles corridor where many federal employees and contractors live. The area is dense with people holding security clearances who work at the FBI, CIA, NSA, and various intelligence contractors. That someone in this community allegedly turned to crypto theft as a side hustle (or exit strategy) will resonate in federal workplace culture where violations of trust carry professional and social consequences beyond the legal penalties.
One question the filing doesn’t answer: did Yarmoch attempt to launder or obscure the funds, or did he simply transfer them to accounts in his own name? The mention of Kraken suggests some portion of the crypto touched a regulated exchange where identity verification applies. If he tried to withdraw to fiat through standard banking channels, the trail would be straightforward to follow. If he kept funds in self-custody wallets or attempted to use mixers or bridges, the investigation becomes more technical but hardly impossible given the FBI’s blockchain analysis capabilities.
The irony here is thick. An agent who spent his career investigating foreign adversaries’ activities, likely including some involving cryptocurrency, allegedly couldn’t resist the assets he encountered in that work. And when he started planning his escape, he asked an AI for advice, generating a perfect record of premeditation that investigators would later find on his own devices.
Whatever happens in the legal proceedings, this case will become a reference point in discussions about government crypto custody. The same agencies asking for expanded surveillance powers over digital assets have to demonstrate they can secure the assets they already control. One rogue agent with a million-dollar confession and Portugal on the brain suggests that work remains incomplete.




