In the winter of 2026, a man who had spent decades learning how to make other people disappear turned to an artificial intelligence for advice on how to make himself disappear. The former FBI counterintelligence chief, now charged with stealing nearly $1 million in cryptocurrency, asked ChatGPT questions that would later land him in a federal courtroom: how should he invest the stolen assets, and what would it take to relocate to Europe under the radar? It is a strange, almost farcical detail — a master of espionage consultancy consulting a chatbot with a cheerful disclaimer message. But the absurdity conceals a deeper, more uncomfortable truth about this industry. The most damaging attacks on crypto are not the ones that break encryption. They are the ones that break the people who hold the keys. And when the custodian is the FBI, the breach stops being a code problem and becomes a crisis of institutional governance. It also becomes a story about the blurred line between the guardians of the law and the predators they are supposed to catch.
The details of the case are stark. The agent, whose name has been redacted in initial filings but whose role as a supervisory counterintelligence specialist is well documented, had direct access to digital wallets containing assets seized during federal investigations. At some point, he transferred a portion of those funds — nearly $1 million worth — into accounts he controlled. The prosecutors' indictment is a straightforward, dreary list of theft and related charges. But the story is not about a petty thief. It is about a systemic vulnerability that has been hiding in plain sight for years: law enforcement agencies have become de facto custodians of vast amounts of cryptocurrency, yet their internal controls were not designed for the job.
To understand the scale of this, consider the numbers. The U.S. Department of Justice has seized assets in cases ranging from the Silk Road to the numerous ransomware attacks that have crippled hospitals and infrastructure. In one high-profile case just a few years ago, the DOJ recovered 63.7 Bitcoin from a group of script kiddies who had hacked a major pipeline; in another, they seized $3.36 billion in Bitcoin from a dark-web marketplace, a record that drew global headlines. That money goes somewhere. It sits in wallets controlled by federal agents, awaiting forfeiture proceedings and eventual auction by the U.S. Marshals Service. The process is opaque, but the pattern is clear: the government is holding billions in digital assets that are not protected by the same institutional-grade custody that the crypto industry has developed for billion-dollar exchanges.
The FBI is not a custody exchange. It has no Fireblocks, no BitGo, no institutional-grade multisig protocol for the assets it seizes. It has a set of standard operating procedures, a few storage wallets, and the implicit trust that its own personnel are above the laws they enforce. That trust, as this case painfully illustrates, is the most dangerous cryptocurrency of all. The agent who stands accused was not an outsider who hacked the system. He was an insider who used the system as it was designed — with too much power concentrated in too few hands.
The deeper context is that this is not the first time a law enforcement officer has been compromised by the assets they were supposed to protect. In 2021, a U.S. Secret Service agent was charged with stealing $225,000 in cryptocurrency that was evidence in a federal investigation. In 2023, a DEA agent was accused of stealing Bitcoin confiscated during a raid. The common thread is not malice; it is opportunity. When you give a person access to a vast, easily transferable, semi-anonymous asset, you create a temptation that no psychometric test can fully eliminate. The blockchain records everything, but it does not record human intentions.
Let me start with a confession: I have built treasuries on Ethereum, and I have audited custody flows for small DAOs. In my own governance work with UnityDAO back in 2020, we implemented a 7-of-11 multisig, a quadratic voting system, and a requirement that no single member could ever see the full key set. The reason was not that we suspected our members of being criminals. It was a simple principle of systems design: every person is an attack surface, and moral character is not a storage medium. The FBI's failure, as this case reveals, is essentially the failure to apply this principle to its own people.
The details of the theft, as reported, suggest a classic single-point-of-failure scenario. The agent was able to access a wallet tied to an investigation, likely because the private keys were in a centrally managed system with little to no independent oversight. Based on my experience with asset custody, I estimate that the FBI relied on a cold storage system secured by a single or dual individual with administrative access, and no daily reconciliation of the wallet addresses. That is not a criticism of FBI technology; it is a commentary on the limits of traditional law enforcement culture. The job of an investigator is to distrust the outside world. But the highest-value target in a crypto case is often not the hacker in the mirror. It is the person who knows the vault's architecture.
The solution to this is not simply "use multisig." I have seen DAOs implement a 3-of-5 multisig where all five signers work in the same office, share the same laptop, and have never once checked the transaction history. Multisig is a procedural control, not a magic wand. The minimum standard for a sovereign-level custodian, whether a nation or a DAO, should be the following: (1) cold storage on hardware security modules (HSMs), not on a portable USB stick; (2) dual-control access, where two separate, unrelated individuals must be physically present to authorize a transfer; (3) an independent audit function that reviews the wallet's transaction history on a monthly basis; and (4) a mandatory separation of duties between the person who initiates a transaction and the person who verifies it. If any of these four elements had been in place at the FBI, the theft would have been detected within hours, not months.
I am not suggesting that the FBI is incompetent. I am suggesting that the legacy of traditional financial crime, where funds are held in bank accounts with multiple reconciliation layers, has not been successfully carried over to the crypto world. In a traditional bank, an employee who wants to steal money must forge checks, manipulate ledgers, and pass through multiple human eyes. In crypto, the private key is the ultimate token of power. If you have it and the approval matrix is weak, you can move astronomically large sums in the blink of an eye. It is the one area where decentralizing power into many hands is a security feature, not a bureaucratic inconvenience.
What makes this case uniquely dangerous is the combination of insider expertise and AI access. The agent didn't need to contact a darknet broker for laundering advice. He used ChatGPT to ask, in plain English, how to invest in a way that might survive scrutiny, and how to establish a new life in Europe. Now, I want to be clear: ChatGPT did not commit a crime. It is a tool. But this case demonstrates a phenomenon I have called the "democratization of operational security." In the past, flight planning and money laundering required a network of contacts, anonymous emails, and deep technical know-how. Today, anyone with a prompt can access a passable approximation of that knowledge. The barrier to entry for financial crime has dropped, and the barrier to entry for preventing it — audit trails, human verification, and constant monitoring — has not.
I wrote about this in my research on "Human-First Protocols," an initiative I led to audit AI-generated content in DAO discussions. We developed a manual verification layer for more than a thousand proposals, ensuring that decisions remained rooted in human consensus rather than algorithmic efficiency. This project was not about mistrusting AI. It was about recognizing that every AI output is a signal that must be confirmed by a human who understands the local context. In the case of the former agent, the AI output was painfully on the nose: "Invest in X, move to country Y." But the local context was that a man with top-secret clearance was planning to flee the country with a million dollars of stolen digital assets. There was no human in the loop to say, "Wait, this is not a vacation; this is a flight risk."
This is the core architectural question of our age: How do we design systems where AI can augment human decision-making without becoming a single point of failure for human ethics? The answer, I believe, is not to remove humans from the flow, but to ensure that every critical action requires multiple, mutually skeptical humans to collaborate. This is not a matter of code; it is a matter of compassion — understanding that even the most trusted individuals operate under pressure, greed, or delusion. Code without compassion is cold. But compassion without accountability is a lullaby.
Perhaps the most reassuring — and ironic — aspect of this case is that the blockchain is the ultimate paper trail. Every transfer the former agent made is permanently etched into a public ledger. The FBI's own Chainalysis tools, which they use to track foreign hackers and ransomware gangs, will be turned on one of their own. This is the vindication of the transparent ledger. When the argument gets bounced around that "crypto is a haven for criminals," cases like this get thrown around. But look closer: the blockchain is the reason this crime is likely to be solved. If the agent had stolen cash from a secret F.B.I. slush fund, the investigation would be fundamentally harder. Instead, his movements are visible in the open as long as someone cares to look.
But here is the blind spot: the transparency is only effective if the authorities know what to look for. If the FBI is not actively monitoring the wallets it controls, the blockchain's transparency is meaningless. The agent did not have to hide his transactions from the public; he had to hide them from his colleagues. In an institution where the supervisor is the one stealing, the monitoring system must be externalized. This is why I have long argued for a proof-of-reserves requirement for any entity that holds other people's assets — public, verifiable, and periodically audited. The FBI should publish a cryptographic commitment to the total balance of its seizure wallets, with the private keys held by a third-party independent auditor. It is exactly what the DeFi protocols like Aave and Compound do, albeit with different mechanisms. The technology exists. The standards don't. It is time for law enforcement agencies to adopt the very transparency principles that the crypto community has been pushing for a decade.
This case reinforces a lesson that I learned the hard way during the 2022 bear market: the health of a community — or an institution — is not measured by the absence of conflict, but by its ability to surface and resolve failure. In the aftermath of FTX, we saw what happens when a centralized leader is trusted absolutely and then betrays that trust. The collapse of FTX was not a technical failure; it was a failure of governance. The same can be said for the FBI. The agent was not a brilliant hacker; he was a trusted administrator who exploited a governance vacuum. The professional standard for the future must be to design systems where no single person is above the law — not in rhetoric, but in technical configuration.
Now let me play devil's advocate against my own industry's tendency toward outrage. Many are quick to see this as an indictment of centralized custody, a reason to shout "self-custody or die." And there is some truth to that. But if we turn this into a simplistic "FBI bad" narrative, we miss the point. The lesson here is not that custody is bad; it is that custody without governance is a fraud in waiting. The risk surface was not centralized custody itself. The risk was the lack of professional oversight. It is the same reason we demand exchanges like Coinbase to undergo SOC 2 audits and maintain segregated cold wallets. They must be held to a higher standard precisely because they hold other people's assets.

The more uncomfortable conclusion is this: the most secure custody solution in the world would have prevented this theft, but it would not have prevented the betrayal. The agent didn't break through a wall. He was invited in. The system failed not because it was too weak, but because it trusted too much. In a world where AI can generate tailor-made fraud instructions in minutes, the institutional challenge is not to build a more perfect lock. It is to build a system that assumes betrayal as a baseline condition. A system that cannot audit its own guardians is not a system; it is a promise.
I also want to push back on the "ChatGPT is a criminal mastermind" angle, which is circulating in the media. An AI tool answering a question about real estate in Portugal is not a conspiracy. It is a search engine with a nicer interface. The real problem is that the procedural walls around that agent's access were so low that he could act on the AI's advice without any friction. The output of AI is only as harmful as the environment in which it is allowed to act.
There is also a quieter, more political implication that the crypto community often fails to acknowledge. When law enforcement agencies become the custodians of seized assets, they gain a financial incentive to seize more. The perverse incentive to "pump" the value of a wallet through successful forfeiture is not a conspiracy theory; it is a structural risk. By demanding that the FBI externalize its custody and auditing functions, we are not only protecting them from internal theft; we are also reducing the temptation for overreach.
Our industry has spent a decade securing the transaction layer. We built smart contract audits, security labs, and decentralized protocols that rival nation-states in their cryptographic rigor. But we have largely failed to secure the people layer. The former counterintelligence chief did not need to exploit a zero-day. He exploited a process. And now, as he sits in a federal holding cell, the question for every DAO, every exchange, and every law-enforcement treasury is the same: Who is the single person that could take down your entire project? Until you can answer that with "no one," your security stack has a backdoor shaped like a human. It is time to stop building vaults for honorable angels and start building them for fallible humans.
If there is one thing I hope you take from this case, it is not fear of AI, and it is not finger-pointing at the FBI. It is a renewed commitment to the principle of radical transparency — not as an ideal, but as an engineering requirement. Let us push for a world where the guardians of the blockchain are no exception to its rules. The blockchain can be a source of ultimate truth. But institutions — all institutions — must learn to treat their own code with the same skepticism they apply to the streets. Because code without compassion is cold, but code without accountability is a crime waiting to happen.