ZachXBT Links ‘Lick’ to Funds Related to US Seizures

ZachXBT Links ‘Lick’ to Funds Related to US Seizures

ZachXBT claims John “Lick” flaunted wallets tied to more than $90 million in alleged thefts, including funds tied to U.S. government seizures.

A leaked group chat recording captured a threat actor named “John” screen-sharing wallet balances and moving millions in cryptocurrency, according to findings shared by ZachXBT.

The network’s prominent investigator said John, also known as “Lick,” was caught flashing approximately $23 million in cryptocurrency during a heated argument with another threat actor in a group chat.

“Band by band” went wrong

The dispute reportedly turned into what cybercrime circles call a “gang-by-gang,” where people try to prove who has more money by showing their wallet balances and moving funds in real time. ZachXBT said the footage shows John controlling multiple wallets and moving large amounts of cryptocurrency while the interaction was captured.

After reviewing the footage, the investigator said he tracked the funds and linked the wallets shown in the recording to more than $90 million in alleged thefts.

ZachXBT said it then traced the funds back and reported that one of the on-chain wallets received 1,066 WETH on November 20, 2025. It further stated that the funds could be traced back to a wallet that received $24.9 million from a US government address in March 2024. which he said was related to the Bitfinex hack seizure, a theft from the US government that he had previously reported in October 2024.

He also said that the wallet shown in the recording was linked to more than $63 million in entries from alleged victims and government seizure addresses in the fourth quarter of 2025, listing several large incoming transfers in November and December 2025. The on-chain detective added that another 4.17 thousand ETH worth approximately $12.4 million was received from MEXC and flowed into the same wallet.

USMS Cryptoasset Contract and a Family Bond

ZachXBT said John had an extensive history of boasting about his net worth on Telegram and shared the account handle linked to those messages. He also noted rumors circulating on cybercrime Telegram channels, which revealed that John could be John Daghitia, who was previously arrested in September 2025, but acknowledged that more investigation would be needed to fully confirm the identity.

You may also be interested in:

Additionally, the investigator raised questions about how John could have gained access in the first place, while also stating that John’s father owns CMDSS, a company with an active government IT contract in Virginia. ZachXBT said the company was awarded a contract to help the US Marshals Service manage and dispose of seized and forfeited crypto assets, but added that it is still unclear how John may have gained access through his father.

After ZachXBT posted the thread, it said John quickly changed his Telegram profile details, including removing NFT-related usernames and updating his username. ZachXBT also reported that its own public ENS address was later “dusted” from one of the wallets linked to the alleged thefts.

SPECIAL OFFER (Exclusive)

SECRET PARTNERSHIP BONUS for CryptoPotato readers: Use this link to sign up and unlock $1,500 in exclusive BingX Exchange rewards (limited time offer).

Leave a Reply

Your email address will not be published. Required fields are marked *