惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
酷 壳 – CoolShell
酷 壳 – CoolShell
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
腾讯CDC
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Jina AI
Jina AI
N
Netflix TechBlog - Medium
有赞技术团队
有赞技术团队
博客园 - 【当耐特】
MongoDB | Blog
MongoDB | Blog
P
Proofpoint News Feed
L
LangChain Blog
aimingoo的专栏
aimingoo的专栏
GbyAI
GbyAI
B
Blog
F
Fortinet All Blogs
T
Tailwind CSS Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
G
Google Developers Blog
A
About on SuperTechFans
C
Check Point Blog
Microsoft Security Blog
Microsoft Security Blog
MyScale Blog
MyScale Blog
B
Blog RSS Feed

GRAHAM CLULEY

'Anne Hathaway' admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars Smashing Security podcast #484: How websites are tracking you with silence CRPx0 ransomware: what you need to know The US military just turned off ad tracking on its phones. Maybe you should too How a hole in Lenovo's login system let hackers walk into 5,000 Dropbox accounts Smashing Security podcast #483: This AI helps thieves steal your iPhone Revolut scam steals £180,000 from Jersey residents in just four weeks Shai-Hulud hackers: two men charged over TeamPCP's global supply chain crime spree that hit OpenAI, and thousands more US Navy tells sailors and their families: scrub your social media, enemies are watching Smashing Security podcast #482: This hacker leaked GTA 6 - and launched their own cryptocurrency Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials Gunra ransomware: what you need to know Smashing Security podcast #481: Never say this to a robot dog Prison for data analyst who tried to extort $2.5 million from his employer An "invisible" car? Researcher uses machine learning to hide vehicles from Flock cameras Smashing Security podcast #480: This is the AI service you should never sign up to Meta's Ray-Bans are being banned from pubs, restaurants, and theatres Beware cut-price AI services that read your every word Apple's bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency Fake IRS letters target cryptocurrency holders The $5 million threat: AI Is supercharging phishing attacks North Korea's elite hackers turned on their own government — and got caught Smashing Security podcast #478: This job interview could destroy your company OpenAI's AI "goes rogue" and hacks Hugging Face: what you need to know Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker Ukraine warns fake CAPTCHAs are being used to make you hack yourself Google's Gemini lets strangers send messages from your locked Android phone Anubis ransomware: what you need to know
They seized $4.8m in crypto... then gave the master key t...
2026-03-03 · via GRAHAM CLULEY

South Korea's National Tax Service (NTS) has found itself in the middle of a deeply embarrassing — and costly — blunder after accidentally handing thieves the master key to a seized cryptocurrency wallet.

The method? Publishing the access key in a press release, in plain sight for the entire world to see.

Last Thursday, the NTS issued a triumphant press release to the media detailing how it had taken action against 124 high-value tax evaders, and boasting about the seizure of digital assets worth 8.1 billion won — roughly US $5.6 million.

And in that press release, officials included photographs of some of the confiscated hardware: including a Ledger cold wallet device and, sitting right next to it, a handwritten note clearly displaying the wallet's mnemonic recovery phrase.

This seed phrase is the 12-to-24 word sequence that functions as the master key for a cryptocurrency wallet. And as everyone who possesses a hardware cold wallet should know, you are never ever supposed to share with anyone, let alone broadcast to the entire internet in an official press release, that seed phrase.

By dawn the following morning, someone had emptied the wallet of all of its cryptocurrency.

For those unfamiliar with how hardware wallets work, the mnemonic (or seed) phrase is essentially your wallet's ultimate password. Anyone who possesses the phrase can restore access to that wallet on any device, anywhere in the world. And then they can transfer every last cryptocurrency token out — with no need for physical access to device, no PIN required, no further authentication of any kind.

Hardware wallets like Ledger are built around the assumption that the seed phrase is kept secret. The whole point of "cold storage" is that the private keys to the wallet never touch the internet. The moment a seed phrase is exposed, the offline protection is weaker than tissue paper.

The NTS officials later explained that they had included the images in their press release to make it "more eye-catching." Unfortunately for them, the press release certain did catch some people's attention.

The confiscated wallet in question belonged to a tax evader identified only by the authorities as "Mr. C," who had had four cryptocurrency storage devices seized from his home. The hardware wallet contained approximately 4 million Pre-Retogeum (PRTG) tokens, worth around US $4.8 million (approximately 6.4 billion won) at the time.

According to a blockchain analysis by Professor Cho Jae-woo, director of the Blockchain Research Institute at Hansung University in Seoul, the theft took place in the early hours of February 27th — shortly after the press release was published.

Professor Cho pointed out that the original owner of the Ledger device had actually been following best practice — recording the seed phrase only on a handwritten note, rather than storing it digitally. The irony, of course, is that while the tax evader took proper precautions to protect his crypto fortune, the authorities tasked with safeguarding the seized assets did not.

So, a win for the crypto thief - yes?

Well, maybe not.

Because the thief may find it considerably harder to actually spend their US $4.8 million worth of cryptocurrency than it was to steal.

As The Block reports, PRTG is an obscure token, that is rarely used. According to CoinMarketCap data, it recorded a volume of just US $332 in 24 hours of trading at the time of the incident and is listed on only a single exchange — MEXC.

Furthermore the 4 million stolen tokens represent approximately 40% of PRTG's entire total supply. Attempting to convert that quantity of crypto into cash would almost certainly impact the token's value long before the full transaction was done.

Furthermore, if the stolen tokens eventually move through a regulated platform with know-your-customer requirements, there is at least a chance of identifying who is trying to capitalise on the theft.

The NTS eventually removed the offending press release from its website, and issued a follow-up statement offering a "deep" apology for what had happened.

South Korea's National Tax Service found out the hard way. One can only hope that law enforcement agencies seizing digital assets around the world are paying attention.

After all, "don't photograph your passwords and publish them on the internet" is a lesson most of us managed to learn years ago.