Home Blog Page 623

How a Seed Phrase Leak Led to a $176M Bitcoin Theft Case

0

Code is not the weakest point in crypto thefts

In crypto, security is usually regarded as a technical issue. You are asked to safeguard your private keys, rely on a hardware wallet and steer clear of phishing links. Yet a prominent case in the UK reveals that the real vulnerability in this case might have had nothing to do with code.

The UK High Court is currently reviewing a case involving the alleged theft of 2,323 Bitcoin (BTC), worth about $176 million. The theft did not stem from hacking or malware. Instead, it began with a seed phrase being exposed, which became the single point of failure in self-custody.

The dispute centers on Ping Fai Yuen, who claims that his estranged wife, Fun Yung Li, and her sister gained access to his Bitcoin by secretly recording his wallet’s recovery information.

The assets were held in a hardware wallet, designed to keep private keys completely offline and shielded from remote threats. Yet the theft still happened and it required no breach of encryption.

Court documents suggest the theft only required discovering the seed phrase.

Alleged timeline of the crypto theft

The allegations describe events that suggest surveillance rather than digital intrusion.

  • The individuals in question are accused of using a camera or recording device to capture the seed phrase and related codes.

  • The claimant later learned of the scheme after receiving a warning from his daughter.

  • He then set up audio recording equipment, which he says captured conversations about moving the funds.

  • The Bitcoin was subsequently transferred to 71 separate wallet addresses.

No additional movements have appeared on the blockchain since Dec. 21, 2023, indicating that the assets have remained inactive since the reported transfer.

Authorities are said to have confiscated devices and cold wallets as part of the inquiry, although the proceedings are still ongoing.

Did you know? In several past cases, hidden cameras, not hackers, have been the weakest link in crypto security. Physical surveillance has quietly become one of the most underestimated threats to self-custodied digital assets.

Why the seed phrase mattered in the UK crypto theft

To understand the case, you need to grasp a core principle of crypto: Whoever has access to the seed phrase has full control of the funds.

A hardware wallet shields private keys from online risks. But the seed phrase, typically 12 to 24 words, serves as a full backup of the entire wallet.

Finding the seed phrase allows anyone to:

  • Rebuild the wallet on any other device

  • Access all the associated funds

  • Move the assets without ever touching the original hardware

Put simply, once the seed phrase becomes known, the physical device loses all relevance.

The surveillance element: An uncommon form of compromise

What stands out in this matter is the reported method used to carry out the breach.

Rather than relying on phishing or malicious software, the allegations center on visual or audio capture, possibly through a hidden camera or covert recording.

This brings attention to a seldom-mentioned risk: side-channel exposure.

Seed phrases are frequently written down, spoken or typed during setup. If any of those moments are watched or recorded:

  • The phrase can be pieced together.

  • The wallet can be copied elsewhere.

  • Assets can be relocated without immediate traces.

In environments full of smart devices, cameras and shared spaces, this type of risk continues to rise.

The UK High Court’s early stance

The matter came before the UK High Court, where Justice Cotter examined the evidence presented.

Although this does not constitute a final decision in the case, the judge indicated that the claimant had demonstrated a very high probability of success.

Among the elements considered were:

The court also stressed the need for swift action, citing security concerns and Bitcoin’s price fluctuations.

Did you know? Some wallets now offer decoy wallets that use different PINs. This feature allows users to display a smaller balance under duress, adding a layer of protection against both physical coercion and surveillance-based attacks.

Why the assets were spread across 71 addresses

The claim states that the Bitcoin was distributed across 71 wallet addresses.

This step carries several implications:

  • It makes tracking and recovery more difficult.

  • It avoids drawing attention to a single large transfer.

  • It fragments the holdings, which can delay legal and investigative efforts.

Although the blockchain’s transparency allows movements to be traced, spreading the funds adds layers of complexity and time to any recovery process.

The dusting attack concern

The claimant also expressed concern about a possible dusting attack on the addresses involved.

Dusting refers to sending tiny amounts of crypto to wallets in order to:

  • Monitor subsequent activity

  • Link addresses to real identities

  • Identify valuable targets for future attacks

If wallet addresses become public, they can attract additional scrutiny, even if no further activity occurs.

Why this matter extends beyond a single conflict

On one hand, this case remains a private legal dispute. On the other, it serves as a case study in the broader risks of crypto custody.

It demonstrates that:

  • Hardware wallets limit digital threats, yet leave human factors untouched.

  • Threats from those close to the owner can outweigh those from outside attackers.

  • Exposure of the seed phrase can result in a complete loss of control.

Above all, this shows that crypto security involves far more than just devices; it relies heavily on environment, conduct, trust and relationships.

Security lessons from the case

This example reinforces several straightforward guidelines:

  • Keep the seed phrase completely hidden from cameras, phones and connected devices.

  • Avoid storing recovery information in places that others can access.

  • Separate personal identity from wallet control whenever possible.

  • Use multiple layers of protection for large holdings.

More sophisticated arrangements may include additional passphrases, split backups or multisignature setups. Each of these methods is designed to reduce reliance on a single vulnerable element.

Bhutan Moves $37M in Bitcoin to Exchanges, Holdings Down Two-Thirds From Peak

0

In brief

  • Bhutan transferred 519.707 BTC worth $36.75 million to external addresses on Wednesday, continuing its 2026 sell-off.
  • The kingdom’s Bitcoin holdings have fallen 66% from peak levels in late 2024 to 4,453 BTC worth $315 million.
  • Year-to-date outflows from Bhutan’s sovereign Bitcoin treasury exceed $150 million as the nation monetizes mining operations.

The Kingdom of Bhutan transferred another 519.707 BTC worth $36.75 million to external addresses on Wednesday, accelerating a sovereign Bitcoin liquidation that has seen its BTC holdings plummet 66% from late 2024 peaks.

The Royal Government of Bhutan now holds 4,453 BTC worth approximately $315 million, down from nearly 13,000 BTC in late 2024, according to on-chain data.

The latest transfer continues a drawdown that began after October 2024, with total year-to-date outflows exceeding $150 million.

The steady pace of transfers has accelerated in recent weeks, with Bhutan moving from $5-15 million clips in January and February to $35-45 million transfers in March, according to transaction analysis. Wednesday’s movement to external wallets follows patterns consistent with exchange deposits, though specific destinations remain unconfirmed.

The sovereign selling represents one of the largest government Bitcoin liquidations on record, creating consistent selling pressure as Bhutan continues to monetize holdings accumulated through its hydropower-backed mining operations.

Bitcoin is currently trading at around $69,410, down 3% on the day according to CoinGecko data.

Unlike the majority of state Bitcoin holdings, Bhutan has accumulated its treasury through mining rather than purchases, leveraging its abundant renewable resources. In December 2025,  Bhutan pledged up to 10,000 BTC to develop Gelephu Mindfulness City, an economic hub in the south of the country.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

Being a Fintech Without Credit is a Reason for Your Customers to Leave

0

By John Downie, SteadyPay

Payments apps, wallets, personal finance tools, vertical fintechs – they’ve all built deep relationships with their users. They see income, spending patterns, cashflow gaps in real time. But when those same users need to borrow, be it for an emergency, a big purchase, to bridge the gap between paydays, they’re sent elsewhere. Back to a traditional bank. To a high-cost lender. To a BNPL provider who doesn’t know them at all.

Over half of our users tell us they’re borrowing to cover an unexpected expense. The Building Societies Association recently found that one in five UK adults couldn’t cover a £300 emergency, rising to more than a third of under-24s. There is clear demand for lending services. And there is the supply – it’s just that if the supply isn’t coming from you then you are going to lose business. And it’s someone else who then monetises the borrowing need – often badly, and often at a price the customer shouldn’t have to pay.

I’m not going to claim that people are blind to the opportunity. It’s just that the barriers are very real. Consumer credit authorisation, FCA reporting, affordability assessments – it’s a different regulatory world from payments or money management. Then there’s the problem that lending ties up the balance sheet at a time when most fintechs are burning cash on growth, rather than provisioning for loan books. Infrastructure can be an impossible task too. Building underwriting models from scratch is a multi-year, specialist endeavour. Get it wrong and you haemorrhage money. Get it publicly wrong and you damage a brand built on trust.

Around 20 million people in the UK fall outside the traditional credit system. Say there’s roughly 53 million adults in the UK and that’s 38% of that population. Are they high risk? Some might be. But, for the vast majority, they are simply unlucky enough that the infrastructure wasn’t built for how they live and earn. It’s the gig workers, the hourly earners, the immigrants, or anyone whose financial life doesn’t fit neatly onto a credit file. Many of them are already using fintechs for payments and money management. When they can’t access credit through that same app, they default to high-cost alternatives – or go without entirely.

What’s crazy is that the data needed to underwrite these borrowers fairly – like the real income, real spending, real cashflow – is already sitting inside the fintechs they use every day. Open Banking makes it accessible. At SteadyPay, we’ve originated over 600,000 loans to exactly this population, maintaining default rates below 5 per cent – less than half the industry average. These are creditworthy people. The system just couldn’t see them.

We saw the great unbundling in payments a few years ago, and this is now reaching credit. Stripe abstracted payment processing so that every internet business didn’t need a merchant acquiring licence, and plug-in credit rails now let fintechs offer lending without building the regulatory, capital, and underwriting infrastructure from scratch.

The split is clean: the infrastructure partner owns underwriting, capital, compliance, collections, and conduct obligations. The fintech partner owns the customer – the UX, the brand, the distribution, the relationship. Credit becomes a feature of your product rather than a separate business you have to run.

There’s a subtler version of this for banks and fintechs that already lend. Any institution with a banking licence operates under a lending policy reviewed and approved by the regulator (as it should be). But that necessarily means a significant segment of customers fall outside their criteria. Those customers don’t disappear. They go somewhere else, usually somewhere worse. Parallel decisioning lets an infrastructure partner catch those declines, serve the customer under the same brand, and graduate them back to the bank’s own book when their profile strengthens. The customer stays in the ecosystem. The bank expands its reach without compromising its lending policy.

None of this means building your own lending stack is always wrong. But before you commit, ask five honest questions:

  1. Do you have the balance sheet capacity, or will you need a funding partner anyway?
  2. Do you have credit risk specialists who’ve built and stress-tested models through a full cycle – not just data scientists?
  3. Is your regulatory appetite high enough for what is a 12-24 month authorisation process and a permanent compliance overhead?
  4. Can your leadership absorb the distraction when your core product still needs focus and scale?
  5. And will your investors – who backed an equity focused growth story – accept balance sheet exposure in the portfolio?

If you answer no to two or more, building your own stack will likely cost you more than it gains. It’s the same logic that made you use Stripe instead of building a payment gateway.

You can’t build everything in-house. But you can assemble the right infrastructure, and use it to serve the millions of people that traditional finance still pretends don’t exist. The infrastructure is ready. The industry just needs to learn to use it.

Coinbase-Backed Crypto Advocacy Organization Unveils 2026 Election Plan

0

Stand With Crypto (SWC), the advocacy organization launched by cryptocurrency exchange Coinbase, said that its strategy for turning out crypto-minded voters in the 2026 US midterm elections will prioritize races in Ohio and Pennsylvania.

In a Thursday announcement, SWC said its November 2026 battleground races would include industry-supported candidates in Iowa, Nevada, New York, North Carolina, Ohio, and Pennsylvania, where “crypto voters represent a meaningful and potentially decisive share of the electorate.”

The advocacy group added that its priority for the midterms would be in Ohio’s 9th Congressional District and Pennsylvania’s 10th Congressional District, where the respective incumbents Democrat Marcy Kaptur and Republican Scott Perry “have concerning records on crypto policy.” Perry voted against the GENIUS Act in 2025, while Kaptur voted against the payment stablecoins bill and the CLARITY market structure bill.

Stand With Crypto said it would use an “aggressive, get-out-the-vote effort” with its advocates, including “paid media campaigns across digital and direct mail, targeted SMS outreach, and robust digital organizing through email and social platforms” as well as groundwork to turn out crypto voters. The group’s platform includes information on candidates’ positions on crypto policy based on their public statements, voting records and their responses to the organization’s questionnaire. 

Launched in 2023 as part of an effort to “unite global crypto advocates,” SWC is one of several crypto-affiliated organizations expected to influence voters in 2026. The group reported about 270 “pro-crypto” candidates won seats in the US House of Representatives and Senate in 2024, with many of the same candidates up for reelection this year.

Related: Crypto-backed PAC spends $8.6M in Illinois races ahead of US midterms

Stand With Crypto said in November 2025 that how US lawmakers vote on a crypto market structure bill could impact their reelection prospects. At the time, the Senate was expected to move forward on market structure legislation, but it is still unclear if or when the bill will advance out of committee and for a full floor vote.

“[As] market structure legislation continues to be negotiated in Congress, 74% of crypto owners say they would be more likely to support a candidate who supports making clearer regulations for cryptocurrency, with nearly a third (31%) who say they would be much more likely to support such a candidate,” SWC said as part of a February survey of 1,000 crypto holders.

2026 races seen testing crypto industry’s impact on candidates

Money from the crypto industry funneled through political action committees (PACs) like Fairshake may have already influenced 2026 voters in early state primaries.

Protect Progress, a Fairshake affiliate spent $1.5 million opposing the reelection of Texas Representative Al Green, who has served in Congress since 2005. Although Green did not lose the Democratic primary, he will head to a runoff with Christian Menefee in May. SWC rated Menefee as “strongly supports crypto.”

However, in Illinois, Lieutenant Governor Juliana Stratton won the Democratic Senate primary against Representatives Raja Krishnamoorthi and Robin Kelly. The victory came despite crypto-tied lobbyists spending millions of dollars on media buys supporting Krishnamoorthi. Stratton is expected to win in the general election and take the seat of retiring Democratic Senator Dick Durbin.