Prefer Koin Bülteni on Google Add as source

$320 Million Loss Is Traceable: Identity Leak Cannot Be Undone

While the $320 million on-chain loss is traceable, leaked identity and address information cannot be retrieved.

On September 7, a blockchain used for Bitcoin transfers lost approximately $320 million in a single attack. Because funds move on the public ledger, transactions can be tracked. It is also reported that the attacker is in negotiations to return the money.

An opinion piece published in CoinDesk emphasized that such financial losses are, at least theoretically, recoverable. In contrast, Trezor confirmed that the names, phone numbers, and home addresses of 67,000 customers were exposed through a shipping provider. In a separate leak, approximately 200,000 records contained wallet addresses verified with government ID numbers.

Identity leaks become permanent via wallet addresses

The impact of address information leaked from hardware wallet manufacturers in 2020 has not yet ended. It is noted that years later, physical mail demanding Bitcoin is still being sent in connection with this data. While a compromised key can be changed, it is not possible to change a home address, face, or passport number with the same speed.

The author of the piece and co-founder of Billions Network, Evin McMullen, argued that the issue should not be limited solely to whether firewalls are strong enough. According to McMullen, companies do not have to store a person’s entire passport to verify that they are a real and non-sanctioned customer.

In this approach, the institution only verifies the necessary information and does not keep the identification document in its database. This prevents the creation of centralized repositories where sensitive identity data is collected. Crypto exchanges, hardware wallet manufacturers, and deposit-withdrawal services can become valuable targets for attackers as they scale.

New risks could grow in AI agents

McMullen stated that the internet is being reshaped by software acting on behalf of users, and these systems will need to prove their authority to transfer money in the future. If these agents carry all their users’ identity information to every service, the number of data targets—currently limited—could rise to billions of centralized identity repositories.

The main message of the piece is that companies should not only better protect the data they hold but should not collect data they do not need in the first place. It was stated that privacy-focused technologies that allow for verification without revealing identity exist today, but their widespread adoption depends on changing data collection habits.

Tüm gelişmelerden ve paylaşımlardan haberdar olmak için Telegram kanalımıza katılın!