Connect with us
DAPA Banner

Crypto World

How a Seed Phrase Leak Led to a $176M Bitcoin Theft Case

Published

on

How a Seed Phrase Leak Led to a $176M Bitcoin Theft Case

Code is not the weakest point in crypto thefts

In crypto, security is usually regarded as a technical issue. You are asked to safeguard your private keys, rely on a hardware wallet and steer clear of phishing links. Yet a prominent case in the UK reveals that the real vulnerability in this case might have had nothing to do with code.

The UK High Court is currently reviewing a case involving the alleged theft of 2,323 Bitcoin (BTC), worth about $176 million. The theft did not stem from hacking or malware. Instead, it began with a seed phrase being exposed, which became the single point of failure in self-custody.

The dispute centers on Ping Fai Yuen, who claims that his estranged wife, Fun Yung Li, and her sister gained access to his Bitcoin by secretly recording his wallet’s recovery information.

The assets were held in a hardware wallet, designed to keep private keys completely offline and shielded from remote threats. Yet the theft still happened and it required no breach of encryption.

Advertisement

Court documents suggest the theft only required discovering the seed phrase.

Alleged timeline of the crypto theft

The allegations describe events that suggest surveillance rather than digital intrusion.

  • The individuals in question are accused of using a camera or recording device to capture the seed phrase and related codes.

  • The claimant later learned of the scheme after receiving a warning from his daughter.

  • He then set up audio recording equipment, which he says captured conversations about moving the funds.

  • The Bitcoin was subsequently transferred to 71 separate wallet addresses.

No additional movements have appeared on the blockchain since Dec. 21, 2023, indicating that the assets have remained inactive since the reported transfer.

Authorities are said to have confiscated devices and cold wallets as part of the inquiry, although the proceedings are still ongoing.

Advertisement

Did you know? In several past cases, hidden cameras, not hackers, have been the weakest link in crypto security. Physical surveillance has quietly become one of the most underestimated threats to self-custodied digital assets.

Why the seed phrase mattered in the UK crypto theft

To understand the case, you need to grasp a core principle of crypto: Whoever has access to the seed phrase has full control of the funds.

A hardware wallet shields private keys from online risks. But the seed phrase, typically 12 to 24 words, serves as a full backup of the entire wallet.

Finding the seed phrase allows anyone to:

Advertisement
  • Rebuild the wallet on any other device

  • Access all the associated funds

  • Move the assets without ever touching the original hardware

Put simply, once the seed phrase becomes known, the physical device loses all relevance.

The surveillance element: An uncommon form of compromise

What stands out in this matter is the reported method used to carry out the breach.

Rather than relying on phishing or malicious software, the allegations center on visual or audio capture, possibly through a hidden camera or covert recording.

This brings attention to a seldom-mentioned risk: side-channel exposure.

Seed phrases are frequently written down, spoken or typed during setup. If any of those moments are watched or recorded:

Advertisement
  • The phrase can be pieced together.

  • The wallet can be copied elsewhere.

  • Assets can be relocated without immediate traces.

In environments full of smart devices, cameras and shared spaces, this type of risk continues to rise.

The UK High Court’s early stance

The matter came before the UK High Court, where Justice Cotter examined the evidence presented.

Although this does not constitute a final decision in the case, the judge indicated that the claimant had demonstrated a very high probability of success.

Among the elements considered were:

Advertisement

The court also stressed the need for swift action, citing security concerns and Bitcoin’s price fluctuations.

Did you know? Some wallets now offer decoy wallets that use different PINs. This feature allows users to display a smaller balance under duress, adding a layer of protection against both physical coercion and surveillance-based attacks.

Why the assets were spread across 71 addresses

The claim states that the Bitcoin was distributed across 71 wallet addresses.

This step carries several implications:

Advertisement
  • It makes tracking and recovery more difficult.

  • It avoids drawing attention to a single large transfer.

  • It fragments the holdings, which can delay legal and investigative efforts.

Although the blockchain’s transparency allows movements to be traced, spreading the funds adds layers of complexity and time to any recovery process.

The dusting attack concern

The claimant also expressed concern about a possible dusting attack on the addresses involved.

Dusting refers to sending tiny amounts of crypto to wallets in order to:

  • Monitor subsequent activity

  • Link addresses to real identities

  • Identify valuable targets for future attacks

If wallet addresses become public, they can attract additional scrutiny, even if no further activity occurs.

Advertisement

Why this matter extends beyond a single conflict

On one hand, this case remains a private legal dispute. On the other, it serves as a case study in the broader risks of crypto custody.

It demonstrates that:

  • Hardware wallets limit digital threats, yet leave human factors untouched.

  • Threats from those close to the owner can outweigh those from outside attackers.

  • Exposure of the seed phrase can result in a complete loss of control.

Above all, this shows that crypto security involves far more than just devices; it relies heavily on environment, conduct, trust and relationships.

Security lessons from the case

This example reinforces several straightforward guidelines:

Advertisement
  • Keep the seed phrase completely hidden from cameras, phones and connected devices.

  • Avoid storing recovery information in places that others can access.

  • Separate personal identity from wallet control whenever possible.

  • Use multiple layers of protection for large holdings.

More sophisticated arrangements may include additional passphrases, split backups or multisignature setups. Each of these methods is designed to reduce reliance on a single vulnerable element.

Source link

Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Crypto World

Which US president was best for bitcoin?

Published

on

Which US president was best for bitcoin?

United States President Donald Trump has marketed himself as the president who truly embraced bitcoin (BTC), but has his willingness to cooperate with the industry resulted in price appreciation compared to previous administrations?

Protos used data from CoinGecko and CoinMarketCap to plot BTC’s relative performance up to this point during Barack Obama’s second term, Trump’s first term, Joe Biden’s term, and Trump’s second term.

Trump’s two terms represent the best and worst relative BTC performances.

Read more: ANALYSIS: Eric and Donald Trump Jr. are cashing in on crypto

Advertisement

The best performance at this point was in Trump’s first term, which saw BTC appreciate from less than $900 to nearly $8,500, an increase of approximately 850%.

Meanwhile, the worst performance can be seen during the current Trump administration, which has overseen a fall for BTC from over $101,000 to just over $71,000, a decrease of nearly 30%.

The two Democrat presidents sit between these relative extremes, with Obama presiding over an increase in BTC’s price from $212 to $584, an jump of around 175%.

Biden and his much-maligned cryptocurrency regulatory regime saw the price increase from approximately $36,000 to $44,000, a rise of 23%.

Advertisement

Trump is the only one of these presidents who has set himself up to profit directly from the crypto industry.

He’s the co-founder emeritus of World Liberty Financial, earns returns from the $TRUMP memecoin and the line of Trump digital trading cards, and Trump Media and Technology Group, the firm behind his beloved Truth Social, has diversified into crypto exchange traded funds.

Got a tip? Send us an email securely via Protos Leaks. For more informed news, follow us on XBluesky, and Google News, or subscribe to our YouTube channel.

Advertisement

Source link

Continue Reading

Crypto World

Argentina’s State-Backed Energy Giant YPF Launches Tokenization Initiative on XRP Ledger

Published

on

the-defiant

Enertoken, developed by Justoken for YPF Luz, launched with over $800 million in tokenized energy assets on XRPL.

YPF Luz, the electricity subsidiary of Argentina’s largest energy company, has partnered with Buenos Aires-based blockchain infrastructure company Justoken to launch an energy tokenization platform built on XRP Ledger (XRPL), the firms announced earlier this month.

The platform, dubbed Enertoken, tokenizes, commercializes, and manages electricity contracts via XRPL, the public blockchain originally developed by Ripple Labs, which remains a core contributor. Meanwhile, Justoken recently emerged as the largest real-world asset (RWA) tokenization platform on XRPL by total value.

Per the announcement, the new platform from YPF Luz, developed by Justoken, is aimed at corporations and large energy consumers to help manage everything from consumption tracking, to billing, to contract execution, “fully supported by tokenized energy assets recorded on blockchain.”

Advertisement

Martín Mandarano, the CEO of YPF Luz — the parent company of which has had a turbulent history of state and private ownership — was quoted as saying in the announcement:

“The integration of tokenized energy assets allows us to optimize processes, enhance traceability, and deliver greater transparency to our clients, reinforcing YPF Luz’s innovative profile within the energy sector.”

Justoken’s Quiet Dominance

In what the companies are calling the project’s initial phase, Enertoken launched with over $800 million in tokenized energy assets on XRPL, per the announcement, evidently referring to Justoken’s tokenized energy fund, JMWH.

Justoken’s JMWH, which, per RWAxyz, represents real megawatt-hours (MWh) of energy, backed by energy producers in Latin America, quietly become the largest tokenized asset on XRPL by total value when it launched in mid-January with over $861 million on-chain. Meanwhile, Justoken has another $832.3 million in various other tokenized commodities on Polygon.

the-defiant
Represented asset value on XRPL by asset. Source: RWAxyz

As of today, March 26, JMWH’s total asset value still stands at $861 million — representing nearly 57% of all so-called represented asset value on XRPL, and a nearly 45% market share of all tokenized RWA platforms on the network.

Per RWAxyz, “represented asset value” refers to tokenized assets that exist on a blockchain but cannot be distributed or transferred on-chain — they represent a real-world commitment recorded on-chain, not freely tradable tokens.

Advertisement

Represented vs Distributed RWAs

Luke Judges, Partner Director at RippleX, Ripple’s open developer platform, explained to The Defiant why JMWH falls into RWAxyz’s “represented” asset category, rather than “distributed” — a distinction that indicates how these assets are used on-chain, stating, “‘represented’ assets operate within more controlled environments, often reflecting regulatory or contractual requirements.”

In JMWH’s case, the tokens operate under Argentina’s capital markets regulator Comisión Nacional de Valores (CNV)’s regime for Virtual Asset Service Providers (PSAVs), with issuance, allocation, delivery, and retirement all tied to contractual obligations. This, Judges argues, explains why Justoken opted for a “closed loop approach.”

“The blockchain serves as a verifiable record of ownership and fulfilment rather than a trading venue,” Judges added.

He also noted that represented assets on XRPL are “an important starting point for many institutional use cases, with distributed assets playing a larger role as liquidity, infrastructure, and regulatory clarity continue to evolve on XRPL.”

Advertisement

Selecting XRPL

Ariel Scaliter, co-founder and CTO of Justoken, told The Defiant that the choice of XRPL was deliberate on multiple fronts, citing speed and scalability for teams building on the blockchain network:

“XRPL was selected for several strategic reasons. First, its institutional quality stands out. Many companies in the energy ecosystem are publicly listed, which aligns with the profile of counterparties involved in this type of business.”

Scaliter also cited the ability to build quickly on the XRPL EVM Sidechain before migrating to the mainnet, and flagged Ripple’s institutional legitimacy, as well as custody as a critical infrastructure consideration. He told The Defiant:

“XRPL, alongside contributions from Ripple, is well positioned to attract institutional investors. This global credibility and trust are essential for high-stakes, regulated use cases like energy tokenization.”

RippleX’s Judges elaborated on the architecture: “Justoken was looking for a way to bring renewable energy credits onchain that could support both traceability and automated compliance for corporate clients, while still fitting within existing custodial structures.”

YPF Luz and Its State-Backed Parent

YPF Luz is the power generation subsidiary of YPF (Yacimientos Petrolíferos Fiscales), Argentina’s majority state-owned oil and gas company. The nation’s largest crude producer was originally established over a hundred years ago as Argentina’s state oil company, but was privatized in 1999 and purchased by Spanish energy giant Repsol.

Advertisement

In 2012, Argentine President Cristina Fernández de Kirchner renationalized YPF, ousting Repsol after a dispute over slumping oil output and investment, Bloomberg reported at the time. Argentina’s Congress nationalized YPF through an overwhelming lower-house vote, clearing the way for President Fernández to sign the bill into law, per Reuters.

RWA Surge

XRPL has been steadily building its RWA credentials, and now has $1.5 billion in represented asset value on chain, and over $404 million in distributed asset value, per RWAxyz.

In late 2024, Ripple announced plans to tokenize the first-ever money market fund on XRPL, collaborating with UK-based digital securities exchange Archax and global investment firm Abrdn, as The Defiant reported. Last March, Ondo Finance deployed its tokenized short-term U.S. Government Treasuries product (OUSG) on the XRP Ledger, aiming to bring it to XRPL’s institutional user base.

Zooming out, the broader tokenized RWA market tripled from roughly $5.5 billion to $18.6 billion over the course of 2025, per The Defiant’s year-end analysis.

Advertisement

This article was written with the assistance of AI workflows. All our stories are curated, edited and fact-checked by a human.

Source link

Continue Reading

Crypto World

ZachXBT calls religion-backed $LAMB presale a 2026 ‘grift’

Published

on

Osmosis proposes OSMO-to-ATOM conversion to deepen Cosmos Hub ties

ZachXBT blasted YoungHoon Kim’s $LAMB presale as a religion-wrapped grift, pointing to botted engagement, recycled scam copy and a playbook he’s seen in prior fraud investigations.

Summary

  • On-chain investigator ZachXBT publicly questioned whether “grifting religion to promote a crypto token presale” is a viable strategy in 2026, targeting a token launch by self-proclaimed IQ 276 holder YoungHoon Kim.
  • Kim, who bills himself as a World Memory Championships-recognized genius, launched the $LAMB token on March 25 via Fjord Foundry, claiming all profits would go to building churches worldwide.
  • The presale’s sale marketcap reached $1.496 million with a fully diluted value of $6.804 million, while ZachXBT alleged the presale announcement relied on botted engagement.

Blockchain investigator ZachXBT fired a pointed public callout on March 26 at a religion-themed crypto token presale, asking on X whether “grifting religion to promote a crypto token presale for a glorified paid group is still a viable strategy in 2026.” The post drew 48,700 views, 1,200 likes, and 51 retweets within hours, touching off a wave of mockery and scrutiny across crypto Twitter directed at the project behind it: $LAMB, a token launched by YoungHoon Kim, who describes himself on X as the world’s highest IQ 276 holder and founder of @LAMB276_X.

Kim announced the presale on March 25 in a post that accumulated 176,000 views and 1,000 likes, writing: “Today, I launch my mission token to build churches across the world where Jesus Christ alone is Lord. Every profit belongs to His Kingdom because Jesus Christ is Lord.” The token was offered through Fjord Foundry, a decentralized token launchpad, with contract address 0x019E1f53Bf2EA52558c33feD363b491362c0d533. By the time ZachXBT weighed in, the presale had raised $51,910 against a token price of $0.246, a liquidity pool of $1.837 million, and a fully diluted valuation of $6.804 million.

Advertisement

Kim, who markets himself as a No. 1 Amazon bestselling author in Christian Apologetics and a Mensa member, had listed Conor McGregor — described as a “5-time World Champion” — as an advisor on the project’s promotional materials. ZachXBT’s screenshots of the LAMB276 website showed marketing language describing $LAMB as “the heartbeat of our community.” A separate reply by ZachXBT suggested the engagement surge around the presale announcement was artificial, writing: “Is botted engagement on a presale announcement considered high IQ?”

The $LAMB Token’s Playbook

The structure of the $LAMB presale follows a pattern that has drawn increasing scrutiny across the industry. The project issued a total supply of 276,000,000 tokens — a number mirroring Kim’s claimed IQ — and framed the sale as a “final sale” ahead of a broader community rollout. Commenter @serpinxbt noted in the replies that the project’s website copy “is clearly also based on historical crypto scams,” pointing specifically to phrases like “LAMB IS THE HEARTBEAT OF OUR COMMUNITY.”

ZachXBT is no stranger to flagging such operations. In March 2026, he exposed a coordinated network of over 10 accounts on X that used geopolitical panic to funnel users into pump-and-dump crypto tokens, with on-chain evidence suggesting the scheme generated six-figure profits. Earlier the same month, he accused employees at crypto trading platform Axiom of misusing internal tools to profit from insider trading — allegations that sent shockwaves through the decentralized exchange community.

Advertisement

The $LAMB situation fits a longer arc of celebrity- and identity-backed token launches exploiting cultural credibility to attract buyers. As CCN reported, Kim’s previous crypto price predictions — including forecasts for Bitcoin to reach $276,000 and XRP to hit triple-digit prices — had not materialized within their suggested timelines. The project had previously operated on the Solana blockchain before the current presale on Ethereum.

ZachXBT’s sardonic follow-up — “guess us plebs cannot possibly understand the grander vision since we’re not 276 IQ” — proved to be among the more viral lines in a thread that quickly went beyond crypto circles. @patty_fi summarized the community sentiment with blunt simplicity: “He’s using the prophet for profit!” As crypto.news has previously reported, social engineering and identity-based manipulation remain among the most effective — and recurring — vectors for retail crypto fraud in 2026.

Source link

Advertisement
Continue Reading

Crypto World

Mezo Taps Aerodrome To Support Token Trading On Base

Published

on

Mezo Taps Aerodrome To Support Token Trading On Base

Mezo, a Bitcoin-native lending protocol, will collaborate with Aerodrome Finance to support trading activity for its token and Bitcoin-backed stablecoin on the Base network, as projects look for ways to bring more financial use cases to Bitcoin.

In a Thursday announcement, Mezo said it will allocate 2.25% of its MEZO token supply to Aerodrome’s vote-escrow (veAERO) participants — users who lock tokens in exchange for governance rights and rewards. The program is designed to encourage those users to direct funds into MEZO trading pairs, increasing activity around the token and its US dollar-backed stablecoin, MUSD.

Aerodrome is a liquidity provider on Base built by the team behind Optimism, a configurable enterprise blockchain infrastructure.

The partnership links Base-based traders with a newer group of Bitcoin-focused applications, as developers experiment with adapting existing DeFi models to Bitcoin.

Advertisement

Mezo, which allows users to borrow against their Bitcoin (BTC) holdings, said it has issued more than 2,000 loans and helped move roughly $23 million in Bitcoin-denominated assets from Ethereum.

Mezo’s key metrics. Source: DefiLlama

The move gives Mezo access to a large and active DeFi user base on the Base network. Bitcoin-native applications often struggle to attract enough trading activity. On Base, infrastructure such as Aerodrome can help support more consistent trading in new tokens and stablecoins.

Related: Coinbase’s Base transitions to its own architecture with eye on streamlining

Bitcoin DeFi activity grows as new platforms emerge

Bitcoin is increasingly being positioned as a base layer for decentralized finance, driven in part by increasing institutional participation and long-term holders seeking ways to generate returns on idle assets.

Bitcoin-based DeFi activity has picked up since 2024, with a growing number of platforms aiming to bring lending, borrowing and yield strategies to the network.

Advertisement

Recent examples include Lombard, which is building Bitcoin-based lending infrastructure and has teamed with Bitwise to allow institutional investors to earn yield and borrow against their Bitcoin holdings.

Another project, Hashi, has recently launched on the Sui network with early participation from BitGo, Bullish and FalconX, among others. The platform enables users to earn yield on Bitcoin through onchain lending and borrowing.

Related: Babylon-Ledger tie-up expands access to Bitcoin Vaults for collateral use

Advertisement