South Korean Police Accidentally Post Cryptocurrency Wallet Password

South Korean Police Accidentally Post Cryptocurrency Wallet Password

Schneier on Security
Schneier on SecurityMar 17, 2026

Key Takeaways

  • Police leaked Ledger wallet recovery phrase publicly
  • $4.8 million in tokens stolen immediately after release
  • Seized assets belonged to 124 high‑value tax evaders
  • Incident exposes gaps in digital‑evidence handling procedures
  • Highlights need for stricter crypto custody protocols

Summary

South Korea’s National Tax Service inadvertently disclosed the mnemonic recovery phrase of a seized Ledger hardware wallet in a press release. The wallet held roughly $5.6 million in crypto assets seized from 124 high‑value tax evaders. Within minutes, thieves moved about $4.8 million worth of Pre‑Retogeum tokens to an external address. The blunder underscores serious lapses in handling digital‑asset evidence.

Pulse Analysis

The National Tax Service of South Korea has become the latest government body to seize cryptocurrency assets as part of a crackdown on high‑value tax evasion. In March 2026, agents confiscated a Ledger hardware wallet containing roughly 8.1 billion won (about $5.6 million) from 124 individuals under investigation. While the seizure itself demonstrated the agency’s technical capability, the accompanying press release unintentionally displayed a handwritten mnemonic seed—the master key that can reconstruct the wallet on any device. This oversight turned a secure cold‑storage asset into an open vault for anyone with basic crypto knowledge.

The immediate fallout was stark: within minutes of the announcement, cyber‑criminals transferred approximately 4 million Pre‑Retogeum (PRTG) tokens, valued at $4.8 million, to an external address. The incident mirrors earlier mishaps, such as the 2023 U.S. Treasury’s accidental exposure of a Bitcoin wallet seed, underscoring a systemic gap in handling digital‑asset evidence. For law‑enforcement, the loss not only erodes public trust but also raises questions about the chain‑of‑custody standards required for blockchain investigations. Regulators may now demand stricter protocols to prevent similar breaches.

Experts advise that agencies adopt dedicated crypto‑forensics units, employ air‑gapped systems for storing recovery phrases, and redact sensitive details before any public disclosure. As governments worldwide tighten crypto taxation and enforcement, the Korean case serves as a cautionary tale for balancing transparency with security. Investors and firms watching the regulatory landscape will likely factor in the heightened operational risk when assessing jurisdictional exposure. Ultimately, robust custodial practices will be essential to preserve the integrity of seized assets and maintain confidence in digital‑asset governance.

South Korean Police Accidentally Post Cryptocurrency Wallet Password

Comments

Want to join the conversation?