On September 7, a blockchain used to move bitcoin between exchanges lost around $320 million in a single exploit. It was a dramatic number, and it dominated the week. It is also, in a strange way, the recoverable kind of loss. The funds moved on a public ledger, so every transaction is visible, and the attacker appears to be a white-hat already negotiating their return. Stolen money onchain, a discoverable rival good, can sometimes be observed, traced, frozen, and even given back.
The unfixable breaches that should keep us up at night make far smaller headlines, precisely because what they takek cannot be returned. In the same time frame of the $320 million hack Trezor confirmed that a further 67,000 customers had their names, phone numbers and home addresses exposed through a shipping vendor. A separate leak put roughly 200,000 records into the open, with government ID numbers sitting beside verified wallet addresses. Address data stolen from a hardware wallet maker back in 2020 is still arriving as physical mail demanding bitcoin, six years later. You can rotate a compromised key. You cannot as easily, quickly, or safely rotate your home address, your face, or your passport number.
Evin McMullen is co-founder and CEO of Billions Network, which builds privacy-preserving digital identity for people and A.I. agents.
This friction is the part of the security conversation we keep skipping. Every layer of the connected technology industry that touches the real world collects identity data. Crypto exchanges verify who you are. Hardware wallet makers collect your physical shipping address. On-ramps store your vital documents. Each becomes a repository of private data critical to their offerings and to the lives of their customers, each transforming with scale into a separate honeypot: a centralized store of highly sensitive data, a growing pile of static value sitting neatly on a server somewhere, waiting to be breached. The stolen $320 million is a wound that can potentially heal — tokens can be returned, identical money can be earned in the future. A leaked identity file is a scar that spreads, because once your name is linked to an address whose balance anyone can read onchain, that link is permanent and public.
The debate is stuck on the wrong axis. We argue about whether platforms were secure enough, whether they patched quickly enough, whether users held their keys correctly. All of it assumes the data had to be collected in the first place. It did not. Verifying a fact about someone and collecting their identity are different operations, and we have known how to separate them for years. A vendor can confirm you are a real, sanctions-cleared customer without keeping your passport on a server. You can prove you are authorized to withdraw without handing every counterparty a copy of who you are. Minimum disclosure: the fact is verified and discarded. No identity collected means no honeypot created, and nothing left to leak, sell, or mail to your door.