A stolen coin can be returned. A leaked identity cannot.
On September 7, a blockchain used to move bitcoin between exchanges suffered an exploit that moved roughly $320 million; because those transactions are public, the author notes the funds may be recoverable and the attacker appeared to be negotiating a return. Evin McMullen, co-founder and CEO of Billions Network, argues the larger threat is widespread identity leakage—examples include a Trezor vendor exposure of about 67,000 customers and a separate leak of roughly 200,000 records—that cannot be undone once public.

Why It Matters
McMullen warns that stolen onchain funds can sometimes be traced and returned, whereas leaked personal identity data is permanent and can be used repeatedly; as AI agents acting for people proliferate, the risk multiplies if services continue to centralize identity data. The piece urges adoption of privacy-preserving, provable identity techniques to avoid creating billions of persistent "honeypots."
Key Facts
- date of bitcoin exploit: September 7
- amount moved in the exploit: around $320 million
- visibility of transactions: transactions moved on a public ledger
- attacker status (reported): appeared to be a white-hat negotiating return of funds
- trezor-related exposure: about 67,000 customers had names, phone numbers and home addresses exposed via a shipping vendor
A recent exploit on September 7 moved roughly $320 million through a blockchain used to transfer bitcoin between exchanges. Because those movements took place on a public ledger, the transactions are observable and—according to the author—there is a plausible path to recovering the funds; the attacker in this case appeared to be negotiating a return. That kind of loss, while dramatic, is in principle traceable and reversible in ways that many other breaches are not.
By contrast, Evin McMullen, co-founder and CEO of Billions Network, highlights a string of identity leaks that he says pose a deeper, longer-term threat. He cites a vendor incident that exposed names, phone numbers and home addresses for about 67,000 Trezor customers, and a separate breach that released roughly 200,000 records containing government ID numbers alongside verified wallet addresses. McMullen also notes that address data stolen from a hardware wallet maker in 2020 is still generating physical mail demanding bitcoin six years later—an illustration of how identity compromises persist.
McMullen argues the underlying problem is structural: many services collect and hold identity data they do not truly need, creating centralized repositories of highly sensitive information—"honeypots"—that become attractive targets. He draws a distinction between verifying a fact about a person and storing their identity; the former can be done without retaining passport copies or other documents, yet the industry has tended to aggregate full identity records across multiple vendors, often replicating the same sensitive documents in many databases.
Looking ahead, McMullen warns that the architecture problem risks expanding as software agents acting on behalf of people become common. These verified agents will need to authenticate and transact at machine scale. If they carry owners' full identities through every service they touch, the number of identity-bearing endpoints could balloon from a handful of honeypots into billions of continuously refreshed ones. The author calls for adopting provable, private, and portable identity technologies that confirm authorization without surrendering personal data, to prevent identity from becoming the permanent architecture of future systems.
Keep Reading

Google says some Pixel phone owners were hacked in zero-day attacks

Robots are waiting for a ChatGPT moment: Nvidia’s Les Karpas explains why at TechCrunch Disrupt 2026

AI Pause Would Help Dominant Firms, Not Safety, Think Tank Warns

The iPhone 18 Pro’s big camera update is all about the small gains
Original source: CoinDesk