On September 7, a blockchain network used for transferring bitcoin across exchanges suffered a $320 million theft in a single exploit. It was an enormous figure that commanded the news cycle all week. In a peculiar sense, however, this is the type of loss that can be undone. Because funds travel across a public ledger, every movement is visible, and the perpetrator appears to be a white-hat hacker currently negotiating restitution. Stolen onchain funds, which represent a traceable asset, can occasionally be tracked, frozen, and given back.
The permanent breaches that ought to keep us awake at night generate far smaller headlines precisely because the data they steal cannot be restored. During that exact same timeframe, Trezor verified that an additional 67,000 users had their names, phone numbers, and physical addresses leaked through a delivery partner. A separate incident exposed roughly 200,000 files publicly, featuring government identification numbers right next to verified wallet addresses. Address details stolen from a hardware wallet manufacturer back in 2020 are still turning up as physical extortion letters demanding bitcoin six years later. You can easily swap out a compromised private key. You cannot just swap out, quickly or securely, your home address, your facial data, or your passport number.
Evin McMullen holds the role of co-founder and CEO at Billions Network, which develops privacy-focused digital identity solutions for individuals and artificial intelligence agents.
This friction represents the missing piece of our ongoing security dialogue. Every connected sector touching the physical world gathers identity records. Cryptocurrency platforms check your background. Hardware wallet creators store your shipping location. On-ramp services retain your essential paperwork. Each platform turns into a repository of confidential information vital to their operations and their users’ safety, eventually evolving into an individual honeypot at scale: a centralized storage vault filled with high-risk information, sitting statically on a server somewhere while awaiting a breach. The stolen $320 million is a wound that might eventually heal, since tokens can be recovered and identical wealth can be generated over time. Conversely, a leaked identity file leaves a widening scar because tying your name to a public wallet address creates an unalterable, permanent record.
Our current debate focuses on the incorrect concerns. We argue about whether platforms maintained adequate security, if they patched vulnerabilities fast enough, or whether users managed their private keys properly. Every one of those arguments assumes the information needed to be gathered initially. It did not. Authenticating a specific detail about an individual and gathering their raw identity are fundamentally different tasks, and we have known how to decouple them for years. A service provider can confirm you are a legitimate, sanctions-compliant client without keeping your passport on file. You can demonstrate withdrawal authorization without distributing copies of your identity to every single counterparty. Minimal disclosure means verification occurs and the data is discarded instantly. Collecting no identity means establishing no honeypot, leaving nothing behind to leak, sell, or mail directly to your residence.
We have witnessed this alternative scenario unfold before. When regulators demanded that websites secure user consent, they outlined the goal rather than the implementation method, prompting the market to introduce cookie banners—those annoying pop-ups you dismiss constantly without reading. The crypto sector engineered its own equivalent: upload your identification everywhere. A single passport photocopy stored across a hundred separate databases protects virtually nobody while enriching whichever entity happens to suffer the weakest security breach.
Furthermore, this situation is merely a preview. The internet is actively transitioning toward software that operates autonomously on our behalf, and the traditional classification of web traffic into simple categories like bots or humans is breaking down. A brand-new category is emerging: verified software agents executing transactions securely and with authorization for living people. These autonomous agents will shift capital around, requiring instantaneous proof of authorization and operational boundaries at machine scale and speed. If they inherit our current architecture and drag their human operators’ complete identities through every service they access, we will not merely have a few honeypots. We will maintain billions of them, constantly updated and active around the clock.
The $320 million will likely find its way back. The addresses, identification numbers, and facial scans will not. The primary takeaway from these recent events is not that we need stronger fortifications around the data we stockpile. Instead, we are hoarding data we never should have collected in the first place. The technological framework required to verify facts without surrendering personal details already exists: it is verifiable, private, and portable for both humans today and their software agents tomorrow. The only remaining question is whether we will adopt it before the honeypot solidifies as the permanent foundation of both worlds.
Note: The views expressed in this column are those of the author and do not necessarily reflect those of CoinDesk, Inc. or its owners and affiliates.
Originally published at https://www.coindesk.com/opinion/2026/09/16/a-stolen-coin-can-be-returned-a-leaked-identity-cannot.