Thursday, October 8, 2026Live markets
BBTC$80,867.92 -2.93%EETH$2,420.76 -5.38%BBNB$721.33 -6.35%XXRP$1.33 -6.43%SSOL$106.18 -8.96%TTRX$0.3329 -0.59%HHYPE$83.14 -5.03%ZZEC$1,140.21 -13.35%DDOGE$0.0819 -7.45%XXMR$521.46 -6.03%LLINK$12.23 -8.54%AADA$0.2259 -11.74%XXLM$0.1872 -6.16%NNEAR$4.35 -16.24%
Security

BasedApp breach exposes KYC data tied to crypto wallets

CDBy · · 2 min read
BasedApp breach exposes KYC data tied to crypto wallets
In this article4 sections
  1. 01Key facts
  2. 02The timing problem for HMRC
  3. 03Why it matters
  4. 04What to watch

BasedApp said on October 8, 2026 that an unauthorized party reached its internal operations system and exposed customer KYC records, each tied to a crypto wallet address. The stolen data includes names, dates of birth, nationalities, home addresses, passport or Singapore national ID numbers, email addresses and phone numbers, Cryptopolitan reported.

The company has not said how many users were affected, nor whether any funds moved. BasedApp previously raised $11.5 million in a Series A led by Pantera Capital and said it had passed 100,000 registered users.

Key facts

  • BasedApp disclosed the breach on October 8, 2026, saying an intruder reached its internal systems and exposed customer KYC records linked to wallet addresses.
  • The stolen data spans names, dates of birth, nationalities, home addresses, passport or Singapore national ID numbers, emails and phone numbers.
  • HMRC published draft legislation on July 13, 2026 reforming its Schedule 36 information and inspection powers; the consultation closed on September 7.
  • Recap, a UK crypto tax firm, filed a response opposing the plan the same day it was published, arguing the rule would let HMRC issue compulsory demands to any person providing services relating to cryptoassets without tribunal sign-off, taxpayer consent or a right of appeal.
  • Recap cited a January 2026 breach at French crypto tax software provider Waltio in which 50,000 users’ gains, losses and balances were exposed, followed by ransom demands.

The timing problem for HMRC

The breach lands as HMRC weighs responses to a draft that would widen its reach well beyond the existing Cryptoasset Reporting Framework. Recap’s CTO, Ben Shepheard, has said the amended rule would allow demands to wallet software makers, block explorers, data vendors and hardware wallet manufacturers — none of which hold a customer’s assets.

The firm also pointed to a 2024 case in which an employee of the French tax administration allegedly sold the names, addresses and wallet balances of declared crypto holders. It has asked HMRC to tighten the wording so that current holdings and wallet addresses are not treated as reasonably required when historic sales data already answers the question, and to require a tribunal’s approval before any notice is issued. HMRC’s draft would take effect from Royal Assent, expected in spring 2027.

Why it matters

A leaked identity file matched to wallet addresses is more sensitive than a stolen email list, because it lets anyone who holds it map a person to a balance and a home. Attackers have used such lists for extortion and physical coercion, not just fraud. For UK crypto users, the practical question is whether the data companies already hold will grow under the new powers — and whether the safeguards attached to those powers keep pace with the harm when a provider is breached.

What to watch

BasedApp has not yet put a number on affected users, and that disclosure — along with any sign that funds moved — will sharpen or soften the case against HMRC’s draft. The Finance Bill 2026-27 language is the next fixed point, with Royal Assent currently expected in spring 2027.

Disclaimer: This article is for information only and is not investment, financial or trading advice. Cryptocurrency prices are highly volatile. Always do your own research.

Source: Cryptopolitan

CD

The CryptoNewsroom editorial desk covers Bitcoin, Ethereum, altcoins, DeFi, regulation and crypto markets. Editorial policy

Related stories