Paddle 412
At a Christie's evening sale the lot everyone came for is bought by a specialist standing at a bank of telephones. The room watches the specialist. The buyer is a voice.
Leonardo's Salvator Mundi sold in November 2017 for $450.3 million. Alex Rotter, then co-chairman of post-war and contemporary art, held the handset. The catalogue said nothing. It took a newspaper investigation to establish that the bidder was acting for Saudi Arabia. The most watched art transaction in history, and not one person in that room knew who had bought it.
That is not an exception, it is the default setting. Registration is confidential. The auctioneer says "sold, paddle 412". Catalogues print Property from a Distinguished Private Collection or Property of a Lady. Museum labels print Private collection. Dealers do not publish buyer lists, because the buyer list is the business.
Underneath the discretion there are layers, and each one is load-bearing. An advisor bids in their own name. Title sits in a Delaware or Liechtenstein entity. The object never leaves a bonded warehouse. The collector appears nowhere in the chain except as a beneficiary of a structure.
Four reasons, and only one is about money
Price. A collector known to want Basquiats pays more for Basquiats. Every room they walk into reprices around them. The advisor exists partly so that the market cannot read the appetite.
Safety. High value, portable, and sitting in a house. Dresden's Green Vault lost roughly €113 million of jewels in one night in 2019. Kim Kardashian was tied up in a Paris bathroom in 2016 and robbed of a ring the thieves had watched her post online. Members of that gang said afterwards that social media was how they found her.
Family. Divorce, inheritance, staff, and relatives who now know exactly what is on the wall and roughly what it is worth.
Becoming a mark. The moment you are known to own the thing, every dealer, every charity board, every fundraiser and every thief has your name on a list.
Three of those four are the same reasons a wallet goes pseudonymous. The art market simply solved for them two hundred years earlier, and with different tools.
The inversion
Here is the difference that matters, and it is not a matter of degree.
The traditional collector's name is known to the auction house and their holdings are secret. The crypto anon's holdings are known to everybody and their name is secret.
Same word, opposite structure, and the second one is much weaker. Not because the cryptography is worse. It is far better. Because of what each arrangement asks its secret to do.
A portfolio is a hard secret. It lives in one vault ledger, one insurance schedule, one confidential register that an institution is legally bound to keep and can be sued for losing. It has few copies and each copy has a name attached to its custody.
A legal name is a soft secret. It is in every exchange onboarding packet, every support ticket, every tax filing, every delivery address, every domain registration, every conference lanyard, and every database that any of those parties has ever failed to protect. It has thousands of copies and no custody chain. It only has to leak once, and it does not leak back.
So the anon is defending a public balance sheet with a single soft secret held in copy by dozens of third parties, most of whom they will never meet. That is the whole exposure. In 2026 it was priced.
Two counts of the same year
The year the room came to the collector
A wrench attack is a physical coercion incident: violence, confinement or credible threat used to make somebody hand over keys, unlock a device, or sign. Two firms counted 2026 independently and did not agree, which is worth showing rather than averaging away.
CertiK Intel3D, first half of 2026
Verified incidents
52
Up from 39 in H1 2025. A 33.3% rise.
Recorded exposure
$124.1m
Demanded, transferred and frozen, not stolen. Up from $10.5m.
Home invasions
20
Up from a single publicly reported case.
European share
75%
39 of 52 incidents, against 35.9% a year earlier.
Chainalysis, 2026 to late June
Documented incidents
46
Against 40 at the same point in 2025.
Actually stolen
$30m
Money that moved. 2025 finished at $58m, a record.
Attempts that paid
26%
12 of 46. It was 49% in 2025 and 67% in 2024.
Kidnapping share
52%
Home invasion 37%, by dominant outcome.
Both are right. The gap is definitional, and each half of it is worth knowing. CertiK counts recorded exposure, so a ransom demanded and never paid still lands in the total; Chainalysis counts value that actually moved on chain. Run Chainalysis on the wider basis and 2026 is around $107 million so far, against $180 million in 2025 and $316 million in 2024.
The attack-type split disagrees for a reason worth borrowing. Chainalysis classifies by what happened to the victim, so an incident that starts at a front door and ends with somebody being moved is recorded as a kidnapping. Other trackers classify by how the attacker got in, which makes the same event a home invasion. Reclassify about six of the 2026 kidnappings that way and home invasion becomes the largest category, which is how CertiK reports it. The events are identical. Only the label moves.
The number that should worry a holder is not either total. It is that three quarters of attempts in 2026 produced no payment, against a third failing two years ago. Attacks are getting more common and less effective at the same time, which is what happens when a target list stops being expensive.
Everything above is the visible portion. Victims do not report, police file these as ordinary robbery, ransoms go unrecorded, and settlements stay private. Every figure here is a floor.
Figures from CertiK's Intel3D H1 2026 Wrench Attacks and Chainalysis. We produced neither and have not independently verified the underlying incidents.
The attack is clerical work with a violent last step
The tactical shift in 2026 was not violence. It was that target selection became a desk job.
The old model needed a visible mark: the flex, the conference photo, the car. The new model does not need to watch anybody. A target package is assembled from leaked databases, exchange customer records, tax and compliance files, social profiles, ENS names, property registers, phone intelligence and public chain activity. Full name, home address, family structure, employer, estimated holdings, travel habits. The physical attack is the final stage of a process that is mostly research.
The reports are blunt about where the research comes from. A national employment agency compromised. A government portal issuing identity documents, passports and driving licences breached, with up to nineteen million citizens exposed: name, address, date and place of birth, phone number, identity verification data. Kraken disclosing an extortion attempt after malicious insiders in its client-support environment recorded systems showing client data. Criminal forums openly recruiting staff at exchanges and other data-rich firms for internal access.
The chain tells them how much. The leak tells them who and where. No amount of key discipline touches either half.
One correction to how that is usually stated, and it came out of checking these cases rather than out of theory. The danger is normally described as identity, location and a wealth signal landing in one file. But the French tax-reporting breach of January 2026 exposed no address at all, only an email address and a per-asset balance, and it is the corpus a court heard in July 2026 had been used to spot the victim of an attempted kidnapping. Meanwhile a hardware wallet order list containing no balances produced counterfeit devices posted to people's homes.
So the two columns are not symmetric. A location is commodity: it sits in every other breach corpus, in electoral rolls, in data brokerage, in a courier's system. A verified wealth signal bound to any durable identifier is scarce, and an email address is a perfectly good identifier. Protect the wealth signal and assume the location is already public.
The five ways in, in the order the datasets find them: the doorbell, where an attacker arrives as a delivery driver, utility worker, neighbour or police officer. The fake meeting, where a victim is invited to an over-the-counter trade or an investment pitch in a room the attacker controls. The transit interception between two predictable points. The proxy, where a spouse, parent, child, driver or assistant is taken instead, because they have weaker security and produce more leverage. And the acquaintance, who supplies the routine.
One line in the Chainalysis analysis describes the whole business model better than a page of ours could. The tradecraft is amateur at the point of violence and professional at both ends. Selection is data work. Laundering is data work. The part in between, the part in your hallway, is increasingly outsourced to disposable low-skill crews recruited through messaging apps for a fixed fee.
What happened in France, and what can actually be said
The clearest evidence that this is a data problem rather than a crypto problem is a natural experiment nobody wanted to run, and we had a seat for it. What follows is a former resident's reading of the public record rather than a view from outside it.
Before 2025, France recorded a handful of crypto-related violent incidents in total, well under one a month. In July 2025, during an investigation into a violent assault, a tax administration employee at the Bobigny centre was placed under formal investigation. Examination of her workstation was later reported to show unjustified consultations of a tax application covering, among others, cryptocurrency investors who had declared digital asset gains.
That paragraph is deliberately weaker than the one this page carried when it first went up, and the correction matters. She is charged with complicity in a violent assault on a prison officer, not with any cryptocurrency offence. The consultations are investigative findings rather than counts in the indictment. No number of consulted files has ever been published. No purchaser or intermediary has been identified or charged. And every crypto-specific detail in circulation, including the version once printed here, descends from a single paywalled newspaper report. The industry has built a settled narrative on one article, and this page was repeating it.
Incidents went to 19 in 2025, then 30 publicly known by the middle of 2026. The rate went from under one a month to 1.9 a month, then to about 4.6. Chainalysis puts the country roughly 48 attacks above its own historical baseline and names data exposure, rather than asset prices, as the likeliest cause. The interior minister, counting on a broader definition, put the true figure past seventy.
Two things happened in January 2026. The tax case became public, and a crypto tax-reporting firm disclosed a breach of some fifty thousand users. Both events are about tax data. Neither is about a wallet, and that is the only claim this page needs.
It spread the way information spreads rather than the way crime usually does. The Paris region stayed the centre, but 2026 reached Strasbourg, Marseille, Grenoble, Toulouse, Nantes and a string of small communes that had never recorded an incident of this kind. Crime spreads from a centre; information does not. The response has been serious: roughly two hundred arrests, 88 indictments and 75 people held before trial by mid-2026, and the arrests have not brought the incident count down. The kidnapping wave sits with the national organised-crime prosecutor. The insider case above does not: it is with an ordinary regional prosecutor, and no public record connects the two.
What can be said without stretching anything: nobody hacked a wallet, nobody broke any cryptography, and the one country where these attacks concentrated is also the country running two live stories about tax data escaping. Whether the first caused the second has not been established by any court, and the honest position is that it is the likeliest explanation on offer and still an inference.
Who is actually in your house
Stolen funds have to move, and how they move says who took them. Chainalysis sorts attackers into three tiers by their on-chain behaviour afterwards, and the tiers matter because they change what you should do.
The first tier does not really understand crypto. Funds go straight from the victim to a centralised exchange with no attempt at obfuscation, because the attacker thinks of coins as one more thing to sell. These are the most recoverable cases in the dataset. Compliance teams freeze, subpoenas name the account holder, and the money sometimes comes back. This is the entire reason the freeze list below is worth writing down before you need it.
The second tier knows the terrain. Decentralised exchanges, bridges, MEV bots, hops across chains, deliberate avoidance of the venues that run compliance programmes. Slower to trace, and often traced anyway.
The third tier is not a crypto crew at all. In documented cases the funds pass through an instant exchange and into what looks like an over-the-counter laundering service, and those services have prior contact with cartel money laundering, a trafficking network, terrorist financing clusters, and Southeast Asian guarantee networks. The violence against a crypto holder is one input into a laundering business that existed before crypto and will outlast this cycle.
Which is the argument for compliance, stated coldly. The organisers may be professionals with a laundering desk, but the person standing in your hallway is usually a stranger hired through an app for a fixed fee, with no stake in the outcome and no plan for it going wrong. That is not somebody to negotiate with, and it is a very good reason to have already made the negotiation short.
The art market already solved this, and not with secrecy
Every anti-coercion control the security industry now recommends already exists in the art world. Most of it predates photography. It is worth reading the two columns side by side, because the crypto version keeps being presented as novel.
The company with two directors
Multi-signature and MPCTitle sits in an entity, and no single officer can sell. A trust does the same thing with a protector who has to countersign. The structure is four hundred years old and its entire purpose is that one person, alone, in a bad hour, cannot act.
The bonded warehouse
Time locks and withdrawal delaysA Geneva or Singapore freeport opens on business hours, under a two-key protocol, to a named representative. You cannot get your own painting at three in the morning. Neither can the man standing behind you at three in the morning.
One work on the wall, the rest in storage
Staged vaultsSerious collections were never in the house. What hangs at home is what the owner is prepared to lose, and the insurer prices the difference. Nobody calls this a vault architecture. It is one.
The museum loan
Transfer frictionThe picture is on a five-year loan to a public institution in another country under a contract the owner cannot unilaterally break. It is a time lock with a curator attached, and it produces a receipt in the form of a wall label.
Advisor, entity, object, owner
Geographically distributed signersThe advisor is in London, the holding company is in Liechtenstein, the object is in a warehouse near an airport, and the owner is wherever they like. No two of those are in the same jurisdiction, and no one of them can complete a sale.
Read down that list and one property repeats. In none of these arrangements does the owner refuse. In all of them the owner cannot.
That is the only property that survives a room with a wrench in it. A person who will not comply gets hurt. A person who cannot comply, provably and within the first two minutes, is not worth hurting, because hurting them does not produce the money.
The 2026 numbers say this works. Three quarters of attempts now end with nothing paid, up from a third failing in 2024. Some of that is a wider and dumber pool of attackers, and some of it is that friction has been getting quietly better while the crime got louder. Either way the crews are finding out what the saleroom already knew, which is that value nobody can produce on demand is a bad thing to point a weapon at.
A decade of custody advice has optimised for the wrong adversary. Not your keys, not your coins is a defence against a custodian going under. It is not a defence against somebody in your kitchen, and against that person a single-signer hardware wallet in a drawer is close to the worst arrangement available: total, instant, irreversible authority, held by one frightened human who can be made to use it.
What to actually do
Three layers. The first reduces the chance you are selected. The second makes selection unprofitable if it happens anyway, and it is the only layer that works once somebody is already in the room. The third is the household, which is where both datasets say the year's growth went.
Layer one
Stop being findable
One statistic should settle any argument about whether this layer is worth the trouble. Almost every victim is attacked where they live. Of victims whose residency is known, the figure is 100% local in Sweden, 93% in France, 82% in Brazil and 77% in the United States. Nobody is being jumped because they were spotted in a bar. They were looked up, and then somebody drove to their house.
- Never let one address be both your name and your holdings. An ENS on the wallet that holds the collection is a brass nameplate on a vault door. Keep the named address near-empty and public. Keep the holding address unnamed, unposted, and never used to bid, sign a message, or claim anything in public.
- Never ship anything crypto-branded to your home. This is the single most expensive lesson the industry has already paid for and keeps re-learning. A locker, a business address, or a forwarding service.
- Break the join between handle and legal name. One conference badge with both on it, photographed once, ends your pseudonymity permanently and retroactively. Pick which one travels and be rigid about it.
- Strip the location data. Photographs of work on your wall carry GPS coordinates in EXIF, and a window, a skyline or a light switch identifies a building to anyone who cares to look. Post the work, not the room.
- Buy your address back. People-search and data-broker sites sell your home address for the price of lunch. Removal is tedious, it works, and it needs redoing every few months because they repopulate.
- Separate the phone number. A number tied to your legal name links every account you own. Use a distinct number for exchanges and custody, put a port-out lock on the carrier account, and remove SMS as a recovery factor everywhere, not just where it is optional.
- Treat every onboarding packet as a future breach. Identity documents, a selfie, proof of address and proof of holdings, in one file, held by a company whose support staff can read it. Minimise how many of those files exist. Prefer venues that delete rather than retain, and assume the rest will eventually be published.
- Audit your own back catalogue. Old interviews, podcast appearances, property records, company filings and photographs from five years ago are all still there, and they are where a target package starts.
Layer two
Make yourself unable to comply
- Nobody should be able to move everything. Two of three multi-signature, or MPC, with at least one signer in another country and one held by a party who is not at your dinner table. This is the whole ballgame. Every other control on this page is a supporting act.
- Put a clock on the vault. A queued withdrawal with a twenty-four or forty-eight hour cancellation window converts a forty-minute home invasion into a multi-day kidnapping with logistics, guards and exposure. That is a different crime with a different risk profile, and most crews are not equipped for it.
- Be able to prove the limit, fast. Duress ends when the attacker believes you. Know the exact sentence, and be able to demonstrate it on the device in front of them: the co-signer is elsewhere, the timer is on, the transaction is queued and visible and cannot be accelerated. "I will not" invites escalation. "I cannot, look" ends the negotiation.
- Fund a decoy properly. A hot wallet with a real, believable, genuinely painful balance and a real transaction history. An empty decoy is worse than none, because being caught lying is the moment these incidents turn violent. Price it as an insurance premium, not as a trick.
- The recovery material does not live where you live. A seed phrase hidden at home is a liability the moment attackers have an hour and no reason to hurry. Bank deposit box, or split across custodians, and never in the same building as the signing device.
- Spending caps and allowlists on everything that has them. Daily limits, destination allowlists, and a separate small wallet for anything that touches a new contract. Revoke approvals on a schedule, not after an incident.
- Write the freeze procedure down before you need it. The exact phone number and account-freeze process for every venue you hold anything at, on paper, plus a second person authorised to invoke it. In one Malaysian kidnapping last April, three million USDT was paid and 2.46 million was frozen and recovered. Speed did that.
- Remove your own unilateral authority. If you control a treasury, admin keys, deployment permissions or a multisig share, you are the reason your household is worth visiting. Split it before somebody else works that out.
Layer three
The household
In 2021 attacks aimed at a relation rather than the holder were near zero. By early 2026 they were a quarter to a third of all cases, and in France more than four in ten. That is the fastest-moving line in either dataset, and it is not an accident: a spouse, a parent or an assistant has weaker security, a more predictable routine, no training, and produces more leverage than the holder does.
So a holder who has secured themselves and not their household has done half the work and the wrong half. Most people will hold a line for their assets. Almost nobody holds one for a child.
- A code word, agreed and practised. One phrase that means: I am under duress, call the police, do not come home. It should be boring, usable in a normal sentence, and known to everyone including whoever collects the children.
- A door protocol that has no exceptions. Nobody opens the door to an unscheduled delivery, a utility worker, a neighbour with a problem, or a uniform. Verify by calling the company on a number you looked up yourself, never the one they offer. The doorbell is the most common entry in the dataset because it is the only one that costs the attacker nothing.
- A camera at the door and a rule attached to it. The rule is that nobody unlocks while the camera shows more than one person, or shows someone standing outside its frame.
- Take the children off the internet. No school name, no uniform, no sports club, no repeating times. The proxy vector runs on routine, and a school run is the most reliable routine most families have.
- Treat meetings as hostile until verified. Confirm the venue, the counterparty and the attendance through a channel you originated. A private over-the-counter trade with someone you met online is the second most common way into these incidents.
- Carry a travel phone. No wallets, no password manager, no exchange apps, no recovery email. What is in your pocket at a conference is what an attacker gets, and biometrics on your own device will be used against your own face.
- Vary the routine. Interception between two predictable points is its own category. Home, office, gym, hotel, airport, school. Change the times before you change the route.
If it happens anyway
Comply. Immediately and completely. Every asset on this page is replaceable and no person is. Do not fight for a wallet, do not stall to protect a balance, and do not gamble that they are bluffing. The entire point of building the architecture above is that full compliance still leaves most of it standing: you hand over everything you are able to hand over, and what you are able to hand over was decided months ago by you, calmly, and not tonight by them.
It also matters who you are complying with. The organisers may be professionals, but the person in the room is usually a stranger hired through an app for a fixed fee, with no stake in how the night ends and no plan for it going wrong. Arguing with an amateur holding a weapon is the worst position on this page.
Afterwards, in this order: police, then every venue on your freeze list, then chain analytics. Hours matter, and this is the one part where the public ledger is working for you. The least sophisticated attackers, who are a large share of them, send stolen funds straight to an exchange with no laundering at all, and those are the cases where compliance teams freeze and account holders get named. Frozen funds come back. Moved funds usually do not.
Where we stand, since we are telling you what to do
We have believed in being our own bank since 2013. We are not, any more, and it would be dishonest to publish the page above without saying so.
Our bitcoin and ether exposure sits in exchange-traded funds at an ordinary bank. There is no hardware wallet in this house.
The other thing to say plainly, since most of this page is about one country. We watched the French chapter from the inside, as residents and as customers of two of the companies named further down. We no longer live there and we are no longer customers of either. Much of what follows is written in the past tense for that reason, and none of it is a complaint about a country we chose, liked and left on good terms.
These are notes from a chapter that is closed, published because they cost us something to learn and because the next person should not have to pay for them twice.
Neither of those changes happened because self-custody failed. It never failed us, and the cryptography has never once been the weak part. They happened because the threat model moved, we were slow to notice, and then we were not.
Why the hardware wallet went
In July 2020 Ledger's e-commerce and marketing database was breached. Roughly 272,000 customer records with names, physical addresses and phone numbers, plus about a million email addresses. The file was published that December and has circulated ever since.
The devices were fine. No key was exposed, no seed was compromised, and the secure element did exactly what it was sold as doing. That is the entire point. The product worked and the customer list was the vulnerability, and a customer list is a directory of households that had recently spent money on storing cryptocurrency, with the address to deliver it to.
We used those devices from early on and we are not making a claim about the engineering. We are saying that owning one required handing a name and a home address to a company whose competence is building secure elements and not warehousing addresses, that the file leaked, that it cannot be unleaked, and that the report above counts twenty home invasions in six months.
A hardware wallet defends a key. Nothing about it defends the person holding the key, and by 2026 the person is the attack surface.
Two things we did not know when this page first went up, both of which make the case rather than weaken it. In October 2024 the French data protection regulator fined Ledger 750,000 euros over the 2020 breaches, on the duration of data retention and how it should have been secured. The decision has never been published, the amount became public only through a leak to the press, and in May 2026 a Paris judge refused to give the full finding to the civil victims because it might reveal choices of commercial value. Weeks earlier the same regulator fined a public employment agency five million euros for a comparable failure and published the whole thing.
And in January 2026 it happened again. Customer order data held by Ledger's merchant of record was accessed: names, contact details, postal addresses, phone numbers, order details. The same three columns, six years later, from the party the data had been moved to. Neither company has disclosed how many people were affected or the date range of the exposed orders, which is the fact that would say whether the retention Ledger promised to shorten in 2021 was ever shortened.
Moving the columns to a merchant of record is a relocation, not a split. A 2026 buyer still ends with their name, address and phone number in one commercial database, because a device has to ship somewhere.
Two companies we will not use again
Everybody gets breached. The question that separates a bad week from a bad company is what happened in the eighteen months afterwards, and we went and checked. This section names two firms, states what is on the public record about each, and then states our own conclusion, which is a judgement and is labelled as one. If either company can show any of it is wrong we will correct it the same day.
Ledger
In January 2021 Ledger said it would delete customer name, address and phone number as soon as possible, segregate order data three months after shipping, and examine every third party in its data supply chain. Five and a half years on: there is no public evidence the historical deletion was ever completed, no statement, no audit and no regulator confirmation saying how much or when. The three month segregation aim was stated once and never mentioned again. The 2026 breach happened at a third party in the data supply chain. And ISO 27001, which the company said in July 2020 it was taking steps toward, is still described on its own site as in process.
It has also never reconciled the roughly 9,500 affected buyers it announced in 2020 with the 272,853 buyer records that were dumped on a hacker forum that December, a file that is still circulating and that was still producing counterfeit devices in the post years later.
The part we find hardest to get past is not the breach. It is that a regulator investigated, found against the company on how long it kept your address and how it protected it, imposed a penalty, and you were never allowed to read the finding. The amount only became public because somebody leaked it. When the victims asked a court for the decision in May 2026, they were refused on the grounds that it might reveal choices of commercial value. Weeks earlier the same regulator published in full a larger fine against a public agency for a comparable failure.
One more thing worth knowing before subscribing to anything. Ledger Recover verifies identity through third-party providers and, per its own privacy policy, retains identity document data and a selfie for seven years after the last verification. Ledger Academy says the service has undergone independent security audits; no auditor is named and no report is published. Ledger's own pages disagree with each other on how many parties hold a share of a recovered seed.
Waltio
Three security incidents in twelve months. The one disclosed in January 2026 exposed, on the company's own account, an email address bound to a 2024 gain or loss figure and a per-cryptocurrency balance for around fifty thousand people. The company learned of it not from an alert but because the attacker emailed them a sample and a ransom demand.
An earlier intrusion, reported by the press in late January 2026 and not previously disclosed, involved roughly $550,000 taken from company treasury via a seed phrase kept in internal online tooling. An audit firm engaged afterwards reportedly found the company had no procedure for analysing administrator digital traces, leaving it blind to its own platform activity, found a critical lack of segregation between company data and client files, and recommended a complete system overhaul. The company was reportedly unable to produce proof that this earlier incident had been notified to the regulator. Its chief executive rejected any suggestion of concealment.
The consequence is the thing that decided it for us. Because those logs did not exist, the auditors could not determine whether client records were reached during that earlier event. So the exposure window may begin a year before the company noticed anything, and the scope of it is not merely unknown. It is unknowable, permanently, and no subject access request can fix that.
Since then: no named auditor, no published report, no ISO 27001, no SOC 2, no SecNumCloud, no published penetration test, no bug bounty, no vulnerability disclosure policy, no data minimisation programme, no retention reduction, no move to client-side computation, and no compensation or monitoring offered. Its public security page, read in August 2026, does not mention either incident. The business grew from roughly eighty thousand to a claimed hundred and fifty thousand users across the period. Nothing about that is illegal. It is simply what happens when nothing requires a company to do better.
What we are not saying
We are not saying either breach caused a specific attack. No court has established that. The strongest link on the record anywhere is press reporting of what was said at a hearing in the Somme on 31 July 2026, phrased in the conditional, in a case with no verdict. A separate claim by a criminal on a forum that the data enabled three kidnappings is an uncorroborated demand for money, the incidents it cites largely predate the breach, and outlets that repeat it with the confidence of the courtroom material are doing something we will not do here.
We are also not saying either company broke the law. One was penalised and the reasoning is sealed; the other has no regulator action on the public record at all, which is not the same as being cleared.
What we are saying is narrower and, we think, harder to argue with. Both companies made specific public commitments after losing customer data. In both cases the announcements are documented, the delivery is not, and the independent verification is absent entirely. On that record we would not hand either of them a name, an address or a balance again, and we would not advise anyone else to.
For the avoidance of doubt about where we are speaking from: we were customers of both. Both accounts are closed, erasure has been requested from each, and whatever answers come back will be published here, including if they are better than this section implies.
The alternative is not another vendor. It is holding less that is worth taking: a tax computation that runs on your own machine, a device bought to a locker rather than a doorstep, and an email address used for nothing else. That is the whole recommendation, and none of it requires trusting anybody.
The part you cannot opt out of
Both of those were choices. This next one is not, and it is why the two above were worth making.
DAC8 became applicable on 1 January 2026. Crypto-asset service providers operating in the European Union now collect reportable transaction data on every EU-resident user and pass it to tax authorities, which exchange it automatically between member states. Whatever you make of the policy, the mechanical output is a set of registries joining a legal name to a home address to a reasonably precise estimate of what somebody holds.
Now set that beside the record on holding the data that already existed. Further up this page: an employment agency and a national identity system breached at the scale of tens of millions, a tax-reporting firm losing fifty thousand identity-keyed balance sheets, unjustified consultations of tax files by somebody entitled to open them, and a country going from under one attack a month to roughly 4.6, spreading into towns that had never recorded one. Three quarters of the world's verified wrench attacks in the first half of 2026 happened in Europe, and the density of administrative records is the explanation both reports reach for.
We do not think those two things are unrelated. Building the registry and failing to hold it are two halves of one exposure, and the second half is the half no amount of personal discipline touches. There is no operational security practice that protects you from a database you are legally obliged to appear in.
None of this is a tax position. We file, we comply, and the policy case for transparency is a serious one that we are not arguing with. The security case is a different case, it points the other way, and it has not been made anywhere near as carefully.
Which is the uncomfortable part of this page. Every other control on it is something you can go and do this afternoon. This one is not a control at all. It is a standing condition of holding these assets, and the only decision left inside it is how much of your physical safety should rest on being a row in a table that keeps getting published.
What the bank buys, and what it costs
The trade, stated plainly, because anybody who recommends this arrangement without stating it is selling something.
Holding an ETF at a bank gives up censorship resistance, self-sovereignty, weekend settlement, and the ability to transact without asking. It accepts counterparty risk and seizure risk. Both are real, both have precedent, and neither is hypothetical: a bank can freeze you, a regulator can reach you, and a fund can be wound up on terms you did not pick. We know exactly what we handed over, and we gave up the part of this technology we spent a decade arguing for.
What we got back is narrow, and it is the whole subject of this page. There is nothing in the house to take. There is no key a threat can convert into a settled transfer. An institution cannot be coerced by frightening one family. Its transfers are traceable, its systems keep business hours, its staff answer to procedure rather than to whoever is standing in the room, and no quantity of pain applied to one person at three in the morning produces a wire.
It is the freeport, wearing a suit. Somebody else holds the object, they hold it somewhere nobody can reach in a hurry, and the delay is the product.
This is a disclosure, not a recommendation, and it is not investment advice. Most people reading it should not copy it. It is here because we are about to have opinions about your custody, and you are entitled to know where ours sits and what it cost to put it there.
The art is a different problem
You cannot put a Fidenza in an ETF. A collection is self-custodied, unavoidably, which means the argument above stops at the gallery door. Two things follow, and the first of them is good news.
Named work makes poor loot. Every headline case in either report was fungible: about €900,000 in bitcoin taken during a home invasion, a ten million USDT ransom demand in a kidnapping, roughly $24 million in a stablecoin in an assault. Crews want assets that launder, and they route them through chains and into Monero. A work with a public provenance record is the opposite of that. Every transfer is visible, marketplaces flag and delist it, and the buyer pool for a stolen grail is close to nobody. The same ledger that makes you findable makes your collection nearly unsellable by anyone else, and that asymmetry is on the collector's side.
The bad news is that the wallet is not the art. If the address holding the collection also holds liquid assets, or has live approvals, or is the one attached to your ENS and your profile, then the art is not the target. It is the advertisement. It is the thing that tells a stranger this address is worth a visit.
So separate them, and treat the named wallet as a shop window with nothing behind the glass.
One address carries the name, holds close to nothing, and does all the public work: bidding, signing, minting, claiming. A second address has never been named and never posted, receives from the first and never sends back to it, and holds the collection behind whatever multi-signature and delay you can live with. Nothing signs on a phone. Approvals get revoked on a calendar. It is not elegant, and neither is a freeport.
What the room knew
The auction room worked this out across three centuries and never needed cryptography for any of it. It needed intermediaries who could be sued, objects that could not move quickly, and owners who genuinely could not deliver on demand.
We rebuilt the first part out of mathematics, which was the hard one, and skipped the second and third entirely because they looked like friction. Somewhere between forty-six and fifty-two households found out last half-year why they were there, depending on whose count you take, and the difference does not matter to a single one of them.
Anonymity was never the defence. It was the thing that bought time while the real defence, which is being structurally incapable of handing everything over, did the work.