French Tax Hack Exposes 678,000 Citizens as Physical Crypto Crime Warns of Global Risk
A breach of France's national tax authority has added nearly 680,000 detailed financial records to a growing criminal data ecosystem, as physical attacks on crypto holders surge to levels that security researchers say should concern regulators worldwide.
A hacker operating under the alias ZeroBytes gained VPN access to an internal lookup tool at France's Direction Générale des Finances Publiques (DGFiP), the country's tax collection agency, and extracted records on 678,438 citizens, according to a report published by The Block on August 14. Security researchers at FrenchBreaches verified the dataset's authenticity. The stolen records include full names, home addresses, dates and places of birth, family status, dependents, tax identifiers, reference tax income figures, withholding tax rates, and administrative request histories.
Security analysts have noted that, taken together, that profile is detailed enough to identify high-net-worth crypto holders and locate them at home.
The breach did not occur in isolation. France has cycled through a series of overlapping data exposures over the past six years. Hardware wallet company Ledger, a French firm, lost records on more than 270,000 customers in 2020; France's data protection authority, CNIL, subsequently fined Ledger €750,000 in October 2024 for insufficient security. Municipal platform breaches compromised data on more than 14 million citizens between 2021 and 2024. A December 2025 attack on France's Interior Ministry exposed more than 16 million records. In January 2026, Waltio, a crypto tax-reporting platform, disclosed a separate breach affecting roughly 50,000 users that included email addresses, 2024 gain/loss figures, and cryptocurrency balances.
According to analysis by Today's Crypto News, LeveX, and the French Compliance Institute, criminal networks have been cross-referencing these datasets to build composite target profiles, matching names from the Ledger leak with income and address data from tax records.
The human cost of this compounding exposure is substantial. French Interior Minister Laurent Nuñez confirmed 77 crypto-related kidnappings, extortions, and attempted extortions in the first half of 2026 alone. That figure already exceeds the 45 incidents recorded across all of 2025, putting France on track to more than double its prior annual record. CertiK's Intel3D H1 2026 Wrench Attacks Report tracked 52 verified physical crypto attacks globally in the same period; France accounted for 33 of them, representing 63.5 percent of the worldwide total and 84.6 percent of all European cases. The same reporting period documented 16 kidnappings, four incidents involving torture, and one murder.
A wrench attack is a physical crime in which criminals use violence or coercion to force a crypto holder, or their family members, to reveal seed phrases, unlock wallets, or transfer funds.
The tactic bypasses digital security entirely by targeting the person rather than the software. The moment that crystallized this threat in France came in January 2025, when David Balland, co-founder of hardware wallet company Ledger, and his partner were kidnapped. Balland reportedly had a finger severed before police rescued the couple. Security researchers and investigators widely described the case as the watershed moment that accelerated criminal interest in physical crypto attacks across France and established it as arguably the highest-profile incident of its kind in European history.
CertiK's data shows home invasions jumped from one incident in H1 2025 to 20 in H1 2026. CertiK's broader estimate, which includes ransoms, coerced transfers, and frozen assets, put total financial exposure at $124.1 million for the first half of the year. Average loss per incident rose from $270,000 in H1 2025 to $2.39 million in H1 2026, a roughly 12-fold increase. Chainalysis separately documented more than $30 million in direct crypto theft via violence over the same period, a narrower figure that captures only confirmed on-chain losses.
A separate case illustrates the insider threat dimension. Ghalia C., a 32-year-old former DGFiP employee in the Paris area, was convicted on charges including aiding and abetting organized criminal activity for selling dossiers on high-net-worth crypto holders to criminal networks for approximately 800 euros per record. Courts found no evidence she personally coordinated attacks; she is reportedly appealing.
The case offers a prosecutorial precedent for treating insider data theft as a distinct criminal offense, which may matter as other jurisdictions build similar tax reporting infrastructure.
Nuñez addressed ADAN, the Association for the Development of Digital Assets, in July with a three-pillar government plan covering intelligence sharing, a deeper partnership with ADAN, and better cross-agency coordination targeting organizers operating from abroad. "These are serious matters, and your concern is legitimate," he said. French authorities have arrested approximately 200 individuals and enrolled 724 people in a crypto holder rapid-alert protection system that launched in April 2026 and produced arrests within hours in at least one documented case.
The regulatory backdrop sharpens the risk. The European Union's DAC8 Directive, which took effect January 1, 2026, requires crypto asset service providers to report detailed customer transaction data to national tax authorities. A proposed French amendment would extend disclosure requirements to self-custody wallets holding more than 5,000 euros. Critics, including the French Compliance Institute, argue this architecture creates exactly the kind of centralized wealth database that criminals have already proven they can penetrate. Cédric Fontaine, a former military and police officer and CEO of Lima Groupe, warned in an analysis cited by Today's Crypto News that centralizing crypto holder information creates "a centralized digital database that criminals can exploit."
That concern extends beyond Europe. India holds an estimated 93 to 100 million crypto holders, the largest absolute user base of any country, and its tax authority has expanded mandatory transaction reporting obligations progressively since 2022. Local police in Maharashtra and Uttar Pradesh have documented several cases of coerced wallet access during robberies since 2022, suggesting the threat is not hypothetical. Nigeria processed roughly $92 billion in crypto transaction volume between July 2024 and July 2025. Both countries are building the kind of centralized exchange reporting infrastructure that France now demonstrates carries serious physical security consequences when breached. Nigeria recorded 281,500 breached accounts in Q1 2026 alone, and Africa's cybercrime losses rose from $192 million in 2024 to $484 million in 2025, a year-over-year increase of 152 percent.
In high-density urban environments with lower conviction rates for financial crime, analysts suggest the downstream risk from a local exchange breach or insider leak may be comparably or more acute than in France. CertiK's security recommendations, including multi-signature setups, MPC wallets, and time-locks, are largely designed for technically sophisticated users. In South Asia and Africa, where most holders access the market through centralized exchanges on mobile phones, exchange-level security becomes the primary line of defense against physical targeting.
Forbes Digital Assets reporting from February 2026 found that conviction rates for physical crypto crime remain extremely low and that criminal networks have been replacing arrested members quickly. The deeper problem, as the Ghalia C. case and the DAC8 rollout both illustrate, is structural: mandatory reporting databases are only as safe as their weakest human access point, and no firewall can eliminate the insider threat that comes with any system requiring human administrators.