Security Breach of Korean Tax Agency Exposes Seed Phrase, Resulting in Loss of Millions

robot
Abstract generation in progress

A press release from the South Korean Tax Agency, issued on February 26, 2026, regarding the seizure of assets from delinquent taxpayers, inadvertently revealed a critical security mnemonic phrase. According to reports by Odaily Planet Daily, the documentation included a non-pixelated photograph showing a Ledger wallet with a handwritten recovery seed phrase, creating a significant security vulnerability that was quickly exploited.

How the Exposure of the Mnemonic Phrase Led to Asset Theft

The mnemonic phrase, also known as a seed phrase or recovery phrase, acts as the master key to access all funds stored in a cryptocurrency wallet. When a mnemonic phrase is publicly exposed, anyone can potentially recover the wallet and transfer the assets. In this case, the accidental disclosure by the government agency created an opportunity for malicious actors to exploit the security flaw.

Experts from the One Star University Blockchain Institute and data analyzed by Onchain confirmed that the exposure resulted in the theft of approximately $4.8 million in digital assets (equivalent to about 6.4 billion Korean won).

On-Chain Data Confirms Movement of 4 Million PRTG Tokens

On-chain analysis reveals that in the early hours of February 27, approximately 4 million PRTG tokens were transferred from the related wallet to an anonymous address. This transfer serves as irrefutable proof of theft, demonstrating how a compromised mnemonic phrase can be used to drain funds quickly and irreversibly.

Experts Criticize Cybersecurity Unpreparedness

Cybersecurity professionals harshly criticized the South Korean Tax Agency, arguing that the department demonstrates inadequate knowledge of basic digital security protocols. The incident highlights a critical deficiency in procedures for protecting sensitive information, especially when it involves documentation containing cryptographic keys. This failure directly resulted in a substantial loss of national assets, raising questions about the capacity of public agencies to handle blockchain technology and cybersecurity.

The episode serves as a warning about the importance of strict data protection policies, proper training in wallet mnemonic security, and internal review protocols before releasing any official communications involving cryptographic information.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin