Skip to content

Invest1 publisherNot yet confirmed elsewhere3 min readPublished

BasedApp's leak of passports tied to wallets bolsters the case against HMRC's crypto record demands

BasedApp said a breach exposed passport numbers and home addresses linked to customer wallets, without saying how many of its 100,000-plus users were hit. The leak gives Recap a live example in its fight against HMRC's draft power to demand crypto records without tribunal approval.

The Investor · Invest desk

How we use AISend a correction

What happened

  • The stolen records also held names, dates of birth, nationalities, emails and phone numbers, each sitting beside a customer's wallet address.
  • HMRC published draft reforms to its Schedule 36 information powers on July 13 within the Finance Bill 2026-27 papers, and the consultation closed on September 7.
  • Recap says the draft would let HMRC compel records from wallet software, block explorers, data vendors and hardware wallet makers that hold no customer assets.
  • Recap wants holdings and wallet addresses declared not reasonably required where historic sales data suffices, and a tribunal's approval before any notice issues.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • exposure If HMRC can compel records from non-custodial providers, holders' identities and holdings end up in more files, and identity plus holdings is the pairing that leaked in the French tax and Waltio cases.
  • decision HMRC has to choose between narrowing what a notice collects and adding a tribunal gate; the BasedApp leak argues for the first, because a judge's approval does not shrink the data held.
  • cost Without a tribunal step HMRC skips a hearing per notice, and the cost of an overbroad request shifts to holders who get no consent right and no appeal.
  • constraint BasedApp's leak came from a private KYC store, so on its own it cannot show that HMRC's copy would leak; the French tax employee case is the one tax-authority example in Recap's filing as reported.

BasedApp reportedly raised an $11.5 million Series A led by Pantera Capital and says it has passed 100,000 registered users [5][6]. That is about $115 of venture money per registered user [19]. The cost of a leaked home address falls on the customer. Cryptopolitan has tracked a rise in wrench attacks, in which victims are assaulted or kidnapped until they transfer their crypto [18]. France counted 77 crypto-linked kidnapping, detention and extortion cases or attempts by the end of June, against 45 in all of 2025 [14]. The first half alone ran 32 ahead of the whole previous year [20].

BasedApp's file joins a run of identity leaks in the sector. Coinbase has said an attacker paid off support contractors abroad to pull customer data, passport and driver's license images among it [16]. In September, reports tied IDScan.net to a collection on a cybercrime forum billed as containing more than 170 million identity documents [17]. A leak at ShipMonk, Trezor's fulfillment partner, affected roughly 80,700 users [13].

Recap's case is that HMRC's draft adds more places where such records sit. Its filing cited a 2024 case in which a French tax administration employee allegedly sold the names, addresses and wallet balances of declared crypto holders [11]. It also cited the January 2026 breach at Waltio, a French crypto tax software provider, where 50,000 users' gains, losses and balances were exposed and a hacking group then sent ransom demands [12]. Both leaks paired identity with holdings. Recap says the draft reaches much wider than the UK's existing Cryptoasset Reporting Framework rules [10]. HMRC is not relying on that framework alone. Its draft adds a compulsory notice that needs no taxpayer consent and cannot be appealed [9].

The Finance Bill 2026-27 text can go three ways [7]. HMRC can adopt Recap's first ask, its second, or neither [15]. I think the BasedApp file argues for narrowing what a notice collects more than for a tribunal gate. A tribunal decides whether a notice issues. It does not cut the number of fields collected or the number of places they are stored afterward, and BasedApp's leak came out of KYC records the company held for its own customer checks [2].

The counter-thesis is that the breach says little about HMRC. BasedApp would have held the same file with or without a Schedule 36 notice, and calling the incident the exact harm Recap cites is Cryptopolitan's framing [1]. The ShipMonk case is the one that would prove my view wrong. Attackers got names and home addresses from that exploit [13], and a list of where hardware wallet buyers live is a target list without any wallet address attached. If the French cases trace back to leaks of that kind, keeping wallet addresses out of HMRC's demands protects holders less than Recap's wording assumes.

What to watch

  • Whether BasedApp discloses how many customers were in the stolen file and whether any funds moved.
  • The Finance Bill 2026-27 text after the September 7 consultation close: whether HMRC adds a tribunal step, carves holdings and wallet addresses out of what is reasonably required, or keeps the draft.
  • Any ransom demands or physical attacks traced to the BasedApp records, as followed the Waltio breach.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence42
Adoption
Insufficient
Hype gap+28
Incentives55
Confidence45
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Cryptopolitan describes the BasedApp incident as the exact harm Recap and others cite in opposing HMRC's draft information powers.

  2. [2]

    BasedApp disclosed through TokenPost on October 8 that an unauthorized party breached its internal operations system, exposing customer KYC records tied to crypto wallet addresses.

    ReportedSupportedSource: BasedApp, via TokenPost, as reported by CryptopolitanView cited source
  3. [3]

    The stolen records include names, dates of birth, nationalities, home addresses, passport or Singapore national ID numbers, email addresses and phone numbers alongside customer wallet addresses.

    ReportedSupportedSource: CryptopolitanView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. cryptopolitan.com

    1 article · October 8, 2026

    BasedApp breach ties names to wallets, fueling the fight over HMRC's new crypto powers

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Loading related stories