Invest1 publisherNot yet confirmed elsewhere3 min readPublished
BasedApp's leak of passports tied to wallets bolsters the case against HMRC's crypto record demands
BasedApp said a breach exposed passport numbers and home addresses linked to customer wallets, without saying how many of its 100,000-plus users were hit. The leak gives Recap a live example in its fight against HMRC's draft power to demand crypto records without tribunal approval.
The Investor · Invest desk
What happened
- The stolen records also held names, dates of birth, nationalities, emails and phone numbers, each sitting beside a customer's wallet address.
- HMRC published draft reforms to its Schedule 36 information powers on July 13 within the Finance Bill 2026-27 papers, and the consultation closed on September 7.
- Recap says the draft would let HMRC compel records from wallet software, block explorers, data vendors and hardware wallet makers that hold no customer assets.
- Recap wants holdings and wallet addresses declared not reasonably required where historic sales data suffices, and a tribunal's approval before any notice issues.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- exposure If HMRC can compel records from non-custodial providers, holders' identities and holdings end up in more files, and identity plus holdings is the pairing that leaked in the French tax and Waltio cases.
- decision HMRC has to choose between narrowing what a notice collects and adding a tribunal gate; the BasedApp leak argues for the first, because a judge's approval does not shrink the data held.
- cost Without a tribunal step HMRC skips a hearing per notice, and the cost of an overbroad request shifts to holders who get no consent right and no appeal.
- constraint BasedApp's leak came from a private KYC store, so on its own it cannot show that HMRC's copy would leak; the French tax employee case is the one tax-authority example in Recap's filing as reported.
BasedApp reportedly raised an $11.5 million Series A led by Pantera Capital and says it has passed 100,000 registered users [5][6]. That is about $115 of venture money per registered user [19]. The cost of a leaked home address falls on the customer. Cryptopolitan has tracked a rise in wrench attacks, in which victims are assaulted or kidnapped until they transfer their crypto [18]. France counted 77 crypto-linked kidnapping, detention and extortion cases or attempts by the end of June, against 45 in all of 2025 [14]. The first half alone ran 32 ahead of the whole previous year [20].
BasedApp's file joins a run of identity leaks in the sector. Coinbase has said an attacker paid off support contractors abroad to pull customer data, passport and driver's license images among it [16]. In September, reports tied IDScan.net to a collection on a cybercrime forum billed as containing more than 170 million identity documents [17]. A leak at ShipMonk, Trezor's fulfillment partner, affected roughly 80,700 users [13].
Recap's case is that HMRC's draft adds more places where such records sit. Its filing cited a 2024 case in which a French tax administration employee allegedly sold the names, addresses and wallet balances of declared crypto holders [11]. It also cited the January 2026 breach at Waltio, a French crypto tax software provider, where 50,000 users' gains, losses and balances were exposed and a hacking group then sent ransom demands [12]. Both leaks paired identity with holdings. Recap says the draft reaches much wider than the UK's existing Cryptoasset Reporting Framework rules [10]. HMRC is not relying on that framework alone. Its draft adds a compulsory notice that needs no taxpayer consent and cannot be appealed [9].
The Finance Bill 2026-27 text can go three ways [7]. HMRC can adopt Recap's first ask, its second, or neither [15]. I think the BasedApp file argues for narrowing what a notice collects more than for a tribunal gate. A tribunal decides whether a notice issues. It does not cut the number of fields collected or the number of places they are stored afterward, and BasedApp's leak came out of KYC records the company held for its own customer checks [2].
The counter-thesis is that the breach says little about HMRC. BasedApp would have held the same file with or without a Schedule 36 notice, and calling the incident the exact harm Recap cites is Cryptopolitan's framing [1]. The ShipMonk case is the one that would prove my view wrong. Attackers got names and home addresses from that exploit [13], and a list of where hardware wallet buyers live is a target list without any wallet address attached. If the French cases trace back to leaks of that kind, keeping wallet addresses out of HMRC's demands protects holders less than Recap's wording assumes.
What to watch
- Whether BasedApp discloses how many customers were in the stolen file and whether any funds moved.
- The Finance Bill 2026-27 text after the September 7 consultation close: whether HMRC adds a tribunal step, carves holdings and wallet addresses out of what is reasonably required, or keeps the draft.
- Any ransom demands or physical attacks traced to the BasedApp records, as followed the Waltio breach.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence42
- Adoption
- Insufficient
- Hype gap+28
- Incentives55
- Confidence45
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Cryptopolitan describes the BasedApp incident as the exact harm Recap and others cite in opposing HMRC's draft information powers.
ReportedSupportedSource: Cryptopolitan2 sources— create a free account to open themView cited source - [2]
BasedApp disclosed through TokenPost on October 8 that an unauthorized party breached its internal operations system, exposing customer KYC records tied to crypto wallet addresses.
- [3]
The stolen records include names, dates of birth, nationalities, home addresses, passport or Singapore national ID numbers, email addresses and phone numbers alongside customer wallet addresses.
- [4]
BasedApp has not revealed how many users were affected by the breach or whether any funds moved.
- [5]
Based reportedly raised $11.5 million in a Series A led by Pantera Capital.
- [6]
Based said it had passed 100,000 registered users.
- [7]
HMRC on July 13 published draft legislation reforming its Schedule 36 information and inspection powers, part of the Finance Bill 2026-27 documents released for technical comment; the consultation closed on September 7.
- [8]
Recap CTO Ben Shepheard pointed out that the new rule would allow HMRC to issue compulsory demands for records to any "person who provides services relating to cryptoassets," meaning wallet software, block explorers, data vendors and hardware wallet makers, none of which hold customer assets.
ReportedSupportedSource: Recap response to HMRC draft, as reported by CryptopolitanView cited source - [9]
A notice under the draft would need no tribunal sign-off or taxpayer consent and cannot be appealed.
- [10]
Recap said the scope of the amended rule would be much wider than the UK's existing Cryptoasset Reporting Framework rules.
- [11]
Recap referred to a 2024 case in which an employee of the French tax administration allegedly sold the names, addresses and wallet balances of declared crypto holders.
- [12]
Recap cited a January 2026 breach at Waltio, a French crypto tax software provider, that exposed 50,000 users' gains, losses and balances, after which a hacking group sent ransom demands.
- [13]
ShipMonk, Trezor's fulfillment partner, suffered a leak affecting roughly 80,700 users; attackers gained a list of names and home addresses.
- [14]
France had 77 crypto-linked kidnapping, detention and extortion cases or attempts by the end of June, up from 45 in all of 2025.
- [15]
Recap wants HMRC to state that users' current holdings and wallet addresses are not "reasonably required" when historic sales data provides the needed information, and wants a tribunal's approval required before HMRC can issue any notice.
- [16]
Coinbase disclosed that a threat actor bribed overseas support contractors to extract customer data, including passport and driver's license images.
- [17]
IDScan.net was reportedly linked in September to a cybercrime-forum collection advertised as holding more than 170 million identity documents.
- [18]
Cryptopolitan has tracked a rise in violent wrench attacks, in which victims are assaulted or kidnapped to force them to transfer crypto.
- [19]
BasedApp's Series A works out to about $115 per registered user.
- [20]
France's count of crypto-linked kidnapping, detention and extortion cases or attempts by end of June exceeded the full-year 2025 count by 32.
Sources
1 independent publisher whose own reporting we read for this story.
- cryptopolitan.comBasedApp breach ties names to wallets, fueling the fight over HMRC's new crypto powers
1 article · October 8, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Entities
- BasedAppFollow
- HM Revenue and CustomsFollow
- RecapFollow
- Ben ShepheardFollow
- Pantera CapitalFollow
- Cryptoasset Reporting FrameworkFollow
- WaltioFollow
- ShipMonkFollow
- TrezorFollow
- CoinbaseFollow
- IDScan.netFollow
- TokenPostFollow
- CryptopolitanFollow