South Korean police arrested two suspects over the alleged embezzlement of 22 BTC (~$1.5M) that had been held in police custody after a virtual asset company turned over a cold wallet during a 2021 hacking investigation. Reporting indicates required procedures to move seized crypto into a police-controlled cold wallet and vault were not followed; instead, the original third party retained control elements and later allegedly provided a mnemonic seed phrase to a hacker as part of a purported “loan” arrangement, enabling the attacker to recover the wallet and transfer the funds without police detection. The theft was reportedly uncovered during a National Police Agency audit triggered by a separate January 2026 incident in which 320 BTC went missing from the Gwangju District Prosecutors’ Office.
Separately, the U.S. Department of Justice announced the seizure of $61 million in USDT (Tether) tied to “pig butchering” cryptocurrency investment scams, stating the funds were traced to addresses used to launder proceeds stolen from victims. The DoJ described typical scam mechanics involving social engineering via dating/social messaging apps, coercion of trafficked workers in Southeast Asia–based scam compounds, and fraudulent investment platforms that display fabricated returns and impose additional “fees” when victims attempt withdrawals, with law enforcement emphasizing cross-border tracing and disruption of laundering infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
By February 28, 2026, South Korean police had arrested two individuals suspected of embezzling 22 Bitcoin that had been held as evidence since 2021. Reporting said the theft became possible after the original wallet-owning company later provided a hacker with the mnemonic seed phrase, allowing recovery of the private keys and transfer of the funds.
On February 27, 2026, the U.S. Department of Justice announced the seizure of $61 million in Tether allegedly linked to pig butchering cryptocurrency investment scams. Authorities said the funds were traced to addresses used to launder victim proceeds through many wallets to obscure their origin.
In January 2026, a separate case revealed that 320 Bitcoin had gone missing from the Gwangju District Prosecutors’ Office. The discovery prompted South Korea’s National Police Agency to audit virtual assets held by local police.
Since June 2025, Tether said it has frozen nearly $250 million tied to scam networks as part of broader efforts against illicit activity. This activity was later referenced alongside a DOJ seizure tied to pig butchering cryptocurrency scams.
In 2021, a virtual asset company handed over a cold wallet containing 22 Bitcoin to South Korean police as evidence in a hacking investigation. Police allegedly failed to transfer the assets to a police-controlled wallet and instead treated possession of the hardware wallet as control of the funds.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
tomshardware.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.