South Korea’s National Tax Service (NTS) inadvertently exposed the mnemonic recovery (seed) phrase for a seized Ledger hardware wallet by publishing unredacted photos in an official press release about a tax enforcement operation targeting high-value tax evaders. Because the seed phrase functions as the master key to restore and control the wallet, the disclosure enabled an unknown actor to take full control of the seized crypto assets and move them off-wallet, turning a law-enforcement seizure into an immediate loss for the public treasury.
On-chain activity described in reporting indicates the attacker first sent a small amount of Ethereum (ETH) to the compromised wallet to cover gas fees, then transferred 4 million Pre-Retogeum (PRTG) tokens—valued at roughly $4.8M at the time—out to a new address in three transactions. The incident has been characterized by observers as a basic operational security failure in government handling of virtual assets, underscoring the need for strict redaction and custody procedures when documenting or publicizing seized cryptocurrency evidence.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
The NTS publicly apologized for exposing the wallet seed phrase and said it had asked Korea’s National Police Agency to trace the unknown perpetrator or perpetrators. The agency also said it had strengthened internal controls and revised procedures for seizing, storing, and disposing of virtual assets, with staff training to follow.
After the seed phrase exposure and resulting theft became apparent, the NTS took down the original press release from its website. The removal was cited across reports as part of the agency’s immediate response to the incident.
Within hours of the publication, an unknown actor used the exposed seed phrase to restore access to the wallet, funded transactions with a small amount of ETH, and transferred out about 4 million Pre-Retogeum tokens worth roughly $4.8 million. Reports describe the theft as occurring in the early hours of February 27 via multiple outbound transactions.
On February 26, 2026, the NTS published a press release with high-resolution photos of seized assets that included an unredacted handwritten mnemonic recovery phrase for a confiscated Ledger hardware wallet. The disclosure effectively exposed the wallet’s master key to the public.
South Korea’s National Tax Service carried out an enforcement operation against 124 high-value tax delinquents and seized assets including cryptocurrency. The confiscated haul was reported at about ₩8.1 billion, including a Ledger wallet holding millions of PRTG tokens.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
7 references tracked. Mallory keeps watching after this page renders.
tomshardware.com
Open sourcebitdefender.com
Open sourcescworld.com
Open sourcego.theregister.com
Open sourcedatabreaches.net
Open sourcerescana.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.