French Crypto Tax Platform Waltio Targeted in Extortion and Data Breach

LiveBTCNews
IN0,88%
  • Waitio was a target of the hacking group Shiny Hunters, and the resulting data breach may have leaked the data of nearly 50,000 crypto users.
  • Some of the stolen data included email addresses and transaction histories, which means that the victims are at risk of phishing and identity theft.
  • On the bright side, since Waltio uses “read-only” API keys, user funds on connected exchanges are safe.

This week, reports surfaced that Waitio, the popular crypto tax platform, suffered a major data breach.

This event quickly turned into an extortion attempt as a notorious hacker group claims to have stolen sensitive financial information from a massive database.

This incident shows a growing danger to investors who use third-party tools to manage their crypto taxes.

The Waltio Data Breach

As mentioned, Waitio was attacked by a hacking group known as the Shiny Hunters. According to reports, this organisation has a long history of attacking victims like tech giants and retail companies.

In the case of the Waltio data breach, the hackers allegedly gained access to a database containing the records of almost 50,000 users. Even worse, some of the stolen data includes email addresses, account balances and detailed transaction histories.

These also turn out to be the exact pieces of information needed to track a person’s assets on the blockchain.

The hackers are actively demanding a ransom and have threatened to leak the information publicly or sell it on the dark web if the company does not pay.

Why Tax Platforms Are Main Targets

Waltio acts as a “crypto assistant” for over 60,000 users in France and beyond, because it helps people calculate capital gains and generate forms for the tax authorities.

Customers use the tool by connecting their exchange APIs or uploading their wallet addresses. The tool then collects this and stores it all on a database.

And even though Waitio does not have the power to move funds on behalf of its users, the information itself is worth a fortune.

When criminals know exactly how much Bitcoin or Ethereum a user has, as well as a roadmap to all of their addresses, they can run highly targeted spear phishing attacks.

They might send an email that looks exactly like a tax notice, and is tailored to the user’s specific holdings. This type of leak could even lead to physical threats against wealthy individuals, as has been happening in Europe for the past year.

🚨 Armed teenagers carried out a violent “wrench attack” on high-profile Twitch and OnlyFans creator Kaitlyn ‘Amouranth’ Siragusa earlier this year, breaking into her home, pistol-whipping her, and demanding access to her Bitcoin after being misled by her online posts about… pic.twitter.com/vc8FNjUwcH

— Subjective Views (@subjectiveviews) December 9, 2025

Differences Between Data and Asset Security

Users need to understand the difference between their data and their actual funds. Based on how the platform operates, your crypto is likely safe from direct theft.

Waltio uses “read-only” API keys, which means the software can view a user’s trades but cannot execute “send” or “withdraw” commands. In other words, a hacker inside the Waltio system cannot drain anyone’s Binance or Coinbase account.

However, their identity is what is at risk here. The hack now has the emails, tax residency and total wealth of thousands of users.

Even users who use a hardware wallet and have synced it with the tax software now have their information exposed.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Articoli correlati

Circle 冻结 16 个热钱包 USDC 余额,涉及交易所等多家业务

Gate News 消息,3 月 26 日,据 ZachXBT 披露,Circle 于昨日(3 月 25 日)冻结 16 个业务相关热钱包中的 USDC 余额。相关企业表示,此举与一项尚未公开细节的美国民事案件有关。ZachXBT 称,经其查看链上数据,这些地址涉及交易所、娱乐场及外汇业务,彼此之间并无明显关联,此次冻结已对相关业务运营产生影响。

GateNews1h fa

Resolv 基金会暂停 Season 4 空投领取及 RESOLV 代币质押功能

Gate News 消息,3 月 25 日,Resolv 基金会宣布,鉴于近期 Resolv Labs 稳定币 USR 发生安全事件,协议和应用均已暂停,Season 4 空投领取功能暂时无法使用,RESOLV 代币的质押和解质押功能也暂时无法使用。一旦协议恢复计划最终确定,且应用可以再次安全使用,相关功能将会恢复。

GateNews11h fa

RootData 发布透明度警报,Hydration、Hyperbot 等 5 个 DEX 缺失核心信息

RootData 在推特上发布透明度警报,指出多个去中心化交易所信息缺失,呼吁项目方更新资料以提升透明度评分。该评分系统从 A 到 F 衡量信息完整性,评分低意味着更高的作恶风险,投资者需谨慎。

GateNews16h fa

Huione 关联地址向某 CEX 转入 20 万枚 USDT,一个月前曾提取 178 万枚

Gate News 消息,3 月 25 日,据 BlockSec Phalcon 监测,一个持续接收非法交易平台 Huione(汇旺)资金的地址向某 CEX 转入 20 万枚 USDT。该地址约一个月前曾分 3 笔从某 CEX 提取共计 178 万枚 USDT。

GateNews19h fa

名校畢業幣圈創辦人傳輕生!KOL爆料:壓力疑來自臭名昭彰造市商

Network3創辦人Rock被曝已於去年輕生,社群指出其承受來自社群、團隊及投資人的多重壓力。KOL指出,Rock的樂觀個性在幣圈中成為弱點,且其面臨的壓力可能與做市商Web3Port有關,該商因單邊拋售導致多項代幣崩跌。事件引發對幣圈創業環境的深度反思。

CryptoCity19h fa
Commento
0/400
Nessun commento