A blockchain used to move bitcoin between exchanges lost around $320 million in a single exploit on September 7, dominating the week's headlines. Yet Evin McMullen, CEO and co-founder of Billions Network, argues that in a strange way it was the recoverable kind of loss: funds moved on a public ledger, every transaction is visible, and the attacker appears to be a white-hat already negotiating their return. The unfixable breaches drew far less attention. In the same window, Trezor confirmed 67,000 customers had names, phone numbers and home addresses exposed through a shipping vendor, while a separate leak put roughly 200,000 records in the open, with government ID numbers beside verified wallet addresses.
Why it matters
McMullen's core argument is that the industry debates the wrong axis: whether platforms patched fast enough or users held keys correctly, all assuming the data had to be collected in the first place. Verifying a fact about someone and collecting their identity are different operations. A vendor can confirm a customer is real and sanctions-cleared without keeping a passport on a server. Minimum disclosure, where the fact is verified and discarded, means no honeypot is created and nothing is left to leak or sell.
The stakes grow with the AI era. Verified agents transacting on behalf of real people will have to prove authorization at machine speed. If they inherit today's model, they will drag their owner's full identity through every service they touch, turning a handful of honeypots into billions of them, refreshed continuously.
Market impact
The practical takeaway for investors and users is that address data, once linked to a real identity, is a permanent public liability: Trezor data stolen in 2020 is still arriving as physical mail demanding bitcoin, six years later. The $320 million will most likely come back. The addresses, IDs and faces will not. Privacy-preserving identity infrastructure, provable and portable for people and their agents, is positioned as the architectural answer, and adoption may decide whether honeypots become the permanent structure of the onchain economy.
Frequently asked questions
-
How much was lost in the September 7 blockchain exploit?
Around $320 million was drained from a blockchain used to move bitcoin between exchanges. The funds moved on a public ledger and the attacker appears to be a white-hat already negotiating their return.
-
What data was exposed in the Trezor breach?
Trezor confirmed 67,000 customers had names, phone numbers and home addresses exposed through a shipping vendor. A separate leak put roughly 200,000 records in the open, with government ID numbers sitting beside verified wallet addresses.
-
Why does a leaked identity matter more than stolen crypto?
Stolen tokens on a public ledger can be traced, frozen and sometimes returned, and money can be earned again. A leaked identity link between your name and a readable wallet address is permanent and public, and it cannot be rotated like a compromised key.
-
What is minimum disclosure in identity verification?
It is the practice of verifying a fact about someone, such as being a real, sanctions-cleared customer, and then discarding the data instead of storing their identity. No identity collected means no honeypot created and nothing left to leak or sell.
-
How do AI agents change the identity security problem?
Verified AI agents will transact on behalf of real people and must prove authorization at machine speed. If they inherit today's collect-everything model, they would drag owners' full identities through every service, creating billions of continuously refreshed honeypots.
CoinDesk