South Korea is reviewing how public agencies handle seized crypto after the National Tax Service exposed a wallet recovery phrase in a public press release. Soon after the image appeared online, roughly $4.8 million in digital tokens was transferred out by unknown actors. The incident has turned into a wider examination of government custody practices for digital assets.
The mistake happened on February 27. Officials published a photo showing a seized hardware wallet and a notebook, and the notebook visibly contained the wallet’s recovery phrase. A recovery phrase is typically made up of 12 or 24 words; anyone with it can restore access to the wallet and take control of the funds. Once the image became public, the assets were moved out quickly.
A public image revealed the wallet’s master access key
Reports said the device was a Ledger hardware wallet holding Pre-Retogeum (PRTG) tokens worth about $4.8 million. The core failure was not on-chain infrastructure but key handling. By showing both the device and the written recovery phrase, the release exposed the single piece of information needed to regain control of the wallet.
Blockchain analytics platform Arkham later traced the suspicious transfers. Investigators found that funds were moved from several Ethereum addresses shortly after the phrase was disclosed. The pace of the transfers showed how little time remains once sensitive wallet credentials are made public.
The latest case follows an earlier government wallet theft
This was not the first crypto security failure tied to South Korean authorities. In an earlier case, 320 BTC, valued at about $21 million, was stolen from government wallets and later returned after pressure from authorities. Repeated losses have pushed custody controls for seized digital assets back into focus.
Deputy Prime Minister and Finance Minister Koo Yun-cheol said authorities will inspect how government institutions manage digital assets obtained through seizures. The review will include the Financial Services Commission and the Financial Supervisory Service, with attention on custody procedures, storage security, and internal handling of digital wallets.
Institutional custody procedures are now under scrutiny
The case has also revived a broader discussion about institutional crypto security. According to the source material, many failures involving public or institutional holdings do not come from flaws in blockchain networks. They come from weak key management, poor procedures, and operational mistakes.
The report also cited a February 2026 U.S. audit that found about $22 billion in seized cryptocurrency had been lost or mismanaged because of fragmented records and improper key storage. Earlier in 2025, blockchain investigator ZachXBT alleged that around $40 million had been stolen from government-controlled wallets. South Korea’s latest leak adds another example: even a hardware wallet offers little protection once the recovery phrase and internal controls fail.

