LATEST NEWS
SELECTED FOR YOU

BasedApp hack raises fresh concerns over HMRC crypto data powers

ByHannah CollymoreHannah Collymore 2 mins read
BasedApp breach exposes the risk critics warn HMRC's crypto powers would multiply
  • BasedApp disclosed on October 8 that a breach of its internal systems exposed customer KYC records tied to crypto wallet addresses. 
  • The incident is the exact harm Recap and others cite in opposing HMRC’s draft information powers. 
  • The tax authority wants to be allowed to demand records from crypto service providers without tribunal approval. 

 

BasedApp said on Thursday that an intruder reached its internal systems and exposed the house and wallet addresses of its customers. 

HMRC recently proposed a change to an existing law that would give it more access to customer data. This breach is an example of what critics say that change would make more common across Britain.

What data was stolen from BasedApp?

BasedApp disclosed through TokenPost on October 8 that its internal operations system was breached by an unauthorized party. The stolen records include names, dates of birth, nationalities, home addresses, passport or Singapore national ID numbers, email addresses and phone numbers alongside customer wallet addresses.

Based reportedly raised $11.5 million in a Series A led by Pantera Capital, and said it had passed 100,000 registered users. 

The company is yet to reveal how many users were affected by the breach, nor whether any funds moved.

The timing is awkward for Britain’s tax authority, HM Revenue and Customs (HMRC), which on July 13 published a draft legislation reforming its Schedule 36 information and inspection powers. The draft is part of the Finance Bill 2026-27 documents released for technical comment, and the consultation closed on September 7.

The same day the draft was published, UK crypto tax firm Recap filed a response opposing the plan. Its CTO, Ben Shepheard, pointed out that the new rule would allow HMRC to issue compulsory demands for records to any “person who provides services relating to cryptoassets,” meaning that HMRC will be able to demand records from wallet software, block explorers, data vendors and hardware wallet makers, even though none of them hold a customer’s assets. 

Such a notice would also need no tribunal sign-off or taxpayer consent, and it also cannot be appealed. 

Recap pointed out that the scope of the amended rule would be much wider than that of the UK’s existing Cryptoasset Reporting Framework rules.

The firm’s opposition to the law is also linked to data security. It referred to a 2024 case in which an employee of the French tax administration allegedly sold the names, addresses and wallet balances of declared crypto holders. 

Recap also mentioned a January 2026 breach that occurred at Waltio, a French crypto tax software provider. 50,000 users’ gains, losses and balances were exposed in that breach, after which a hacking group sent ransom demands.

How dangerous are data leaks in the crypto industry?

IDScan.net was reportedly linked in September to a cybercrime-forum collection advertised as holding more than 170 million identity documents. Coinbase disclosed that a threat actor bribed overseas support contractors to extract customer data, including passport and driver’s license images. 

ShipMonk, Trezor’s fulfillment partner, suffered a leak that affected roughly 80,700 users. Attackers gained a list of names and home addresses from the exploit.

Cryptopolitan has tracked a rise in violent “wrench attacks,” in which victims are assaulted or kidnapped in order to force them into transferring their crypto. 

France alone had experienced 77 crypto-linked kidnapping, detention and extortion cases or attempts by the end of June, up from 45 in all of 2025. In Britain, Crimestoppers has offered £10,000 for information about a December 2025 home invasion near Birmingham. 

Recap wants HMRC to tighten the wording of its bill and state that users’ current holdings and wallet addresses are not “reasonably required” when their historic sales data provides the needed information. The firm also wants a tribunal’s approval to be required before HMRC can issue any notice. 

If you're reading this, you’re already ahead. Stay there with our newsletter.

FAQs

What data did the BasedApp breach expose?

The exposed records include names, dates of birth, nationalities, home addresses, passport or Singapore national ID numbers, emails and phone numbers, each linked to a customer's crypto wallet address. BasedApp did not say how many customers were affected or whether funds were accessed.

What is HMRC proposing with its new information powers?

HMRC's draft legislation, published July 13, 2026, would let it issue a compulsory demand for records to any "person who provides services relating to cryptoassets" without tribunal approval, taxpayer consent or a right to appeal the notice, and would take effect from Royal Assent expected in spring 2027.

Why do critics say collecting wallet data is dangerous?

Recap argues that records pairing a person's identity with their wallet addresses act as a live, traceable map of their wealth, and points to cases like a January 2026 French breach of 50,000 users' balances that led to an extortion demand.

Share this article

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Hannah Collymore

Hannah Collymore

Hannah is a writer and editor with nearly a decade of blog writing and event reporting experience in the crypto space. At Cryptopolitan, Hannah contributes to the news page, reporting and analyzing the latest developments in DeFi, RWA, crypto regulation, AI and frontier tech industries. She graduated from Arcadia university with a degree in Business Administration.

MORE … NEWS