Crypto security tends to focus on the thing everyone can see: the money.
A $320 million exploit on September 7 put that instinct on full display. The incident hit a blockchain used to move bitcoin between exchanges, turning stolen funds into the headline of the week. But money, for all its drama, has one useful quality: it can sometimes be recovered.
An identity doesn’t work that way.
The stolen funds moved across a public ledger, making the trail visible. The attacker also appeared to be a white-hat hacker negotiating their return. In other words, the loss was potentially reversible. The same cannot be said for a passport number, a home address or a face.
That distinction is becoming harder to ignore.
Around the same period as the $320 million exploit, Trezor confirmed that another 67,000 customers had their names, phone numbers and home addresses exposed through a shipping vendor. A separate incident exposed roughly 200,000 records that paired government ID numbers with verified wallet addresses.
And one older breach is still producing consequences. Data taken from a hardware wallet maker in 2020 has continued to surface in physical mail sent to victims asking for bitcoin — six years after the original leak.
You can replace a compromised crypto key. Replacing your home address or passport number is another matter entirely.
Crypto security keeps protecting data we never needed to store
This is the uncomfortable part of the crypto security story: the biggest risk is often created before an attacker ever arrives.
Exchanges need to verify customers. On-ramps need documentation. Hardware wallet companies need shipping information. Each service has a legitimate reason to interact with identity data, but that does not necessarily mean it needs to retain a complete record of who you are.
Once it does, the company has created a honeypot: a centralized collection of sensitive information with potentially enormous consequences if it is breached.
The problem gets worse as that pattern repeats across the internet. A single person’s identity can end up scattered across exchanges, vendors and other services, each holding another copy of information that cannot simply be replaced after a breach.
Then comes the particularly dangerous combination: a real-world identity attached to a public blockchain address.
When a person’s name becomes linked to an address whose activity or balance can be observed onchain, the exposure does not disappear when the stolen data is deleted. The connection can remain visible and usable long after the original breach.
That makes the conventional security conversation feel slightly backward.
We tend to ask whether a company secured its database properly, patched a vulnerability fast enough or gave users better custody tools. Those questions matter. But they all begin from the assumption that the sensitive information had to be collected in the first place.
It didn’t.
There is a meaningful difference between proving that someone satisfies a requirement and collecting everything that proves who that person is. A service could confirm that a customer is legitimate and cleared for a transaction without permanently storing a copy of their passport.
The principle is simple: verify the fact, then discard the identity data.
That leaves attackers with less to steal in the first place.
The internet has already shown what happens when regulation focuses on an outcome without changing the underlying data model. Websites were told to obtain consent, and the market produced the cookie banner — a pop-up now so ubiquitous that most people click through it on autopilot.
Crypto developed its own version of the same reflex: upload your ID everywhere.
A passport ends up copied into database after database, creating more opportunities for exposure while doing little to reduce the consequences when one of those systems is compromised.
And the next stage of the internet could multiply the problem dramatically.
AI agents are beginning to act on behalf of people rather than simply waiting for humans to click buttons. The old distinction between “bot” and “human” is becoming less useful as software starts making transactions with permission from the people behind it.
Those agents will need to prove things, too.
They may need to demonstrate that they are authorized to spend money, access an account or perform a specific action. And they may need to do it at machine speed, across enormous numbers of services.
Carrying a user’s full identity through every one of those interactions would reproduce today’s problem at an entirely different scale.
Instead of thousands or millions of identity honeypots, there could be billions of them — constantly updated, continuously connected and operating without sleep.
The irony is that the technology needed to avoid that outcome already exists.
The alternative is to prove what needs to be proved without handing over everything else: private, portable credentials that establish authorization without turning identity into another asset sitting in a database.
That changes the question for crypto security.
It is no longer only about building stronger defenses around sensitive information. It is also about deciding whether that information needed to be collected at all.
The $320 million may come back. The exposed addresses, identification numbers and faces will not.
As AI agents become another layer of the internet’s infrastructure, that distinction matters even more. The future of crypto security may depend less on protecting ever-growing piles of personal data and more on learning how to operate without creating those piles in the first place.
