In January 2026, a Paris court rejected a request to release a 32-year-old former tax-office employee from pretrial detention. Prosecutors say she used her access to France's national tax authority to look up people investigators later described as "crypto specialists." She then sold their names, home addresses, and declared crypto holdings to criminal networks. The case is still under judicial investigation, with no trial date set. But it already illustrates a risk that has nothing to do with exchange hacks or a lost seed phrase: the risk that someone else holding your financial records mishandles or sells them.
This article walks through what is actually known about the French case and a separate breach at a French crypto tax software vendor. It explains why crypto holder data specifically attracts this kind of criminal interest, and lays out what to look for when deciding who gets to hold your crypto tax records.
Key Takeaways
- A real criminal case, not a hypothetical: French prosecutors have charged a tax-office employee with selling taxpayers' declared crypto holdings and home addresses to criminal networks.
- The risk sits with third parties, not with you: your crypto holdings become dangerous in the wrong hands only after someone else who stores that data mishandles or sells it.
- Governments and vendors are both potential points of failure: the French case involves a tax authority, while a separate breach at a French tax software vendor shows the same risk applies to private companies.
- Crypto holder data is valuable specifically because it's actionable: unlike a stolen card number, a name, address, and known crypto balance can point criminals toward a physical target.
- A short checklist can meaningfully lower your exposure: data minimization, encryption, read-only access, and a clear deletion policy are things you can actually verify before handing over your financial records.
What Happened in the French Tax Data Case
The case centers on an employee at a Direction Générale des Finances Publiques (DGFiP) tax office in Bobigny, near Paris, identified in press reports only as "Ghalia C.," 32. Investigators say she used an internal DGFiP tax software tool called Mira to look up and locate individuals' information, including crypto investors, in searches that had nothing to do with her actual job.
According to reporting on the case, those searches targeted people described as crypto specialists or investors, along with a small number of unrelated individuals, including a prison officer and a judge. Investigators allege she then sold the resulting personal data, including names, home addresses, and declared wealth such as crypto holdings, to criminal intermediaries. They allege she was paid partly in cash and partly through Western Union transfers.
The trail back to her began with a violent incident rather than a data audit. On September 26, 2024, three armed assailants attacked a prison officer at his home in Montreuil in front of his wife. Investigators tracing how the attackers found that address eventually worked their way back to the tax-office searches.
She has been held in pretrial detention since June 30, 2025. She faces charges of complicity in organized violence against the prison officer and of participating in a criminal conspiracy. In early January 2026, a Paris court rejected her request for release. The prosecutor argued that she had used her position "in a totally abnormal manner to serve hardened delinquency" and that "her place is in prison."
This case is a pending criminal matter, under judicial investigation, with charges filed but no trial and no verdict. Nobody has been convicted in connection with the Bobigny searches at the time of writing. What the case already demonstrates, independent of its eventual outcome, is that a government system built to hold declared crypto holdings can be misused by someone who has legitimate access to it.
Why This Matters Even If You've Never Been to France
It is tempting to read the DGFiP case as a French problem tied to one government database. The more useful lesson is broader. Any organization that stores your name alongside your crypto holdings, whether a tax authority, a bank, or a piece of software, is a potential target for this kind of misuse. The country and the specific database are incidental. The combination of identity and known crypto wealth is what makes the data valuable in the first place.
That combination matters more for crypto than for most other financial data, for a specific reason. A stolen card number can be cancelled within minutes of a fraudulent charge, but a crypto transfer made under duress cannot be reversed once it is confirmed on-chain. That difference is a large part of why criminals have shifted some of their effort from purely online fraud toward physical coercion. According to Chainalysis, so-called "wrench attacks," physical assaults or kidnappings intended to force a victim to hand over wallet access, resulted in more than $30 million in stolen crypto during the first half of 2026 alone, putting the year on pace to surpass 2025's already-record total. Home invasions specifically have become a larger share of these incidents over time.
France has recorded a disproportionate share of these cases in 2026, and reporting on the wave has repeatedly pointed to leaked government and vendor data, including the Bobigny case, as one contributing factor among several, alongside doxxing and other data exposures. Leaked holder data does not explain the entire wave on its own, but it can hand criminals a ready-made list of who to target and where to find them, which is exactly why the data itself deserves the same scrutiny you would give a password.
Your crypto activity, tracked without ever touching your funds
CoinTracking only ever requests read-only exchange access to import your transaction history. It cannot send, receive, or withdraw crypto on your behalf.
It's Not Just Governments: The Waltio Case
Governments are not the only organizations that hold this kind of data. Crypto tax software needs to know your gains, losses, and year-end balances by design, which makes any vendor holding that information a target in its own right.
Waltio, a French crypto tax platform, is a documented example. A hacking group stole data belonging to roughly 50,000 Waltio users. Waltio confirmed the exposed data was limited to email addresses and summary tax-report figures: gains, losses, and year-end balances as of December 31, 2024. No wallet-access or account-interaction data, such as private keys or the ability to sign transactions, was affected.
Waltio received an extortion demand around January 21, 2026, and French prosecutors along with the national cyber unit opened an investigation. The hackers later claimed, in a statement made to promote their own leak, that the stolen data was linked to at least three kidnappings totaling $17.1 million in stolen crypto. That claim comes from the attackers themselves and has not been independently confirmed.
France's official cybersecurity advisory service, cybermalveillance.gouv.fr, published an advisory on the incident. It has also warned more broadly that data stolen in crypto-sector breaches tends to resurface later as targeted phishing, impersonation attempts, and extortion aimed at the people named in it.
Waltio is not the only case of this kind. Vendor-side incidents, a compromised email tool here, a breached analytics subcontractor there, have exposed user data at other portfolio and tax platforms in the past. The pattern is the same regardless of which company is involved: the vendor holding your financial data is only as trustworthy as its own security practices, and those practices are usually invisible to you until something goes wrong.
What to Actually Look For When Choosing Who Holds Your Crypto Tax Data
You cannot audit a vendor's internal systems yourself, but you can check for a handful of concrete signals before handing over your crypto transaction history and holdings.
- Data minimization: does the service actually need your full trading history and balances to do its job, or does it collect more than the task requires?
- Encryption: is sensitive data stored encrypted, both in transit and at rest, rather than in a format that would be readable if a database were ever accessed without authorization?
- Read-only access only: when a service asks to import your exchange data, does it request read-only API keys, or does it ask for withdrawal permissions it has no legitimate reason to need?
- A real deletion policy: if you ask a provider to delete your account, does it actually remove your data immediately and permanently, or just deactivate the account while keeping your records?
- Jurisdiction and regulatory compliance: where are the servers located, and is the provider subject to a framework like the GDPR that gives you enforceable rights over your own data?
- Anonymous or minimal-data registration: can you use the service without handing over personal identifying details you don't actually need to share?
- Independent security certification: has the provider had its security practices independently audited and certified, for example against a recognized standard such as ISO/IEC 27001, rather than simply asserting that it takes security seriously?
None of these questions require special technical expertise to ask. Most reputable providers publish the answers directly on a security or trust page, and a provider that cannot or will not answer them clearly is telling you something useful in itself.
What CoinTracking Does With Your Data
CoinTracking has processed crypto transaction data since 2012, for more than 2.2 million users across over 400 exchanges, and its data-handling practices reflect that history.
CoinTracking is not a wallet or an exchange. It cannot send, receive, or withdraw crypto on your behalf, because it was never built to hold funds; it only imports and organizes the transaction data you already have. When importing from an exchange, CoinTracking only ever requests read-only API access, and it never asks for your password, private keys, or seed phrase.
On the infrastructure side, CoinTracking's servers are located exclusively within the European Union, and data processing is carried out in compliance with the GDPR. CoinTracking is also fully ISO/IEC 27001:2017 certified, an independent standard covering information security management, and publishes more detail on these security practices directly. Sensitive data is stored encrypted, and the platform uses SSL encryption throughout.
You can also register with CoinTracking anonymously, without providing personal data, and if you ask CoinTracking to delete your data, that deletion is immediate and permanent. Taken together, these practices are the same checklist described above, applied to the way CoinTracking itself operates.
Conclusion
The French tax-official case is a pending criminal matter, not a proven scandal. But it already shows that the biggest privacy risk to your crypto holdings can come from the third party you trusted to hold your records rather than from your own security habits. Whether that third party is a government tax system or a tax software vendor, the questions worth asking are the same: does it collect more data than it needs, does it store what it has encrypted, does it only ever request read-only access, and will it actually delete your data if you ask? Choosing a provider that can answer those questions clearly, and that has already built its practices around them, is the most concrete step you can take about a risk you otherwise have little control over.
Track your crypto taxes without handing over control of your funds
CoinTracking has processed transaction data for over 2.2 million users since 2012, with EU-based servers, GDPR-compliant processing, and read-only exchange access only.
Disclaimer
The information provided in this article is intended for general informational purposes only and should not be construed as financial, tax, or legal advice. Details of the ongoing French criminal case described here are based on publicly available reporting and may change as the investigation and any subsequent legal proceedings continue. Readers are encouraged to conduct their own research and consult with a qualified professional before making decisions based on the information presented here. The author and publisher are not responsible for any losses or damages incurred as a result of using the information in this article.