Based reportedly raised $11.5 million in a Series A led by Pantera Capital, and said it had passed 100,000 registered users.
The company is yet to reveal how many users were affected by the breach, nor whether any funds moved.
The timing is awkward for Britain’s tax authority, HM Revenue and Customs (HMRC), which on July 13 published a draft legislation reforming its Schedule 36 information and inspection powers. The draft is part of the Finance Bill 2026-27 documents released for technical comment, and the consultation closed on September 7.
The same day the draft was published, UK crypto tax firm Recap filed a response opposing the plan. Its CTO, Ben Shepheard, pointed out that the new rule would allow HMRC to issue compulsory demands for records to any “person who provides services relating to cryptoassets,” meaning that HMRC will be able to demand records from wallet software, block explorers, data vendors and hardware wallet makers, even though none of them hold a customer’s assets.
Such a notice would also need no tribunal sign-off or taxpayer consent, and it also cannot be appealed.
Recap pointed out that the scope of the amended rule would be much wider than that of the UK’s existing Cryptoasset Reporting Framework rules.
The firm’s opposition to the law is also linked to data security. It referred to a 2024 case in which an employee of the French tax administration allegedly sold the names, addresses and wallet balances of declared crypto holders.
Recap also mentioned a January 2026 breach that occurred at Waltio, a French crypto tax software provider. 50,000 users’ gains, losses and balances were exposed in that breach, after which a hacking group sent ransom demands.
How dangerous are data leaks in the crypto industry?
IDScan.net was reportedly linked in September to a cybercrime-forum collection advertised as holding more than 170 million identity documents. Coinbase disclosed that a threat actor bribed overseas support contractors to extract customer data, including passport and driver’s license images.
ShipMonk, Trezor’s fulfillment partner, suffered a leak that affected roughly 80,700 users. Attackers gained a list of names and home addresses from the exploit.
Cryptopolitan has tracked a rise in violent “wrench attacks,” in which victims are assaulted or kidnapped in order to force them into transferring their crypto.
France alone had experienced 77 crypto-linked kidnapping, detention and extortion cases or attempts by the end of June, up from 45 in all of 2025. In Britain, Crimestoppers has offered £10,000 for information about a December 2025 home invasion near Birmingham.
Recap wants HMRC to tighten the wording of its bill and state that users’ current holdings and wallet addresses are not “reasonably required” when their historic sales data provides the needed information. The firm also wants a tribunal’s approval to be required before HMRC can issue any notice.