The previous article was about precious metals, and before that about bonds and options. All of them dealt with how much of an income goes to tax. This one is about a different risk: who knows that you hold crypto, where that information sits and what can happen to it. From 1 January 2026 the answer changes in Slovakia, because crypto-asset service providers have started collecting data for the tax administration.

Why crypto data is more sensitive than bank account data

A bank transfer has brakes. The bank has daily limits, calls the customer about an unusual payment, can stop a suspicious transaction and in some cases reverse it. Anyone trying to move a large sum out of someone else's account has to go through an institution with its own controls.

A crypto transfer has no such brakes. A transaction written to the blockchain cannot be taken back, and all it takes to send it is the private key. A private key is a long number, in practice usually written down as 12 or 24 words, that gives the right to dispose of the coins. Anyone holding crypto in self-custody, that is not on an exchange but in a wallet to which only they hold the key, keeps that key in their head, in a drawer or on a hardware device at home.

This is where the term wrench attack comes from. It goes back to a well-known internet cartoon: encryption worth millions of dollars cannot be broken, but the person who knows the password can be intimidated with a five-dollar wrench. The attacker does not solve mathematics, he deals with the person.

For that he needs three pieces of information: who you are, where you live and that you hold crypto of significant value. Each of them on its own is ordinary. Anyone can find a name and address, and the fact that someone owns bitcoin reveals nothing by itself. What is dangerous is the combination of all three in one place. It is like the code to a lock written on a note hanging on the lock itself.

Tax databases contain exactly this combination. A tax office has to know who you are, where you live and what you earn. With crypto, the information that you hold it is added on top.

France: four leaks in one year

France is today the country with the largest number of documented physical attacks on crypto holders in the world. Over 2025 and 2026 it also accumulated four data leaks in which someone unauthorised got hold of information about people. Three of them concerned the state, one a private company.

CaseWhenHow the data was accessedWhat leaked
Tax official in the Mira systemuncovered in June 2025employee with legitimate accessaddresses, wealth data, searches for crypto investors
Waltio appJanuary 2026hacker attack and extortion attempte-mails and aggregate tax report data of about 50,000 users
FICOBA bank account register28 January to 13 February 2026stolen login of an officialidentity, address, bank and IBAN for 1.2 million accounts
DGFiP tax administration systemsJune and July 2026stolen logins, no second factoridentity, address and tax data of 678,000 people, land registry data

The official in the Mira system. On 30 June 2025 a 32-year-old employee of the tax office in Bobigny near Paris was charged with complicity in violence by an organised group and with criminal conspiracy. According to investigators she used the internal tax software Mira to look up the address of a prison guard who was then attacked at home. Her work computer also showed searches unrelated to her job: billionaire Vincent Bolloré and several people whom investigators described as crypto specialists and investors. She was paid through Western Union. According to the French press she admitted passing on the data but denies knowing about the violent intentions of whoever ordered it. The proceedings are not over and she is presumed innocent until a final judgment.

Waltio. Waltio is a French app that calculates crypto tax from exchange statements and fills in the tax forms. On 21 January 2026 the company received an extortion message from hackers who claimed to hold the data of about 50,000 users. According to the company this meant e-mail addresses and aggregate figures from tax reports, that is gains, losses and balances. Passwords, exchange API keys and private keys did not leak. A few weeks later a family was attacked in Taverny north of Paris. The father was stunned with a taser and the family held at home. According to Le Parisien the attackers had their tip from the Waltio file. About one hundred euros remained in the victim's account, because the tax report was almost a year and a half old and said nothing about the current state of the wallet.

FICOBA. FICOBA is the French national register of all bank accounts. It records who holds which account at which bank and is used by authorities for enforcement and audits. From 28 January to 13 February 2026 someone entered it with the login of an official who had authorised access as part of information exchange between ministries. They viewed or downloaded data on 1.2 million accounts: name, address, bank, IBAN and for some also the tax identification number. The tax administration announced it on 18 February.

DGFiP in summer 2026. In June and July 2026 someone again logged into the French tax administration's systems with other people's credentials. An attacker going by the name ZeroBytes publicly claimed the breach on 12 and 13 August and offered the data for sale. On 14 August the ministry confirmed that it concerned data on 678,000 individuals and businesses: identity, addresses, reference household income, withholding rate and for some also land registry data. According to the ministry, passwords to personal tax accounts did not leak.

The most important document came on 29 September 2026. At the prime minister's request, the French national cybersecurity agency ANSSI published a report on the summer incidents. According to the report, the attackers obtained genuine staff credentials that had also been used on personal devices, and the portals with sensitive data did not require a second authentication factor such as a code from a phone. Sensitive applications were reachable from the internet or from the government network without sufficient separation, and one of the access paths came from the network of the education ministry. Neither of the two waves of data extraction was detected by the tax administration or by ANSSI. One of the portals through which the data left was not monitored by anyone.

The common denominator of the three state cases is simple. Nobody broke encryption and nobody cracked a database. All three involved legitimate access, misused either from the inside or with a stolen password. In the Waltio case the company has not published details of how the intrusion happened. The fault lay not with individuals but with systems that allowed one account to see too much, did not verify who was really logging in and did not watch what was being done with the data.

France also has one peculiarity that does not apply to Slovakia. French taxpayers must report accounts on foreign crypto exchanges every year on a separate form, 3916-bis, even if they sold nothing. The tax administration therefore has a list of people who hold crypto, not only of those who made money on it.

Kidnappings: what the numbers say

French authorities publish two sets of figures that differ in what exactly they count. Interior Minister Laurent Nuñez said on 30 June 2026 that since the start of the year police had recorded 77 crypto-related kidnappings and extortions, including attempts. For the whole of 2025 there were 45 and in 2024 about thirty. The national prosecutor's office for organised crime reported in September 2026 more than 70 kidnappings and forcible confinements since the start of the year, compared with 67 for all of 2025 and about twenty in 2024. More than ninety people have been charged in its cases. Regardless of methodology, both figures show the same thing: 2026 overtook 2025 before the year was out.

The start of the wave is associated with January 2025, when Ledger co-founder David Balland was kidnapped and the attackers cut off one of his fingers. Since then the profile of victims has shifted. In January 2026 the interior ministry said the threat now also affects private individuals with no public profile. In April 2026 two armed men held a family of five in Ploudalmézeau in Brittany and forced the father, who works in the crypto sector, to transfer about 700,000 euros. On 19 September 2026 a couple with two children aged eight and twelve were tied up and beaten in Vendin-le-Vieil in northern France and the father was forced to transfer 40,000 euros.

The government responded with a security plan for people in the industry, and according to the interior minister the emergency measures led to around two hundred arrests. By September this had not shown in the number of attacks.

Map of reported attacks worldwide

Nobody keeps a complete global record. The most widely used source is a public list that American security researcher Jameson Lopp has maintained on GitHub since 2014. It records cases reported by the media or courts, with date, location and a link to the source. As of 29 September 2026 it contained 364 entries.

The list has two limitations that should be stated plainly. First, it is not complete: most attacks never reach the media and victims often do not even report them. For France it contains 43 cases for 2026, while the official figures are almost twice as high. Second, it does not consistently separate kidnappings from other physical attacks. A description such as "the family was tied up at home and the father forced to transfer crypto" is forcible confinement under French law, but in the list it sits next to a street robbery. The map therefore shows all entries: kidnappings, confinements, home invasions and robberies.

World map of reported kidnappings and physical attacks on crypto holders by country, 2014 to 2026. France has the most cases (71), followed by the USA (59) and the United Kingdom (25). Slovakia has none.
The size of the light circle reflects all entries since 2014, the solid dot the entries in 2025 and 2026. For France the two circles are almost the same size, because most cases there date from the last two years.
CountryEntries 2014 to 2026Of which 2025 and 2026
France7166
USA5915
United Kingdom256
Canada182
Thailand188
Hong Kong136
Brazil127
India123
United Arab Emirates101
Russia101

For 2025 and 2026 the list contains 151 cases, 66 of them from France. For 2026 alone it is 43 out of 64. In the USA, which was long in first place, most entries are older. Neither Slovakia nor the Czech Republic has a single case in the list. That does not mean nothing has happened here, but it does mean nothing was published in a way that reached the record.

The list itself does not establish the cause of the French wave. Data leaks are one of the factors pointed to by French media and people in the industry, and in the Taverny case and the case of the official in the Mira system this is confirmed by the investigation. The second factor is organised crime that has turned to this type of attack.

What the Slovak tax administration knows about you today

Until the end of 2025 the Slovak tax administration learned about crypto mainly from tax returns. Income from the sale of a crypto-asset falls under section 8(1)(t) of the Income Tax Act and is reported in a type B return. Anyone who bought and held crypto without selling had no obligation to report it anywhere. Slovak law has no form similar to the French 3916-bis on which the exchange accounts themselves would be reported.

On ordinary financial accounts abroad the tax administration has received data automatically since 2017 under the OECD Common Reporting Standard, known as CRS. For crypto on exchanges no such mechanism existed. That changes from 1 January 2026.

DAC8: what changes from 1 January 2026

DAC8 is the eighth amendment to the EU directive on administrative cooperation in the field of taxation, Council Directive (EU) 2023/2226. Its content is based on the OECD standard called the Crypto-Asset Reporting Framework, CARF for short. The principle is the same as for bank accounts: the authority does not collect data from the taxpayer, but from the firm that provides the service.

In Slovakia the directive was transposed by Act No. 200/2025 Coll., which with effect from 1 January 2026 added new sections 15a to 15j to Act No. 359/2015 Coll. on automatic exchange of information. The obligations lie with the reporting crypto-asset service provider. That is a provider under the EU MiCA regulation, meaning an exchange, a crypto exchange office or a firm that holds crypto-assets in custody, and also any other operator that carries out exchanges for clients.

What the provider reports about you. Under sections 15g and 15h(9) there are two groups of data.

GroupContent
Who you arename, residential address, tax identification number, state of tax residence, date and place of birth
Purchases for eurosaggregate amount paid, number of units and number of transactions per year, separately for each type of crypto-asset
Sales for eurosaggregate amount received, number of units and number of transactions
Crypto-to-crypto exchangesaggregate fair market value, number of units and number of transactions, acquisitions and disposals separately
Payments for goods and serviceswhere a single payment exceeds the value of 50,000 dollars
Transfersaggregate value and number of units of transfers received and sent, including transfers to addresses not belonging to any provider, most often to one's own wallet

Just as important is what is not reported. The law does not ask for the account balance, so the report does not directly tell the authority how much crypto you hold on 31 December. Nor does it ask for the wallet addresses themselves: for transfers to self-custody only the aggregate value and number of units are reported. And the acquisition cost, meaning what you originally paid for the crypto, is not reported either.

The last point has a direct tax consequence. If in 2026 you sold bitcoin for 20,000 euros that you had bought for 18,000 euros, the report shows a sale of 20,000 euros. The tax base, however, is 2,000 euros, and to prove it you need your own record of purchases. Under section 22(12) of the Act the tax administration uses data from the exchange of information to determine the correct amount of tax, so it will compare them with the returns filed. How the acquisition cost of crypto-assets is determined is covered in the article on crypto taxation in Slovakia.

Timeline. Providers collect data for calendar year 2026. They must hand it to the tax administration by 31 May 2027, and this deadline cannot be extended. By 30 September 2027 the tax administration then sends data on foreigners to their home states and in the same way receives data on Slovak residents from foreign authorities. The provider must keep the data for at least five and at most ten years.

Your obligations and rights. The user must cooperate with the provider, above all by providing a tax identification number and tax residence details. If the user fails to do so even after two reminders and at least 60 days have passed since the first request, the provider must block the transactions that are subject to reporting. A tax office can impose a fine of up to 3,000 euros for false information. On the other hand, the provider must inform every individual in advance that their data will be collected and reported, and give them the information they need to exercise their rights under the GDPR.

Where the data goes. A common misconception is worth correcting here. Data on a Slovak resident does not go to every state that has joined the exchange, only to the state of their tax residence. If a Slovak trades on an exchange licensed in Malta, the exchange reports the data to the Maltese tax administration, which sends it to Slovakia. Copies are therefore created at the provider, at the tax administration of its state, at the Slovak tax administration and in the central register for administrative cooperation in taxation, in which the Slovak authority sees only data on Slovak residents. Outside the EU the exchange follows the CARF framework. According to the list of the Irish Revenue as of January 2026, 48 jurisdictions including Slovakia, the United Kingdom, Norway, Japan and Korea will exchange 2026 data in 2027. Others, such as Switzerland, Singapore, the United Arab Emirates and Hong Kong, join a year later.

MiCA: who may provide services, not who reports what to whom

MiCA, Regulation (EU) 2023/1114 on markets in crypto-assets, is often confused with tax reporting. They are not the same thing. MiCA determines who may provide crypto-asset services in the EU, what conditions they must meet and who supervises them. In Slovakia that is the National Bank of Slovakia. The transitional period during which providers without a MiCA licence could also operate ended on 1 July 2026. The MiCA regulation itself sends no data to the tax administration.

It is, however, connected to the subject of this article in two places. The first is the definition. The act transposing DAC8 refers to MiCA terms, so every licensed provider is automatically also a reporting provider. In addition, every year by 31 December the National Bank sends the Financial Directorate a list of the providers it has authorised. The second is security. Licensed providers are subject to the DORA regulation on digital operational resilience, which since 17 January 2025 has required them to manage cyber risks and report serious incidents. On the private side there are therefore binding data protection standards that can be enforced.

Alongside MiCA and DAC8 there are two more regulations that work with data on holders, but not for tax purposes.

RegulationWhat it coversWho receives dataSince when
MiCA (2023/1114)licences and rules for providersthe supervisor, in Slovakia the NBSfrom 30 December 2024, transitional period until 1 July 2026
Travel rule (2023/1113)every transfer between providers carries the names of sender and recipient, and for transfers above 1,000 euros to one's own wallet the provider checks that it belongs to the clientthe provider on the other side of the transferfrom 30 December 2024
DAC8 (2023/2226)reporting for tax purposesthe tax administration and its foreign partnerscollection from 1 January 2026, first report in 2027
AMLR (2024/1624)ban on anonymous accounts and anonymity-focused coins at providersnobody new, it is a banfrom 10 July 2027

The travel rule takes its name from banking: information on who pays and who receives travels together with the money. For crypto it applies regardless of the amount.

What the real risks are

A balanced assessment starts with where most of the data sits. It is not the state. The exchange where you open an account has a copy of your ID card, a photo of your face, your address, phone number and the full history of all transactions, including the wallet addresses to which you sent coins. A DAC8 report contains only a fraction of that, in aggregate annual figures. DAC8 therefore does not create the first database of crypto holders, but another copy of part of it, this time in a state system.

Private databases have leaked too. Wallet maker Ledger lost its customer database in 2020, and the names, addresses and phone numbers of about 270,000 customers appeared freely on the internet in December 2020. US exchange Coinbase announced in May 2025 that attackers had bribed staff at an outsourced customer support operation who passed them customer data. Every additional copy of data is another place from which it can leak.

RiskFrench exampleWhat reduces it
Insider misusethe official in the Mira systemaccess only to data needed for the job, logging of every search and regular review
Stolen passwordFICOBA, DGFiP in summer 2026two-factor authentication, separating sensitive systems from the internet, monitoring unusual downloads
Leak at a third partyWaltioless data at fewer firms, deletion once the purpose ends
Public registersin Slovakia the business register in August 2026anonymising documents before publication
Fraud using leaked dataDGFiP warning about scams after the summer leakverifying every request through an official channel

The Slovak state is no exception. In January 2025 a ransomware attack hit the land registry's information system and halted its operation for several weeks. It was an outage, not a leak, but it showed that Slovak state systems are targets too. In August 2026 the justice ministry launched a new business register portal under Act No. 29/2026 Coll. Documents that companies file in the document collection were left with personal identification numbers, full addresses, signatures and ID document numbers of directors and shareholders unredacted. On 19 August 2026 the Office for Personal Data Protection opened proceedings against the ministry. The ministry denies any error and points to the law, under which a document is published even if it contains data that is otherwise not published. For anyone who is a director or shareholder of a company, this means their address may be publicly traceable without any leak at all.

The most common consequence is not kidnapping. Far more often, leaked data is misused for fraud. An attacker who knows your name, address and that you have an account at a particular exchange writes or calls on behalf of the exchange, a bank or the tax administration and sounds credible. When announcing the summer leak, the French tax administration advised affected people to be particularly careful about exactly such attempts.

How high the risk is in Slovakia. According to available data, the likelihood of a physical attack is low and the public record contains no case from Slovakia. The consequences of this type of risk are, however, so serious that a low likelihood does not mean it can be ignored. DAC8 data does not show a balance on its own, but the sum of purchases and transfers to one's own wallet does say something about wealth.

What can be done within the law

Reporting obligations cannot be avoided, and trying would not be a sensible strategy. Anyone who refuses to give a provider their data loses the ability to trade. Anyone who gives false data risks a fine. Anyone who does not declare income has a tax problem that is easy to detect when compared with DAC8 reports. The room for action lies elsewhere: in how much data you publish about yourself and whom you entrust it to.

Do not publish balances. Wallet screenshots, mentions of portfolio size on social networks and public appearances with specific numbers are the simplest source of information that someone holds crypto. No leak is needed for that.

Separate contacts. A separate e-mail address for exchanges and tax tools makes it harder to link data from different leaks and easier to recognise a fraudulent e-mail that arrives at another address.

Ask who keeps what. When choosing an exchange, a tax calculation app or a tax adviser, it makes sense to ask what data they keep, for how long and who has access to it. You have the same right against the state under Article 15 of the GDPR.

Split authority. For larger amounts people use multisig, a wallet in which a transaction must be signed by several keys stored in different places or with different people. Under duress in one place, not everything can be transferred. A time lock, which allows a transfer out of the wallet only after a certain time, serves a similar purpose.

Verify every request. Neither the tax administration nor any exchange ever asks for a private key or wallet recovery words. The Slovak tax administration communicates through the electronic mailbox at slovensko.sk and through the tax administration portal. A request that arrives any other way is worth checking directly with the office.

Takeaways

The French cases are not an argument against tax transparency. They are an argument for the state to handle data on crypto holders with the same care a bank applies to vault codes. The ANSSI report shows that the technical fixes are known and cheap: two-factor authentication, restricted access and monitoring who downloads what. What was missing was consistent implementation.

For a Slovak taxpayer this leads to two practical conclusions. First: from 2026 the tax administration knows about trades on exchanges, so the return and your own records must match what the provider reports. Second: data about crypto is worth sharing with as few people and firms as possible, because every copy is another place from which it can leak.

This article is a general overview, not individual tax or security advice, and not an investment recommendation. Reconciling the data a provider reports under DAC8 with the tax return and keeping verifiable records of acquisition costs are part of the routine work kryptotax.sk does for clients. 🇸🇰