Roger

Bitcoin · Macro · AI · Freedom Tech
← All writing

The Informant and the Hot Wallet

Brazil's central bank now files reports on every self-custody withdrawal above $10,000, effective 1 October. Four days earlier Bitget froze withdrawals on a $351.6M hot-wallet breach. Surveillance built on intermediaries inherits their fragility.

25 Sep 2026 1,101 words · 5 min Also on Nostr as a long-form note
The Informant and the Hot Wallet

On October 1 a withdrawal stops being a withdrawal and becomes a filing.

Brazil's central bank published Resolutions 588 and 589 on September 24, and both take effect on that date. Resolution 588 requires every BCB-authorized exchange to report transfers to or from a self-custody wallet at or above $10,000 to COAF, Brazil's financial intelligence unit. Resolution 589 forbids those same licensed exchanges from transacting with any virtual asset provider the central bank has not authorized. One rule installs the camera. The other builds the gate.

The BCB was not shy about its reasoning. Resolution 588 states that self-custody wallets "can reduce the availability of information for monitoring and risk assessment purposes, unlike cases in which assets are held in custody in an institution authorized by the Central Bank." Read that sentence twice. The complaint is not that self-custody hides crime. The complaint is that self-custody hides information the state wants.

What the threshold actually selects for

Ten thousand dollars is a strange number if you are hunting criminals. It is not a strange number at all if you are building an inventory. The threshold sweeps in cold storage runs, UTXO consolidation, and anyone slowly moving savings off an exchange. None of those events needs to look suspicious, and the resolution does not require anyone to say that they do. Each report is a small brick: this verified identity moved this much to a wallet the reporter can now label.

Stack the bricks over a year and you have something the reporting architecture was never advertised as producing, an address registry keyed to know-your-customer files. COAF compiles what it receives. The Brazilian text raises that possibility by itself.

The market structure sharpens it. A CertiK report counts roughly 120 crypto providers operating in Brazil. According to Valor Econômico, five have applied for a BCB license, and one application has already been denied. Minimum capital under the framework runs from R$10.8 million to R$37.2 million depending on the business model. That arithmetic ends in a handful of licensed on-ramps, all of them legally obligated to file, all of them walled off from unlicensed counterparties.

Fewer doors, every one of them with a camera behind it, is a cleaner surveillance product than a hundred doors with none. Concentration is usually sold as a consumer-protection story, and this one is no exception, but the effect here is closer to an engineering decision.

The case against, put properly

The case against my reading deserves room, because it is not weak. Regulators face a real problem. When value leaves a licensed venue for an unhosted wallet, it leaves the supervised perimeter entirely, and the Financial Action Task Force has been pushing members toward exactly this reporting since its 2021 guidance update. Brazil is a G20 economy and a FATF member state, and it is implementing guidance it did not invent. Nothing in either resolution bans self-custody. A Brazilian can still withdraw to their own keys tomorrow. The obligation lands on the institution, not the holder.

The defense also has a falsifiable form. If COAF commits publicly to targeted investigation only, with judicial oversight, data retention limits, and no passive address-mapping program, the rule is ordinary AML hygiene wearing an unfamiliar shape. Watch for those commitments before October, because the resolution text does not contain them, and the agency's own language about self-custody reducing information availability points the other way.

The intermediary problem

Now put the two stories from this week next to each other, because they are the same story.

Bitget confirmed roughly $351.6 million in unauthorized transfers from its hot and warm wallet layers, detected at 18:31 UTC on September 24. Withdrawals froze platform-wide while the investigation ran. CEO Gracy Chen said the exchange's User Protection Fund holds more than $464 million and covers the whole loss, which on paper is a 132 percent coverage ratio. No independent attestation of the fund's composition exists, and the entity asserting that the fund is whole is the same entity that just lost the money on a Wednesday evening. I could not verify the fund's assets, their liquidity, or whether they are genuinely segregated from operating capital.

The attacker's mechanics are worth understanding, because they describe the fault line in custodial design. Blockchain researchers watched the funds consolidate across ETH, USDT, USDC, AVAX, BNB, and XAUT, then convert into ETH. Stablecoins carry an issuer who can blacklist an address at the contract level. ETH carries no such phone number. Swapping freezable assets into unfreezable ones is not cleverness, it is the standard response to a custody stack that spans multiple trust models. A system holding several kinds of token inherits several kinds of counterparty.

Chen later pointed at a North Korean group, citing IP addresses matching VPN choices, and said investigators found no forging of user withdrawal requests and no compromise of cold-wallet keys. IP-based attribution is thin evidence, no law enforcement agency has corroborated it, and the reasonable posture is a working hypothesis.

Bitcoin, 30 days through 25 September 2026
Bitcoin, 30 days through 25 September 2026

Here is the part that connects to Brazil. Resolution 588 makes the licensed exchange the state's information channel about self-custody. Resolution 589 makes that channel the only legal door. Bitget is a live demonstration of what those channels are: internet-connected infrastructure with a staff, a treasury, and an attack surface, run by a company whose protection fund is an unaudited claim made by the interested party.

Brazil's ledger therefore rests on exactly the institutions most likely to disappoint it. A surveillance architecture built on intermediaries does not just inherit their reach. It inherits their fragility, and it makes that fragility everyone's problem at once. The customers who could not withdraw from Bitget last week had done nothing wrong, held nothing suspicious, and still could not reach their own money.

What resolves it

Two things would settle the questions this week raised. Bitget pays every affected user in full, on time, with an independent attestation confirming the fund was genuinely segregated, and no payout stretched. And Brazil's legislature, or COAF itself, publishes the limits on what Resolution 588 data may be used for. If both arrive, the reading here is wrong and the year is unremarkable.

If they do not, the interesting fact is not that Brazil wants visibility, since states always do. It is that the visibility now runs through an institution that lost a third of a billion dollars in one evening, with bitcoin printing $84,380 on the daily index while this is written and no proof that the fund covering the hole is real.