PLN 7.6 million disappeared from the wallet. The seed was on a phone secured by KAS

Over 2.1 million USDT disappeared from the wallet belonging to the famous streamer Szymool. The man claims that he did not approve the transaction, and the phrase allowing him to take control of his cryptocurrencies was in a phone secured a few months earlier by the National Tax Administration.

The transfer date is the most controversial. The payment was to be made on the exact day when IT specialists finished examining the streamer’s devices. Eight days later, another transfer was made, and one of the digital traces was supposed to lead to an IP address located in Opole.

For now, this is not evidence of the involvement of officers or office employees. However, the coincidence of circumstances means that the case may become one of the most famous Polish proceedings regarding cryptocurrencies and the security of digital evidence.

Szymool’s phone and tablet ended up in the hands of KAS

On November 20, 2025, officers of the National Tax Administration detained Szymon Besser, known on the Internet as Szymool. According to Zero.pl’s findings, devices belonging to him were then secured: iPhone 16 Pro Max and iPad Pro.

The equipment was to be handed over to IT specialists to copy and examine the data contained on it. The activities were part of proceedings regarding the promotion of online casinos, which cannot legally offer their services to players residing in Poland.

The media reported the streamer’s detention in November. Szymool was released after interrogation, but according to reports at the time, he was banned from leaving Poland. The FAME MMA spokesman presented the activities of KAS as routine activities related to the ongoing proceedings.

Besser himself pleads not guilty to the charges against him and considers himself innocent. The gambling promotion investigation is a separate case from his reported disappearance of cryptocurrencies.

24 words gave you access to millions

According to Szymool, his phone and tablet were logged into the same iCloud account. The synchronized Notes application was supposed to contain a 24-word recovery phrase, i.e. a seed phrase allowing to recreate the cryptocurrency wallet.

This phrase acts as a primary key. The person who recognizes it no longer needs the owner’s phone, lock code, fingerprint or application password. He can type the words on another device, recreate the wallet and sign the transaction himself.

Szymool claims that only he knew the phrase. If it was indeed saved in a note synchronized via iCloud, potential access to the funds did not necessarily require the physical use of a secured phone. All you need is access to your account, a copy of your data, or another synchronized device.

It’s also a brutal reminder why seed phrases should never be stored in the cloud, email, instant messaging, or regular notes app.

On April 1, 2.1 million USDT disappears from the wallet

The most important transaction took place on April 1, 2026. Accurately sent from the wallet associated with Szymool 2,111,263.74962 USDT. At the time of the transfer, the cryptocurrencies were worth approximately $2.1 million, or over PLN 7.6 million.

The transaction was recorded in the Ethereum network. Blockchain allows you to confirm the amount of the transfer, the time of its execution and the addresses of the sender and recipient.

However, the public register does not reveal who entered the seed phrase and approved the operation. The wallet address does not contain the name, surname or details of the device from which the transaction was signed. Szymool assures that he did not make the transfer and did not authorize anyone to do so. At that time, he was supposed to be in Malta, while the secured devices were still in Poland.

A surprising coincidence of dates

According to the information provided to Zero.pl by the streamer and his representative, IT specialists completed the examination of the phone and tablet on April 1, exactly on the day of the transfer of 2.1 million USDT.

The devices were then to be returned to an officer associated with the Opole Customs and Tax Office.

This is the strongest circumstantial evidence presented by Szymool, but it still does not settle the case. The exact time of completion of the equipment examination and its handover was not given. Therefore, it is not known whether this occurred before or after the cryptocurrency transfer.

Another transfer and IP address from Opole

The story does not end with the main transaction.

On April 9, eight days later, another 10,000 USDT was transferred from the wallet that received over 2.1 million USDT. USDT. The funds were then to be exchanged for bitcoin.

Szymool also presented an analysis according to which one of the operations was associated with an IP address located in Opole. In the same city there is the office conducting the activities and the place where the streamer’s equipment was supposed to be tested.

This trace also needs to be treated carefully. IP geolocation usually indicates an approximate area, operator headquarters or network node. It does not identify a specific person. The user could also use a VPN, an intermediary server or a remotely controlled computer.

In other words: Opole is an interesting clue, but it is not proof of the guilt of the office employee or officer.

USDT was to be frozen

The good news for the streamer is that most of the funds are probably not permanently lost yet.

According to Zero.pl, the stolen USDT has been frozen and cannot be transferred any further at this time. Szymool was to report the matter to both Polish and Maltese authorities. The services in Malta then contacted Tether, the issuer of USDT.

Unlike native bitcoin, USDT is a token controlled by a central issuer. Tether can block specific addresses and prevent the transfer of tokens on them. The company has repeatedly confirmed that it carries out such operations in cooperation with law enforcement agencies.

In some proceedings, Tether not only froze funds, but also invalidated tokens located at the blocked address and re-issued them to the rightful owner. It is such a scenario that could enable Szymool to recover millions, provided that his ownership and the unauthorized nature of the transaction are formally confirmed.

Could cryptocurrencies have been taken over by someone with access to the phone?

This cannot be ruled out at this stage. Nor can it be considered proven.

There are several alternative scenarios. The seed phrase may have been previously copied, malware may have stolen it, it may be on another synced device, or someone may have accessed your iCloud account. It is also possible that it was disclosed before the equipment was secured.

What will be decisive will be not just screenshots or IP geolocation, but the full digital material: iCloud logs, login history, device data, hours of copying, list of people in contact with the equipment, a record of the IT tools used and the further path of USDT on the blockchain.

The chain of custody will be key

In the case of a secured phone, it should be possible to determine exactly who received the device, where it was stored, when it was activated and to whom it was given.

The Code of Criminal Procedure requires that the report on the seizure or search of property should include, among other things, the exact start and end time of the activity, a list of secured items and an indication of the court’s or prosecutor’s order.

Computer forensics standards require maintaining data integrity and a strict chain of custody. NIST emphasizes that digital data can be changed relatively easily, so it is crucial to document its acquisition, copying, examination and transmission.

Szymool’s case touches on a broader problem of Polish procedures. The Ombudsman pointed out that the current regulations on searching electronic data carriers do not correspond to the realities of the modern world, and phone inspection procedures do not provide sufficient protection against arbitrary access to private information.

A serious accusation, but not yet proof

Based on available information, it can be confirmed that over 2.1 million USDT was transferred on the Ethereum network. You can also analyze the further path of funds and set dates for individual operations.

However, no evidence has been publicly presented to determine who learned the seed phrase and who signed the transaction. There is also no published position of KAS or the prosecutor’s office regarding the streamer’s allegations.

If device logs, documentation of their security and on-chain data confirm Szymool’s version, we will be dealing with an unprecedented scandal regarding the security of property under the control of state institutions.

If not, the source of the phrase leak will have to be looked for elsewhere.

For now, one thing is certain: 24 words saved on the phone gave access to a fortune, the movement of which could not later be hidden from the blockchain.