According to a report by The Paper on January 19, 2026, a case involved a network information security engineer from Shenzhen who was accused of exploiting vulnerabilities in the servers of an overseas online gambling website to obtain a large volume of personal information and replacing the bank account used for receiving commissions for the gambling website’s agent accounts with an account under his own control. In this case, public security organs in Hunan and Henan provinces successively intervened and seized approximately 183 bitcoins from his digital wallet, with a converted value exceeding RMB 80 million. Subsequently, the People’s Procuratorate of Changge City, Henan Province, initiated public prosecution against him on suspicion of theft and infringement of citizens’ personal information. The report indicated that the case was heard in open court at the Changge Court in Henan in January 2026, and after adjournment, a further hearing will be scheduled.
This case is highly representative and serves as a reminder: when virtual assets, gambling platforms, technical intrusions, personal information, and on-chain assets are intertwined, criminal risks often extend beyond the single question of whether coins were “stolen.”
The fact that the counterparty is a gambling website does not mean that you may directly take away funds under its control.
Many technical professionals hold a misconception: because gambling websites are themselves illegal, the gambling funds, commissions, and illicit money within them are not protected by law; therefore, taking a portion of such funds does not constitute an infringement of lawful property.
This line of reasoning is perilous in criminal cases.
Illicit funds shall be recovered and confiscated by the state in accordance with the law; the problematic origin of such funds does not render them “public prey” available for arbitrary appropriation by anyone. If an actor obtains benefits by infiltrating backend systems, replacing payment accounts, controlling the flow of funds, or transferring away crypto assets, such new conduct may itself undermine computer system security, the order of property management, and the order of personal information protection, and may even be characterized as criminal offenses such as theft, illegal acquisition of computer information system data, or infringement of citizens’ personal information.
Conversely, it must be clarified: this does not mean that any involvement with funds from a gambling website necessarily constitutes the crime of theft, nor does it mean that the amount of virtual assets seized automatically determines the conviction and sentencing amount.
What criminal defense truly requires is not speaking on behalf of the gambling website or exonerating “black-on-black” conduct, but rather disaggregating and examining the conduct, the object, the amount, and the evidence.
Why such cases oscillate between different charges
According to public reports, this case has involved various charges at different stages, including operating a casino, illegally obtaining data from computer information systems, theft, and infringement of citizens’ personal information. On the surface, this appears to be a change in charges; in substance, it reflects different evaluative approaches by the handling authorities toward the same set of facts.
If the focus of the case is understood as “participating in or assisting in the operation of a gambling website,” the analysis tends to lean toward the charge of operating a casino.
If the focus of the case is understood as “accessing servers through vulnerabilities and obtaining backend data,” the discussion enters the realm of illegally obtaining data from computer information systems.
If the focal point of the case is construed as "replacing commission-receiving accounts to obtain funds that should have flowed to others," it may be evaluated as theft or other property crimes.
If the backend data contains information such as names, mobile phone numbers, ID card numbers, bank card numbers, account passwords, and location trajectories that can identify the identity or activities of specific natural persons, it may also give rise to charges of infringing upon citizens' personal information.
The complexity of cases involving virtual currencies lies herein: a single technical action may simultaneously implicate system permissions, user data, fund accounts, on-chain addresses, and fiat currency exchanges. If investigating authorities focus on only one aspect, they risk oversimplifying the case; likewise, if defense counsel fixates on a single charge, they may overlook evidentiary issues that truly impact sentencing and factual determinations.
Theft
A detail in public reports warrants attention: the prosecution alleged that the total amount of stolen funds exceeded RMB 35.5 million, of which more than RMB 6.44 million was transferred to bank cards purchased by the defendant, and another more than RMB 29.05 million was converted into virtual currencies such as Bitcoin through a criminal syndicate and transferred to the defendant's wallet. The public security organs in two jurisdictions ultimately seized a total of approximately 183 Bitcoins, with a converted value exceeding RMB 80 million.
At least several issues requiring verification arise here.
First, which agents correspond to the replaced commission-receiving accounts, what are the commission rules, and to whom should the funds have originally flowed? It is insufficient to merely state that "he changed the accounts"; one must examine whether backend records, account binding records, login logs, permission trails, and fund transaction records corroborate each other.
Second, whether the so-called commission funds are in RMB, USDT, BTC, or internal platform bookkeeping entries. Different asset forms correspond to different methods of control, acquisition, and valuation, and must not be commingled in calculations.
Third, how the alleged amount of over RMB 35.5 million translates into the subsequently seized 183 Bitcoins. This requires examination of bank statements, third-party accounts, exchange records, on-chain addresses, transaction hashes, KYC information, OTC counterparties, and cold wallet transfer paths. One cannot retroactively infer that "all these coins are proceeds of crime" simply because "coins were later seized."
Fourth, whether the seized Bitcoins include holdings from earlier periods, normal trading transactions, holdings on behalf of others, or commingled storage. Public reports mention that family members claimed the defendant had engaged in stock and cryptocurrency trading since 2016 and possessed certain Bitcoins. The validity of this claim must be supported by early trading records, deposit and withdrawal records, wallet address history, exchange accounts, and proof of fund sources.
Therefore, in theft cases involving cryptocurrencies, defense regarding amounts is not simply a debate over "whether virtual currencies possess property attributes." The essential task is to map out every accused fund flow from its source, acquisition, conversion, and transfer to its seizure. Where the chain of evidence is broken, where commingling occurs, and which time points and bases are used for price calculations will all affect the outcome of the case.
Infringement of Citizens' Personal Information
In this case, another charge mentioned in public reports is the infringement of citizens’ personal information. The prosecution contends that the defendant obtained the personal information of more than 1.84 million Chinese citizens from gambling websites through technical means. The defense, however, argues that the relevant external hard drives were not sealed, there are traces of multiple modifications to the electronic data, much of the information does not constitute complete personal information, and the defendant did not derive profit therefrom.
In similar cases, the assertion that “the data volume is large” can easily create a psychological impact, but criminal determinations cannot be based solely on quantity.
It is first necessary to examine whether such data constitutes citizens’ personal information within the meaning of the Criminal Law. Website accounts, betting records, IP addresses, device identifiers, agent codes, commission rebate ratios, and the number of downstream referrals may be highly sensitive or important for investigative purposes, but it cannot be presumed as a matter of course that they can, alone or in combination with other information, identify specific natural persons.
It is also necessary to assess the reliability of the processes for obtaining, preserving, authenticating, and comparing the data. In cases involving electronic data, the greatest concern arises when findings are summarized in a single statement such as “a certain number of records were discovered on the hard drive.” Issues such as when the hard drive was seized, who maintained custody, whether it was sealed, how the forensic image was created, whether hash values matched, whether the data was altered, what deduplication rules were applied, and which fields were counted toward the total number of personal information items can all affect the admissibility and probative value of the evidence.
At a deeper level, it is necessary to examine the relationship between the conduct involving personal information and the conduct aimed at obtaining property. If the backend data was accessed solely to filter for agent accounts with high commission rebate ratios and numerous downstream referrals, and there was no separate sale, provision, exchange, or use for other unlawful activities, then a key defense issue will be whether the conduct should be separately evaluated as the crime of infringing citizens’ personal information, or instead assessed holistically as an instrumental step in the property-obtaining conduct.
This is not to exonerate the defendant as a matter of course, but rather to remind family members: when the indictment cites “infringement of citizens’ personal information,” do not be intimidated by the numbers alone. Instead, systematically analyze the data types, identifiability, completeness, evidence-collection procedures, intended uses, and any profits derived.
Involvement of Technical Personnel
Such cases carry particular cautionary significance for technical personnel.
Many professionals in cybersecurity, data, and blockchain may characterize their conduct as “discovering vulnerabilities,” “running data queries,” “reviewing backend systems,” “conducting tests,” or “exploiting platform incentives.” However, criminal justice proceedings will not focus merely on how the actor labels the action, but rather on the role that action played within the overall chain of conduct.
Merely discovering a vulnerability and reporting it in accordance with the law is entirely different from exploiting the vulnerability to access systems, export data, control accounts, or transfer funds.
Merely studying on-chain transactions is entirely different from knowingly providing addresses, channels, scripts, or conversion services for funds derived from online gambling, fraud, or money laundering chains.
Merely having access to certain technical interfaces is entirely different from understanding the platform’s agent hierarchy, commission rebate rules, account-binding logic, and fund settlement pathways, and leveraging those rules to obtain profits; the criminal risks in these scenarios are fundamentally different.
Technical capabilities are often not neutral in criminal cases. They may serve as important sources of evidence regarding the actor’s knowledge, control capabilities, implementation capabilities, and intent to illegally possess. How vulnerabilities are discussed in chat records, what actions the code and scripts performed, which backend pages were accessed, whether verification was circumvented, whether identities were concealed, and whether funds were dispersed and transferred will all be used to reconstruct the actor’s subjective awareness.
Materials that family members and the client should organize first
If family members encounter similar cases, they should not pin all their hopes on the statement that “the other party was also acting illegally.” This statement can at most indicate that the case background is complex; it cannot substitute for facts and evidence.
A more practical approach is to promptly organize several categories of materials.
First, procedural materials: detention notices, arrest warrants, seizure decisions, seizure inventories, documents related to release on bail pending trial or changes to compulsory measures, and records of changes in the handling authorities and charged offenses. In crypto-related cases, joint handling by authorities in two locations, repeated seizures, cross-jurisdictional handling, and liquidation of seized assets may all become entry points for procedural review.
Second, technical materials: servers involved in the case, backend systems, accounts, access permissions, login logs, code and scripts, methods of exploiting vulnerabilities, scope of data exports, and the processes for device seizure and electronic data extraction. Technical issues cannot rely solely on oral explanations; they must be translated into evidentiary issues that are understandable within the case file.
Third, financial materials: bank card statements, exchange account records, on-chain addresses, transaction hashes, cold wallet records, OTC counterparties, proof of early cryptocurrency purchases, and explanations of fund sources. In particular, the correspondence between seized virtual assets and the alleged proceeds of crime must be verified item by item.
Fourth, communication materials: chat records, emails, support tickets, agreements on remuneration, identities of trading counterparties, evidence of instigation or inducement by others, and evidence of selling data or seeking additional profits. Subjective knowledge and intent to illegally possess are often inferred from these fragmented pieces of information.
Fifth, materials regarding family and corporate background: professional experience, lawful business activities, early investment records, corporate operational documents, sources of income, and sources of family assets. While these may not directly determine guilt or innocence, they help explain commingling of funds, early holdings of cryptocurrencies, and behavioral motives.
Concluding Remarks
Cases involving “black-on-black” conduct in the virtual asset sector are most prone to misjudgment.
On one hand, given the involvement of gambling websites, illicit funds, and overseas platforms, family members may easily question why the other party should receive any protection. On the other hand, due to the presence of Bitcoin, on-chain addresses, backend data, personal information, and cross-regional seizures, handling authorities may easily steer the case toward characterizations involving high amounts, high technical sophistication, and significant harm.
Effective criminal defense cannot rest solely on emotional judgments.
In theft cases, it is essential to determine whether the acquired item constitutes 'property' within the meaning of criminal law, who had control over it, how it was obtained, and how the amount involved is calculated. In cases involving the infringement of citizens' personal information, key considerations include whether the data can identify specific natural persons, how the quantity is verified, and whether the data has independent utility. For virtual assets involved in a case, it is crucial to examine whether the source, circulation, commingling, and seizure and disposal processes form a closed chain of evidence.
If you or your family members are already involved in criminal cases related to virtual assets, technical intrusions, platform funds, or personal information, the first step is not to seek an absolute answer online, but to clearly organize the case stage, changes in charges, seizure lists, on-chain addresses, fund flows, backend access permissions, and the status of electronic data forensics. Under different factual structures, the conclusions may vary significantly.