Abstract:
When a family member or friend is detained in connection with virtual assets, is your primary concern “what sentence will ultimately be imposed?” This article aims to help you understand this issue. For the same act of transferring virtual currencies from another person’s account, some defendants receive sentences exceeding ten years, while others receive slightly more than three years. What accounts for the difference? The key lies in whether the charge is classified as “theft/fraud” or as “the crime of illegally obtaining data from computer information systems.” The former carries a statutory minimum sentence of ten years, whereas the latter has a maximum sentence of seven years. Drawing on actual judgments from Shanghai, Zhejiang, and other jurisdictions, this article explains that if technical means such as phishing websites, Trojan programs, or password theft were employed, there is a significant opportunity to argue for classification under the lesser offense. Promptly assess whether your family member’s or friend’s circumstances fall within this category, as this directly affects the defense strategy and the final sentencing outcome.
Keywords:crime of illegally obtaining data from computer information systems, theft of virtual currencies, characterization of charges, sentencing defense, criminal defense lawyer
Main Text:
In criminal cases involving virtual assets, many parties involved or their families often ask: Why are some cases of transferring another person’s virtual currencies from their account characterized as theft or fraud, while others are handled as the crime of illegally obtaining data from computer information systems?
Such differences in legal characterization are not isolated instances in judicial practice.
However, the sentencing ranges for these two offenses differ markedly: the former may entail imprisonment of ten years or more, or even heavier penalties, whereas the latter carries a maximum term of seven years.
Therefore, in theft- or fraud-related cases involving virtual assets where the amount involved is substantial, whether it can be argued that the conduct more closely satisfies the constituent elements of the crime of illegally obtaining data from computer information systems often directly influences the direction of the defense and the ultimate sentencing.
Drawing on the practical experience of Attorney Shao Shiwei’s team in handling such cases and relevant precedents, this article attempts to outline the circumstances under which arguing for characterization as the crime of illegally obtaining data from computer information systems is more likely to gain court support.
I. Author: Attorney Shao Shiwei
1
Where the perpetrator’s methods exhibit distinct technical features, there is greater scope to argue for characterization as the crime of illegally obtaining data from computer information systems
In cases involving the transfer of virtual currencies, even if the investigating authorities initially tend to characterize the conduct as property-related offenses such as theft or fraud, where the perpetrator’s core modus operandi reflects technical means, it is necessary to focus on arguing that the conduct more closely satisfies the constituent elements of the crime of illegally obtaining data from computer information systems.
Under the provisions of the Criminal Law concerning the crime of illegally obtaining data from computer information systems, establishing this offense typically requires that the perpetrator bypass the security protections of a computer information system through technical means.
For example: inducing users to input mnemonic phrases or account passwords through phishing websites; sending victims fake software containing Trojan programs (such as counterfeit Telegram applications or exchange clients); exploiting system vulnerabilities to obtain control over account permissions; or remotely controlling another person’s digital wallet in the background and transferring the virtual assets held in the account.
From the perspective of technical implementation, these acts usually involve cracking account passwords, exploiting system vulnerabilities, implanting Trojan programs, or unlawfully controlling account permissions. In essence, they constitute intruding into or controlling computer information systems through technical means and obtaining the data stored therein.
Therefore, if the perpetrator’s modus operandi primarily consists of intruding into systems, controlling accounts, or obtaining system data through technical means, then in cases involving the transfer of virtual assets, even if the case-handling authorities initially lean toward classifying the conduct as theft or fraud, there remains room to argue for characterization under the crime of illegally obtaining data from computer information systems.
In judicial practice, certain typical cases have been characterized by courts as the crime of illegally obtaining data from computer information systems precisely because the perpetrators primarily controlled accounts through technical means.
For instance, in the case of Cai tried by the Jing’an District People’s Court of Shanghai Municipality in 2023 [Case No.: (2023) Hu 0106 Xing Chu 112], the virtual assets transferred by the defendant Cai from others were statistically determined to be 99.01 BTC and 1,192 ETH. Based on a rough estimate using the market prices of Bitcoin and Ethereum at the time, the amount involved approached RMB 50 million at its highest.
If characterized as theft, and absent any statutory mitigating circumstances, such an amount would typically entail a sentencing risk of fixed-term imprisonment of ten years or more.
However, based on the specific modus operandi ascertained in the case, the defendant did not engage in the traditional direct appropriation of property, but rather obtained and controlled account permissions through a series of technical pathways. Specifically, these included:
The defendant promoted pre-established phishing websites through search engine advertisements, inducing users to download and install counterfeit Telegram messaging software containing hidden Trojan programs; subsequently, the defendant unlawfully obtained user accounts and related authentication information through the Trojan programs. After obtaining the relevant account passwords, the defendant logged into the virtual asset accounts of multiple employees of a Shanghai-based company (the victim entity) and converted and transferred the virtual assets controlled in those accounts to accounts under the defendant’s control.
Viewed as a whole, the core method employed was to intrude into and control others’ accounts through technical means, thereby obtaining the virtual asset data stored in the systems.
Accordingly, the court ultimately held that the conduct more closely matched the constituent characteristics of the crime of illegally obtaining data from computer information systems, and on that basis sentenced the defendant to fixed-term imprisonment of three years and four months.
This case also illustrates that, in cases involving the transfer of virtual assets, if the core of the conduct lies in obtaining and controlling accounts through technical means, rather than directly committing traditional property-acquisition acts, there is room to characterize the offense as the crime of illegally obtaining data from computer information systems.
2
Even in the absence of a typical "hacking attack," as long as the essence of the conduct constitutes unauthorized access to or control of a system, it may still be possible to argue for treatment under the crime of illegally obtaining data from computer information systems.
In practice, the more controversial cases are often not those involving typical "hacking attacks," but rather those where the actor, without using obvious cracking techniques, Trojans, or exploit vulnerabilities, accesses another person's digital wallet or account system and completes the transfer of virtual assets by means such as account credentials, authorization boundaries, or control permissions.
For example, an actor may log into another person's digital wallet or trading account by purchasing account credentials, stealing login information, or obtaining mnemonic phrases or verification codes, and then proceed to transfer virtual assets.
On the surface, such conduct appears closer to traditional property-infringing offenses, such as theft or fraud.
However, from the perspective of the operational mechanisms of computer information systems, the actor is, in fact, accessing and controlling another person's account system without authorization, thereby obtaining data stored in the system or control permissions over assets.
Therefore, within the framework of a defense strategy aimed at securing a lesser charge, it can be argued that such conduct falls under the circumstance of "adopting other technical means" within the crime of illegally obtaining data from computer information systems.
This view has received some support in judicial practice. For instance, Guiding Case No. 36 published by the Supreme People's Procuratorate (Procuratorial Guiding Case No. 36: Wei Menglong, Gong Xu, and Xue Dongdong – Case of Illegally Obtaining Data from Computer Information Systems) reflects this approach.
In that case, a current employee conspired with a former employee, whereby the current employee provided the former employee with account credentials, passwords, and token tokens for the company's internal management and development system that were within the current employee's knowledge. The former employee subsequently logged into the company's computer information system, downloaded electronic data stored in the system, and handed over the relevant data to others for online sale and profit.
The court held that "intrusion" in the context of the crime of illegally obtaining data from computer information systems refers to the act of illegally entering a computer information system against the will of the victim. In terms of specific manifestations, this includes both the use of technical means and situations where the actor lacks the victim's authorization, or has authorization but acts beyond its scope.
Therefore, in that case, even though the actor did not carry out typical technical attack behaviors, but merely logged into the system to obtain data by acquiring system account credentials and tokens, the conduct was still determined to constitute the crime of illegally obtaining data from computer information systems.
In addition to the aforementioned guiding cases with demonstrative significance, in specific judicial practice, many courts have adopted this interpretive approach in similar cases and accordingly evaluated the relevant conduct under the crime of illegally obtaining data from computer information systems.
For example, in a case heard by the Wenzhou Intermediate People’s Court of Zhejiang Province [Case No.: (2019) Zhe 03 Xing Zhong No. 1117], the defendant created a “BTCETH Secured Transaction Group” and recruited members under the pretext of providing escrow services for Ethereum transactions. On a certain day, the victim posted information about selling Ethereum in the group, and the defendant falsely claimed to purchase it. After the victim transferred the Ethereum to the wallet address designated by the defendant, the defendant immediately blocked and removed the victim from the WeChat group, and subsequently cashed out the 60 ETH obtained through fraud for approximately RMB 300,000.
During the trial, the procuratorial organ argued that the conduct should be characterized as fraud, warranting a fixed-term imprisonment of four to six years. However, after adjudication by courts at two levels, the court of final instance held that the defendant’s actions of blocking and removing the victim prevented the victim from continuing to trace the flow of funds. This conduct exploited the technical features of remote, non-contact operations via instant messaging software, with an effect similar to “obtaining data by deception from another person’s computer information system.” Accordingly, the defendant was ultimately found guilty of the crime of illegally obtaining data from a computer information system and sentenced to fixed-term imprisonment of three years and ten months.
Similarly, in a case adjudicated by a Chongqing court [Case No.: (2022) Yu 04 Xing Zhong No. 154], the defendant secretly recorded the digital wallet address and password of another party by taking photographs, and thereafter unauthorizedly logged in and transferred the virtual assets from that party’s wallet. The court likewise determined that the act of photographing constituted the use of “technical means,” and thus convicted the defendant of the crime of illegally obtaining data from a computer information system.
In light of the foregoing cases, it can be seen that in certain cases, judicial authorities adopt a relatively broad interpretation of “technical means,” which provides some room for characterizing the offense as a lesser crime.
3
Why do courts support handling certain cases as the crime of illegally obtaining data from a computer information system, while other cases are still characterized as theft or fraud?
However, in judicial practice, some case-handling authorities remain inclined to characterize such conduct as traditional property-infringing crimes. Their reasoning typically includes: first, the view that virtual assets constitute “property” within the meaning of the Criminal Law; and second, the view that after obtaining control over the account, the perpetrator also engaged in acts such as transferring, disposing of stolen goods, and cashing out. If evaluated solely as the crime of illegally obtaining data from a computer information system, it would be difficult to fully reflect the nature of the unlawful appropriation of property.
For example, in a case heard by the Xuhui District People’s Court of Shanghai Municipality (Case No.: (2023) Hu 0104 Xing Chu No. 856), three employees of a cybersecurity company were ultimately found guilty of theft for stealing another person’s virtual assets, and were sentenced to fixed-term imprisonment of ten years and six months (for further reading ➡️In cases involving the theft of virtual assets, does the conduct constitute the crime of theft or the crime of illegally obtaining data from a computer information system?)。
However, as can be seen from the aforementioned case before the Wenzhou Intermediate People’s Court and Guiding Case No. 36 issued by the Supreme People’s Procuratorate, even if the perpetrator subsequently engages in acts such as transferring, selling, or cashing out, the court may still determine that the conduct constitutes the crime of illegally obtaining data from a computer information system, based on the specific technical pathway and modus operandi.
Therefore, in cases involving the transfer of virtual assets, the determination of the charge often depends on the evaluation of the manner in which the act was carried out. As defense counsel, it is necessary to argue around the constituent elements of the crime of illegally obtaining data from a computer information system, by combining the perpetrator’s specific modus operandi, the method of obtaining account control, and the pathway of system intrusion, so as to seek room for characterizing the offense as a lesser crime.
4
Conclusion
As can be seen from the foregoing cases, there is no clear and uniform conclusion regarding the legal evaluation of conduct in cases involving the transfer of virtual assets. Even where the conduct involves obtaining and transferring virtual assets from another person’s account, different behavioral pathways, technical means, and evidentiary circumstances may lead to entirely different determinations of charges and sentencing outcomes.
It is precisely for this reason that the crux of such cases lies in how judicial authorities evaluate the modus operandi. In practice, significant room for defense often remains regarding issues such as whether the conduct constitutes unauthorized access to computer information systems, whether it amounts to obtaining system data, and whether it can be adequately addressed under property-infringement crimes.
For parties involved in such cases or their family members, even if there is limited scope to reduce the amount involved from a monetary perspective, opportunities may still exist to strive for a more favorable characterization of the charges.

Special Disclaimer: This article is an original work by Attorney Shao Shiwei. It reflects only the personal views of the author and does not constitute legal consultation or legal advice on specific matters. For article reposting, legal consultations, or professional exchanges, please add: sswls66.
Recommended Reading


