Brazil Seizes Record $1.7M From Self-Custody Wallets in Operation ClickFix
Brazil's Civil Police seized more than R$8.7 million in crypto from self-custody wallets during Operation ClickFix, recovering four seed phrases during physical raids and transferring funds via Chainalysis-assisted blockchain analysis. The cryptography was never broken.

Brazil's Civil Police cracked self-custody crypto for the first time at scale, not by breaking the cryptography, but by finding the seed phrases.
Key takeaways
- The Civil Police of Santa Catarina seized more than R$8.7 million (roughly $1.7M USD at the time of seizure) in crypto from self-custody wallets during Operation ClickFix on September 10, 2026, the largest such seizure ever recorded by a Brazilian state civil police agency.
- Police physically recovered what reports describe as four seed phrases during raids, imported the wallets, and moved funds to a state account on exchange Foxbit, using Chainalysis tools to identify assets.
- The cryptographic layer of Bitcoin was never compromised. Criminals stored seed phrases on internet-connected, malware-infected devices. That opsec failure, not any technical exploit, is what law enforcement capitalized on.
The Civil Police of Santa Catarina, operating through its Cybercrime Repression Police Station and State Directorate of Criminal Investigations (DRCI/DEIC), announced on October 7, 2026 the results of Operation ClickFix, a September 10 enforcement action targeting a cybercrime ring that had penetrated Brazilian police systems, the judiciary, and financial-sector supply chain companies. The Brazilian Ministry of Justice published its own official account the following day.
The operation executed 17 search-and-seizure warrants and 2 arrest warrants, froze nearly R$93 million (approximately $18.5M USD) in bank accounts, seized urban real estate valued at R$5 million, and confiscated luxury vehicles including a Corvette valued at over R$1.5 million.
How They Got Into the Wallets
The criminal group used ClickFix social engineering: fake browser error alerts tricked victims into pasting malicious code directly into their OS terminal, handing attackers full device control. Dark Reading has documented ClickFix as an active, evolving attack vector well beyond Brazil.
When DRCI/DEIC detective Eduardo Graebin's team raided the suspects, they found, according to reports, four seed phrases on seized devices. They imported the wallets and used Chainalysis tools to map the assets, then moved the funds into the Santa Catarina Civil Police's institutional account on Foxbit, a Brazilian centralized exchange.
"This result demonstrates, in a concrete way, how specialized technical knowledge and the use of appropriate tools can represent the difference between locating or failing to seize more than one million reais in assets related to criminal activity," Graebin said in the PCSC release. He called it "the largest seizure of this nature ever recorded among the Civil Police of Brazil."
The record claim is scoped to state civil police agencies specifically. Brazil's Federal Police (Polícia Federal) operates separately and may have larger seizures on record.
What This Actually Signals
Reading this as proof that self-custody doesn't work is the wrong frame, and it's likely the frame the state benefits from most.
The seed phrases were on networked devices that had already been compromised by the group's own malware. The attackers beat themselves. Police found the keys lying in plain sight on hardware the criminals had already surrendered control of.
Bitcoin's cryptography was not touched. An airgapped hardware wallet with a BIP39 passphrase and no digital seed backup still sits beyond reach of this enforcement action. The opsec gospel, keep your seed phrase off any networked device, period, is exactly the countermeasure this case validates. For context on how Brazil is tightening the regulatory perimeter around self-custody in parallel, Brazil's Central Bank issued Resolution BCB No. 588 on September 23, 2026, requiring regulated institutions to report crypto transfers of $10,000 or more to or from self-custody wallets to Coaf, effective October 1, 2026.
The more durable signal is infrastructure. Chainalysis is now standard-issue law enforcement tooling in Brazil, mentioned not as a breakthrough but as routine. The Ministry of Justice's Ciberlab cybercrime laboratory is scaling. The state's technical capacity on crypto enforcement is purpose-built and improving.
The ClickFix attackers also made a specific, notable error in target selection: they penetrated state systems, including the police and the judiciary, before monetizing crypto. That guarantees maximum institutional motivation for the response. When you hack the cops, the cops build a better crypto seizure unit.
What to Watch
Brazil's enforcement apparatus is self-funding in design. Law No. 15.358, signed by President Lula on March 25, 2026, already authorizes seized crypto to fund police re-equipment, training, and special operations with judicial approval. Each record seizure raises the floor for the next one. The seed-phrase recovery here is a capability demonstration, not a ceiling.
Sources
Frequently Asked Questions
How did Brazilian police access self-custody wallets without breaking the private key?
During physical raids, investigators found, according to reports, four seed phrases stored on seized devices. Those phrases were used to import the wallets directly, giving police full access to the funds. The Bitcoin protocol was never exploited. This was a physical evidence recovery, not a cryptographic attack.
What is the ClickFix attack technique?
ClickFix is a social engineering method where victims are shown fake browser error messages prompting them to "fix" the problem by pasting code into their computer's terminal. That code installs malware and hands the attacker full control of the device. The group used this to compromise Brazilian government agencies, police systems, and private-sector companies before using the access to steal funds they subsequently held in self-custody wallets.
Does this mean governments can seize Bitcoin from self-custody wallets?
Yes, if opsec fails. No, if it doesn't. The attack surface exploited here was bad key management, specifically seed phrases stored on internet-connected, malware-compromised devices. A seed phrase that exists only in a person's memory, or secured on an airgapped device with no digital backup, was not at risk in this scenario.
The lesson is not that self-custody is vulnerable. The lesson is that seed-phrase security is the entire security perimeter, and it has to be treated that way.


