The Zonda Wallet That Woke Up
Five and a half million zlotys, a single private key, and a court order that was already in force.
By Robert Nogacki
The wallet I am about to describe has one door and one key. For two and a half years, the only money that entered it came from the Zonda exchange, and the only money that left it went back to Zonda; the key belonged to someone known to no one but themselves. On Saturday, August 22, 2026, at 3:39 in the afternoon, Warsaw time, that someone turned the key for the first time since April. They did so while an Estonian court was already forbidding the company from disposing of its assets, and while the defense team of its chief executive was preparing to announce that their client had placed “an enormous fortune” at the disposal of prosecutors. Out went twenty-one thousand XRP, roughly a hundred and five thousand zlotys, or about twenty-nine thousand dollars. Inside remained 1,108,000 XRP: some five and a half million zlotys, a little over a million and a half dollars.
These are the findings of a joint investigation by my firm, Kancelaria Prawna Skarbiec, and the newsroom of money.pl, one of Poland’s largest business-news sites, which is publishing the reported version of this story, complete with the parties’ responses. This piece is something else. It is the technical and evidentiary layer that usually gets relegated to footnotes and that, in this case, is the whole story. It is also the latest installment in a series I have been writing since April: it began with Zonda’s cold wallet and the dismantling of the claim that the keys had vanished with the exchange’s founder, continued with the exchange that lent out its customers’ money and the merger of two criminal investigations, the wallet itself I first described publicly in May, in an interview with Forbes Polska, and it returned in August in an inventory of the “enormous fortune” that money.pl also covered. I will write plainly, because behind every sentence stands an entry in a public ledger that any reader can verify by clicking a link.
Why XRP Leaves a Trail That Cannot Be Wiped
Begin with the object of the story, because without it the rest is incantation. XRP is the native currency of the XRP Ledger, a public register that has existed since 2012. It differs from Bitcoin in its construction: there is no mining and there are no miners; transactions are approved by a network of independent validators that agree, every few seconds, on the next version of the book, and the entire supply of a hundred billion XRP was created at once, at the start. A transfer settles in three to five seconds and costs a fraction of a cent. What matters for this story, though, is something else. Every transaction stays in the book forever, with its amount, its time to the second, and the addresses on both ends, and anyone with a browser can read the book.
Two popular shorthands deserve to be disarmed at the outset. The first: XRP is not “DeFi.” Decentralized finance means financial protocols that run without an intermediary; the XRP Ledger is simply a register, and holding XRP at your own address is self-custody, like cash in a safe. Zonda was the precise opposite of DeFi: a centralized exchange with a ledger, accounts, and a chief executive, and the entire drama of this case rests on the fact that there was an intermediary. The second shorthand: “the blockchain is anonymous.” It is not. It is pseudonymous. An address is a pseudonym under which every movement is visible, minus the name. The name appears at the exact moment the pseudonym touches the regulated world, an exchange, a payments app, a currency booth, because there every customer has passed an identity check. This is why cryptocurrency investigations rarely end on the blockchain and almost always end at the seam between the blockchain and an institution that knows its customer. We will return to that seam, because on August 22 the wallet reached it.
Anatomy of the Zonda Wallet: Two and a Half Years in a Dozen Numbers
On the XRP Ledger, an account does not exist until someone deposits into it a base reserve. An account, in other words, has to be funded into being, and whoever funds it signs the transaction with their own key. On November 27, 2023, at 9:52 A.M. Coördinated Universal Time, the Zonda exchange’s account, identified in the ledger by a verified domain, zondacrypto.com, sent exactly eleven XRP to an address that did not yet exist: the reserve of the time, ten XRP, plus a small cushion (the reserve was lowered to one XRP only in December, 2024). Thus was born the address rKkujfkmhasWFZxoPVh6s1WbR5azFiuMro. Over the next hour and forty-two minutes, ten more tranches arrived from the same account, a million XRP in all.
Then came the whole of 2024, in which nothing happened. Not a single transaction. In early 2025, the exchange topped the wallet up with 300,989.18 XRP in six transfers, and between February and August of that year the wallet sent 300,988.62 XRP back to the exchange in four transfers, the last of them, two hundred thousand XRP, closing the account; each carried the same internal marker, 23531. The difference between what came in and what went back was 0.565 XRP, less than three zlotys. The balance returned to a million. This is not what managing one’s own money looks like. It is what a bookkeeping reconciliation looks like, someone squaring a balance to the fraction.
On the evening of April 7, 2026, the day before withdrawals were halted, Zonda’s fortune made its last move toward this address. 133,692.56 XRP arrived at the exchange’s account from outside; fifteen minutes and nine seconds later, the exchange sent 32,500 XRP to the wallet under examination, and seventy seconds after that 97,499.6 XRP: 97.2 per cent of what it had just received. The next day, Zonda shut the door on withdrawals for thirty thousand customers. On April 11, the wallet sent a thousand XRP to Binance, to a specific sub-account, and fell silent. The follow-up never came.
Until August 22. At 1:39:20 P.M. U.T.C., a thousand XRP went out; exactly sixty seconds later, twenty thousand, both to the same address and the same sub-account. A thousand, then twenty thousand a minute later, is the sequence that practitioners call a test transfer; the ledger records no intentions, only patterns, and the August pattern is the April pattern carried through to the end. In April, someone checked one route and abandoned it; in August, someone checked another and took it. The abandoned route, through Binance, I had described publicly, sub-account number included; the August operator chose an exit that nobody had publicly flagged. Someone is reading the information around this wallet and avoiding the marked doors.
The full accounting: inflows from the exchange of 1,430,989.22 XRP across nineteen transactions; outflows of 322,988.62 XRP across seven; a balance of 1,108,000.60 XRP, matching the ledger to within fractions of a cent, the gap being network fees. The only inflows from anywhere other than the exchange in the entire history of the address are twenty-three micropayments of 0.000001 XRP each, the “dust” with which automated monitoring systems tag wallets they are watching: a fraction of a cent in total. This is the Zonda wallet in numbers. I state the dust plainly because rigor cuts both ways: the sentence “every deposit came from the exchange” would be false by one and a half billionths of a per cent, and the defense would seize on that inaccuracy more eagerly than on the million.
The Number on the Envelope
The recipient address of August 22 is an institution’s omnibus account: a shared mailbox into which thousands of customers drop their envelopes. So that the operator knows whose account to credit, the sender writes a number on the envelope, a Destination Tag, an ordinary integer in a field of the payment whose meaning is assigned solely by the recipient’s own system. Both August transfers bore the same number: 4227973493. The number is public; it sits in the ledger for anyone to see. But only the operator of the mailbox can match it to a human being, because only the operator has the list of tenants. This is the hole in the anonymity through which the entire path to recovery runs: a marker on the recipient’s side, and only on the recipient’s side. By the same logic, the marker 23531 on the 2025 returns identifies an account on the exchange’s side, not the sender; who lies behind it is known to Zonda’s books, which are now in the hands of a bankruptcy trustee.
A Calculus of Probability: Why I Call It the Zonda Wallet
The ledger knows nothing of ownership. The protocol knows only which key can sign a transaction; “whose money is this” is not a question the blockchain answers. The books answer it, and the courts. The ledger knows control, the law knows ownership, and between the two stretches forensic analysis, which is a calculus of probability run on open data. Let us run it honestly.
Four models are consistent with the trace: an account belonging to the company itself; an account belonging to a person managing the company’s assets; a segregated account of a large client; and a market maker’s account. The last two fail four independent tests. For nearly a thousand days the wallet left not a single trace of contact with anyone but the exchange: no other exchange, no swap, no private address. A person’s money usually lives; this address behaved like a pocket. The 2025 top-ups were returned to within half an XRP; clients do not square balances, they hold or they sell. Three days after the exchange froze, the wallet tested an exit with a thousand XRP and then went dormant for four and a half months; a client who managed to withdraw the day before the catastrophe has his money safe and needs to test nothing, unless he knows that the origin of that money is going to be a problem. And the sequence of April 7: the exchange pushed ninety-seven per cent of freshly acquired liquidity through this address on the evening before the day it would close the door on everyone else.
Each of these tests can be explained away on its own. Together they form an asymmetry that no single counterargument reverses. The U.S. Treasury’s Office of Foreign Assets Control has sanctioned addresses on the strength of weaker behavioral clusters than this one. So I call this address the Zonda wallet, because that is what the exchange would have called it in its own books had those books been public, and I take responsibility for the name in a way a journalist must dilute into the conditional. But in naming it I say nothing about a person. Who holds the key, the ledger does not know, and neither do I.
One more thing about the person, because the point demands precision. The exchange’s account is configured with multi-signing and a disabled master key: to move money out of it, several signatures must be gathered, and that is exactly how the 2025 and 2026 transfers into the wallet under examination were signed. The Zonda wallet works differently. It is controlled by a single active master key, with no list of signers at all. A million XRP fed exclusively by an exchange and hanging on one key is individual control, not procedural control. Who personally held that key is the central question of the whole affair; and it is a question to which an answer exists, just not in the ledger.
And If It Was a Client? On Paying Some Creditors and Not Others
Honesty requires playing out to the end the variant most lenient to the exchange. Suppose, then, that the Zonda wallet belonged to a client of unusual discipline: a wealthy investor who kept XRP off the exchange and for two and a half years did nothing with it except shuttle it between his own address and his account at Zonda. Such profiles exist. They do not explain the zeroing-out of the 2025 top-ups to within half an XRP, or the test of April 11, but let us suppose those, too, have innocent explanations.
What remains is a question that this variant not only fails to remove but sharpens: why, on the evening of April 7, in the days when customers were publicly complaining of delayed withdrawals and the exchange already knew that it would close the door on everyone the next morning, did one man have a withdrawal of a hundred and thirty thousand XRP, about a hundred and eighty thousand dollars, executed in a quarter of an hour, out of liquidity brought in from outside specifically for the occasion? Thirty thousand customers held, that same evening, an identical claim to withdraw their own funds. One of them did, taking ninety-seven per cent of a sum that had just landed. The rest woke the next day to a balance on a screen.
Polish criminal law has a name for this. Article 302, paragraph 1, of the Penal Code (Kodeks karny) criminalizes the favoring of selected creditors: whoever, facing insolvency or bankruptcy and unable to satisfy all his creditors, pays or secures only some of them, to the detriment of the rest, is liable to up to two years’ imprisonment. Underlying the provision, as the commentary edited by Michał Królikowski and Robert Zawłocki reminds us, is a principle of civil law: a debtor may not arbitrarily privilege one creditor to the prejudice of the others. And the doctrine captures its rationale in a sentence that fits this case like a key in a lock: for the creditor who is not paid, it makes no material difference whether the dishonest debtor squandered the estate or handed it to other creditors of his own choosing (R. Zawłocki and M. Gałęski, in “Kodeks karny. Część szczególna. Tom III. Komentarz,” ed. M. Królikowski and R. Zawłocki, 5th ed., 2024, commentary to Art. 302). The elements are three: payment of some, a state of looming insolvency, and the resulting endangerment of the rest. The offender may be anyone who in fact manages the company’s financial affairs, which is how Article 308 of the Code operates; conditional intent suffices, meaning a willingness to accept that paying one endangers the others; and in practice the favoring of a single creditor is enough. The evening of April 7, read in the client variant, is a textbook illustration of the provision: an exchange in manifest distress, one withdrawal financed ad hoc, everyone else cut off by morning.
Add the civil layer. Insolvency law, including Estonia’s, under which the bankruptcy of BB Trade Estonia OÜ, the exchange’s operating company, is proceeding, provides mechanisms for clawing back payments made to selected creditors in the period before bankruptcy; the trustee may demand that such a payment be returned to the estate for distribution among all. The “client’s” money of April 7 is therefore not untouchable even in the gentlest reading, and its recipient becomes, to the trustee, a debtor of the estate rather than a creditor.
And finally, the question that the client variant cannot close, because it opens it: who was this client, and how did he know that April 7 was the last evening? The exchange knew him by his identity documents, because every account carried full verification, and the marker 23531 leads, in its books, to a name. If the defense wishes to argue that this was not the company’s wallet but a client’s, it must simultaneously explain why the company chose that client from among thirty thousand and paid him on the eve of the collapse. The client variant does not cleanse Zonda’s fortune of questions. It adds a charge.
Why Prosecutors Cannot Seize the Zonda Wallet with a Single Letter
Here one must disappoint everyone who asks why the authorities did not simply freeze the money. The XRP Ledger does have a built-in freezing mechanism, Freeze and Deep Freeze, but it applies only to tokens issued on the network by companies, stablecoins for instance. Native XRP cannot be frozen by anyone: not by the technology’s creators, not by a court, not by a government. This is not a loophole in the law but a deliberate design feature, the very one for which cryptocurrencies were invented. Whoever knows the private key controls the funds, and no document changes that.
The Zonda wallet has no custodian. There is no institution that keeps this account, and so there is no window to which one can deliver a seizure order. Two roads remain, and only two. The first is to obtain physical control of the key: through a search, the seizure of devices, the questioning of the person who has it. That is how the F.B.I. recovered, in 2021, most of the ransom paid by Colonial Pipeline, by coming into possession of the key to the address to which the extortionists had moved their bitcoin. The second is to wait until the money touches the regulated world, and to strike there. On August 22, for the first time since April, that second road genuinely opened: twenty-one thousand XRP landed in the omnibus account of an institution that knows every customer by name. The instruments exist and they are quick: a European Investigation Order under Directive 2014/41 for the data, and a certificate under Regulation 2018/1805 for the freeze, both enforceable in a fellow E.U. member state within days rather than months. The anonymity of this wallet is real, but it leaks at both ends: at the entrance, through the exchange’s books, and at the exit, through the marker at the recipient.
There is, however, something that no road settles on the authorities’ behalf: tempo. The institution that received the money has its own monitoring systems and its own obligations; it may hold the funds on its own initiative, but such a hold is short-lived and lapses unless a formal freezing order is placed beneath it. The clock in this case is ticking on the prosecutors’ side, not the blockchain’s.
Wallets That Woke After Years: What History Teaches
Nothing in this account is without precedent, and the precedents are consoling for the victims and unsettling for whoever holds the key. In August, 2016, nearly a hundred and twenty thousand bitcoin were stolen from the Bitfinex exchange. For five years they lay almost untouched; when they began to move, chain analysis led investigators to a married couple in New York, and in February, 2022, the Justice Department announced the seizure of 3.6 billion dollars, the largest in its history. Bitcoin stolen from the Silk Road marketplace in 2012 slept for nine years; its holder, James Zhong, was traced in 2021, and fifty thousand bitcoin passed into government custody. The creditors of Mt. Gox waited a decade for their first distributions, but the distributions came, because the failed exchange’s assets sat visibly in the ledger the whole time and no one could quietly consume them.
The moral is singular and, for Zonda’s fortune, fundamental: the blockchain does not forget, and time works for whoever has patience and tools. The holder of the key to the Zonda wallet can wait, but every attempt to cash out will leave a trace; every attempt will eventually touch an institution that knows its customer; and with every publication, the circle of such institutions willing to accept his money without an alarm grows smaller. In April, he tested Binance and did not follow through. In August, he chose an unmarked exit. Each time, the circle is tighter. It is a war of attrition in which the victims have the ledger on their side and he has only patience.
The Rules of Blockchain Forensics I Hold Myself To
Because this piece will also be read by people who would like to discredit it, let me set out the method, since the method matters more than the conclusions.
First, four levels of certainty, always labelled. A ledger fact is a transaction record, cryptographically signed, beyond dispute. A label is an explorer’s tag on an address; labels have a hierarchy of reliability, from domain verification through curated name registries and behavioral clustering to community submissions, and they sometimes diverge between services. An inference is an analytical conclusion drawn from facts. A hypothesis is an interpretation awaiting procedural verification. In this piece, “the exchange’s account” is a label of the highest grade, domain-verified and consistent across two independent services; “the Zonda wallet” is an inference of high strength; “who holds the key” is a hypothesis, and I treat it as one.
Second, a label tells you whose an address is; the ledger tells you what the address did. A label can be disputed; the ledger cannot. The Zonda wallet carries no label at all, it is an anonymous private address, and that is precisely why everything we know about it comes from the layer that cannot be disputed.
Third, falsifiability. Every claim in this piece is framed so that it can be overturned with a single screenshot if it is false. I submit to the test myself: in the May interview with Forbes, I said that every withdrawal from this wallet had gone back to Zonda, and that was already inaccurate on the day I said it, because three weeks earlier a thousand XRP had gone to Binance, which I had not caught. I correct it here, because a method that does not correct its own errors is not a method. Whoever asserts that the wallet is unconnected to the exchange, let him point to one material deposit from another source. Whoever asserts that it belonged to a client, let him point to one contact between this address and the world beyond the exchange in nearly a thousand days. Whoever asserts that the August 22 movement was authorized, let him say by whom.
Fourth, everything is checkable without intermediaries. Go to XRPScan or Bithomp, paste the address, and scroll through the history, forty-nine transactions in all: for every entry you will see the date to the second, the amount, the direction, and the address on the other side. No account, no permissions. The register is public, and that is the greatest strength of this case.
A footnote on method: since the wallet was first described publicly, new addresses have been tagging it with dust, including on days when nothing whatever happens on it. Ordinarily it is a tracker’s alert that wakes the press; here the press woke the trackers, because the wallet was too small for the threshold-based bots and too large, for the case, to remain unnoticed. The observatory grows to the rhythm of the case, not the rhythm of transactions.
Zonda’s Fortune Under One Key: Three Scenarios and a Single Procedural Step
The amount is a footnote; the movement is the thesis. Twenty-one thousand XRP, in a case worth three hundred and fifty million zlotys, is a rounding error. What matters is that someone reached for the key to Zonda’s fortune at the moment a court was forbidding the company to dispose of its assets, and its chief executive, according to his lawyers’ public statements, was placing that fortune at the prosecutors’ disposal. There are three possibilities, and none of them is neutral.
First: the movement was authorized, as part of coöperation with the authorities or with the consent of the interim trustee. Against this stands nearly everything visible in the ledger: a test transfer before the real amount, a marginal sum, an ordinary customer sub-account rather than an authority’s custodial account, a Saturday afternoon. A formal seizure does not look like this. But if it were so, a single sentence of confirmation would suffice, and no one has yet spoken it.
Second: the key is in the hands of the person declaring coöperation, who nonetheless disposes of funds without the authorities’ knowledge. Then August 22 is proof that the declared coöperation does not extend to full disclosure of assets, and it opens, alongside money laundering, a case of frustrating the satisfaction of creditors.
Third: someone else has the key. Then the defense’s declarations secure nothing where this wallet is concerned, and the “enormous fortune” of the public statements has a hole in it the size of a million XRP.
Between the second and the third, public data cannot decide. Two procedural steps, available to the authorities at once, can: a question to the party declaring coöperation, whether it executed or authorized the transfers of August 22; and the identity of the holder of sub-account 4227973493, from the operator that keeps it. A single procedural step separates the investigators from a name. The public has a right to ask whether it has been taken, and I will keep asking.
And if it turns out, after all, to have been a client, the story does not become innocent; it merely changes the addressee of the questions, and the statute, from money laundering to the favoring of a creditor under Article 302, discussed above.
What Now
The findings set out here have been delivered by my firm to the prosecutors, together with motions to freeze the funds in the recipient’s sub-account, to establish the account holder’s identity, and to place the wallet under live transaction monitoring. The proceedings, consolidated on July 30, run under case number 1001-109.Ds.77.2022, and the National Prosecutor’s Office declared on August 25 that securing as much of the assets as possible is a priority. The same day, the chief executive’s defense lawyer wrote publicly of an “enormous fortune” placed at the prosecutors’ disposal. The Zonda wallet is the simplest test of both declarations one could devise: one address, one key, one question.
Since Harju County Court in Tallinn declared BB Trade Estonia OÜ bankrupt on August 27, a two-month window for filing creditors’ claims has been running, and the first creditors’ meeting is set for September 17. Victims who want to know how to file a claim in Estonia and how it fits with the Polish investigation will find updates in our guide to the Zondacrypto case (in Polish); the broader picture of what remains of Zonda’s fortune is in last week’s inventory.
Thirty thousand people were harmed. They voted in every direction; they were robbed in exactly one. Their money has no political color. It has an address, a balance, and a key, and that is the only thing in this affair still worth arguing about.
Robert Nogacki is an attorney and the founding partner of Kancelaria Prawna Skarbiec, in Warsaw, and represents victims of the Zondacrypto collapse. All zloty amounts reflect XRP prices in late August, 2026, roughly five zlotys per token; dollar equivalents are approximate, at about 3.67 zlotys to the dollar. Every transaction identifier and address in this piece is a live link to the public ledger.

Robert Nogacki – licensed legal counsel (radca prawny, WA-9026), Founder of Kancelaria Prawna Skarbiec.
There are lawyers who practice law. And there are those who deal with problems for which the law has no ready answer. For over twenty years, Kancelaria Skarbiec has worked at the intersection of tax law, corporate structures, and the deeply human reluctance to give the state more than the state is owed. We advise entrepreneurs from over a dozen countries – from those on the Forbes list to those whose bank account was just seized by the tax authority and who do not know what to do tomorrow morning.
One of the most frequently cited experts on tax law in Polish media – he writes for Rzeczpospolita, Dziennik Gazeta Prawna, and Parkiet not because it looks good on a résumé, but because certain things cannot be explained in a court filing and someone needs to say them out loud. Author of AI Decoding Satoshi Nakamoto: Artificial Intelligence on the Trail of Bitcoin’s Creator. Co-author of the award-winning book Bezpieczeństwo współczesnej firmy (Security of a Modern Company).
Kancelaria Skarbiec holds top positions in the tax law firm rankings of Dziennik Gazeta Prawna. Four-time winner of the European Medal, recipient of the title International Tax Planning Law Firm of the Year in Poland.
He specializes in tax disputes with fiscal authorities, international tax planning, crypto-asset regulation, and asset protection. Since 2006, he has led the WGI case – one of the longest-running criminal proceedings in the history of the Polish financial market – because there are things you do not leave half-done, even if they take two decades. He believes the law is too serious to be treated only seriously – and that the best legal advice is the kind that ensures the client never has to stand before a court.