One-line brief

CZ's Bitcoin Asia remarks focused public attention on a possible $1 million Bitcoin, but the harder question is what happens after capital enters the market. This article uses his discussion of institutional adoption, tokenized assets, AI payments and Hong Kong to examine why “on-chain traceable” does not mean “recoverable.” It proposes a five-layer, verifiable digital-asset security infrastructure covering prevention, attribution, cooperation, evidence and responsibility.

1. The loudest number at the Hong Kong conference was $1 million; the important issue was not price

At Hong Kong's Bitcoin Asia conference, CZ's most widely repeated line was that Bitcoin could reach $1 million soon, and the event promoted that forecast. Reading the conversation only as “CZ is bullish and Hong Kong welcomes Web3” misses the more consequential structure.

CZ's underlying judgment points to four changes: Bitcoin is moving from personal holdings toward institutions and national reserves; more traditional assets are moving on-chain through stablecoins, RWAs and tokenized shares; AI agents may first use stablecoins for automated transactions and then Bitcoin and other assets; and national competition is shifting from whether crypto is accepted to whether regulation and financial infrastructure are actually implemented.

The public conversation also moved from price to structure: institutional adoption and global capital flows, authorization, budgets and settlement for AI agents, and Hong Kong's combination of policy, capital, AI and talent as a digital-asset gateway.

Price is the easiest surface to distribute, but it hides a harder fact: as asset scale increases, the absolute scale of theft and disputes increases too. The conference celebrated capital entry without fully answering what happens when capital is lost.

2. The ignored half: as assets move on-chain, risk is institutionalized and amplified

If the main narrative is how capital enters, the ignored half is what losses follow. Chainalysis estimated that about $3.4 billion in crypto was stolen in 2025, including roughly $2 billion attributed to North Korea-linked hackers, compared with about $2.2 billion stolen from platforms in 2024. The February 2025 Bybit theft of about $1.5 billion (roughly 401,346 ETH) was the largest digital-asset theft on record and was attributed by the FBI to the TraderTraitor operation.

Personal wallets became a high-frequency surface: theft from personal wallets represented about 44% of stolen value in 2024, then about 20% or $713 million in 2025, while incident count rose to roughly 158,000. Attackers were moving toward more victims and smaller losses. Physical coercion, sometimes called wrench attacks, also rises with asset prices.

The symmetry is uncomfortable: higher prices and wider adoption increase the absolute scale of theft and fraud. National reserves, institutional custody, tokenization and AI trading can multiply exposure through exchange or custodian cold-wallet compromise, key-management failure, bridge exploitation, stablecoin/RWA freeze disputes, AI-agent overreach and cross-chain laundering. Public examples include the $230 million WazirX multisig theft, the $305 million DMM Bitcoin loss and the $455 million Ronin bridge theft.

That is where Delta's framing differs from the conference's dominant narrative. The mainstream story describes the entry point; it has not fully answered security and accountability after entry.

3. Three questions the conference has not answered after capital enters

After an asset is stolen, who traces it and how far? On-chain transactions are visible, but address attribution, cross-chain continuation, exchange cooperation and judicial materials do not happen automatically.

When a platform or custodian fails, how is responsibility divided? Internal-control failure, an erroneous risk block and a freeze dispute require rules about who bears the consequence.

When an AI agent loses control of automated trading, is the user, model, developer or platform responsible? These three questions are the core of this article.

4. Why “on-chain traceable” does not equal “recoverable”

CZ is right that Bitcoin transactions are easy to trace and therefore do not sit outside regulation. But the statement is only half the story. Blockchain can show whether a transaction occurred and which addresses exchanged value; it does not automatically establish who owns the funds, who is responsible, who can freeze them or how recovery will be executed. The gap between visibility and recovery is an execution chain that often breaks.

4.1 Entity attribution: from an anonymous address to a real actor

The chain shows an address, not a person. Evidence becomes actionable only when an address is associated with a real individual, platform or exchange through clustering, behavioral analysis and external intelligence. Without attribution, cooperation requests have no subject.

4.2 Chain-hopping: regulatory fragmentation is exploited systematically

After Bybit was stolen, funds were split across thousands of addresses and multiple chains, then converted through DEXs and bridges. Elliptic reported that about 33% of cross-chain investigations in 2025 crossed three or more blockchains. Each additional chain adds another break point.

4.3 Mixers: breaking the input-output link

Stolen funds are often sent to mixers. Tornado Cash has processed more than $7 billion since 2019 and was sanctioned by OFAC in 2022; North Korea-linked hackers used it to launder more than $455 million stolen from Ronin. After mixing, the funds remain visible but are much harder to attribute.

4.4 Endpoints: only identity-gated rails can usually freeze funds

Practical freezing and cooperation usually become possible when proceeds reach a centralized exchange, a stablecoin issuer or another identity-gated endpoint. In the Bybit case, about $335 million had been laundered within days and about $900 million remained under tracing. Across more than 28 exchanges and custodians, only about $78.9 million had been frozen or recovered in related proceedings—very little compared with the $1.5 billion loss.

4.5 Multi-jurisdiction execution: evidence must be accepted by platforms and courts

Even complete tracing, attribution and freezing still require a police report, judicial process and cross-border cooperation to turn on-chain facts into legal action. Evidence standards, jurisdiction and willingness to cooperate make this the slowest and least certain link.

The conclusion is direct: between technical visibility and practical recovery stand attribution, cross-chain continuation, anti-mixing analysis, endpoint identification, compliance-grade evidence and multi-jurisdiction execution. Break any link and recovery may stop. Preventive protection is therefore more certain than post-incident pursuit, and no one can honestly guarantee recovery.

5. Delta's view: the industry needs verifiable asset-security infrastructure

Once Bitcoin becomes a global capital asset, the scarce capability is no longer merely an entry channel. It is infrastructure that proves fund paths, identifies responsibility, coordinates freezes and supports recovery. Delta divides it into five layers:

Prevention: key and multisig governance, signature visualization, authorization and budget controls. Can accidents be reduced and contained immediately?

Attribution: address clusters, entity labels and cross-chain identification. Where did the money go and who may control it?

Cooperation: exchange assistance, stablecoin freezes and cross-border channels. Who can intercept the proceeds at an endpoint?

Evidence: a compliance-grade timeline and a report accepted by a platform or court. Can on-chain facts become legal action?

Responsibility: rules dividing liability among custodian, platform, user and model. Who is accountable after an incident?

5.1 Prevention: the signature interface is itself an attack surface

In July 2024, about $230 million was stolen from a six-of-signers WazirX multisig wallet. The custody interface displayed something different from the transaction that executed. Signers thought they approved a normal transfer, but a delegatecall replaced the multisig implementation with a malicious contract. Multisig alone is not security; the gap between “what you signed” and “what you thought you signed” is the attack surface. Prevention must include what-you-see-is-what-you-sign visualization, pre-change contract-logic checks and an independent second review.

5.2 Cooperation: Hong Kong's edge is whether it can handle incidents

CZ argued that a framework is not enough: licenses must be approved, bank accounts usable and businesses able to operate. The same logic applies to security. A financial center's digital-asset competitiveness depends on whether it can form evidence, assign responsibility and coordinate treatment after theft, fraud, freezes or custody disputes.

Hong Kong's VASP licensing and stablecoin framework solve how capital enters compliantly. Adoption remains incomplete without on-chain forensics, exchange cooperation, issuer-freeze channels and dispute resolution. A complete digital-asset center needs both entry (license and capital) and exit (security and dispute resolution).

5.3 Responsibility: an AI agent may pay, but must not control unlimited assets

Conference side events already pointed to AI-agent authorization, budgets and settlement. If human signers can fail when a display differs from a real transaction, an automatically signing, high-frequency agent can scale losses at machine speed when its boundary is missing.

Default controls should include per-transaction and cumulative budgets, address allowlists, high-risk-contract blocking, anomaly-frequency detection, secondary confirmation for large transfers, revocable authorization, complete decision and signature logs, and a post-incident tracing interface. “Can an agent pay?” is only the first phase; “who is responsible when it pays incorrectly?” is the commercial phase.

5.4 Cooperation in practice: stablecoins have different freeze rules

Tokenized stocks lower the barrier to U.S. assets but do not automatically lower legal, custody or fraud risk. Stablecoin freezing shows how uneven cooperation can be. Tether is comparatively active, with about 9,600 addresses frozen and a cumulative scale in the billions; it cooperated with OFAC and U.S. agencies to freeze more than $344 million in one April 2026 action. Circle is more conservative: its CEO said it generally does not freeze without a court order, and public figures for 2023–2025 were about 372 addresses and $109 million.

Whether a stolen token can be frozen, and whether a freeze harms a legitimate holder, depends on issuer policy rather than the blockchain. RWA competition is therefore not just about issuing quickly; it is about mapping assets, responsibility and evidence correctly.

5.5 Narrative: national reserves are not a reason for retail leverage

CZ discussed long-term, market-based national-reserve allocation, not retail investors chasing a $1 million forecast or using leverage. Separate national-reserve logic, institutional-custody logic and retail trading logic. A state discussing Bitcoin reserves does not mean a retail trader should pre-position with high leverage. Institutional recognition is not a promise that the price cannot fall. Quantum-computing risk discussed at the event reinforces the same point: long-term value narratives require matching security and risk mechanisms.

6. Recovery is neither magic nor hopeless: three real outcomes

Public cases are highly differentiated. In the exceptional Poly Network 2021 case, about $610 million was stolen but most was returned because funds were hard to liquidate, exchanges cooperated and Tether froze about $33 million USDT. In the more common partial-freeze and long-tracing outcome, the Bybit case produced only about $78.9 million frozen or recovered across more than 28 institutions. A few victims have recovered a high dollar percentage because investigators found part of the funds and the asset price rose, but that is luck, not a reproducible service.

Recovery depends on traceability, an identity-gated endpoint, platform and judicial cooperation, and the degree of cross-chain or mixer use. This again makes prevention more certain than pursuit.

7. What Hong Kong should compete for next

Hong Kong should compete for a fuller standard: capital can enter, assets can be understood, incidents can be handled and responsibility can be pursued. Licenses and capital solve the entry; security and dispute resolution solve the exit. As stablecoins, RWAs, institutional custody and AI payments land locally, the moat will be whether the five-layer security infrastructure becomes default financial infrastructure.

8. Closing

Bitcoin reaching $1 million may be a question of time, but a higher price does not create a mature financial system if theft, fraud, custody, freezes and AI overreach remain unsolved. Annual theft of $3.4 billion, a $1.5 billion single case and an immediate-freeze rate below 5% are the questions behind the price celebration.

Hong Kong should aim not only to be Asia's crypto trading center, but also a center for digital-asset security, compliance and dispute resolution. The past decade moved assets onto chains; the next must show how to prove, trace, freeze and recover them after something goes wrong.

Key concepts

RWA: Traditional assets such as stocks, bonds and property mapped on-chain as tokens. This lowers access barriers but also brings issuance, custody and legal rights onto the chain.

AI-agent payments: On-chain payments initiated and settled autonomously by AI. The core risk is authorization and asset control, not merely the ability to pay.

Entity attribution: Associating an anonymous on-chain address with a real person, platform or exchange; a prerequisite for cooperation and recovery.

Chain-hopping: Repeated conversion across chains and DEXs to break tracing. About one third of cross-chain investigations in 2025 crossed three or more blockchains.

Mixer: A tool that mixes transactions to break input-output links, such as sanctioned Tornado Cash. Funds remain visible after mixing but are harder to attribute.

KYT: Transaction-level anti-money-laundering controls that underpin recovery cooperation.

Verifiable asset-security infrastructure: A five-layer capability spanning prevention, attribution, cooperation, evidence and responsibility, not a single tool.

Frequently asked questions

Q: If blockchain transactions are traceable, will stolen funds definitely be recovered?
A: No. Traceability only establishes that a transaction occurred. Recovery also requires attribution, an identity-gated endpoint, cross-chain and mixer analysis, platform cooperation and a judicial process. In the Bybit case, about $78.9 million was frozen or recovered against a $1.5 billion loss.

Q: Why can some stablecoins be frozen while others cannot?
A: Freezing depends on issuer policy, not the blockchain alone. Tether is relatively proactive; Circle generally requires a court order. Different tokens offer different post-incident cooperation space.

Q: Who is responsible when an AI agent makes a bad trade?
A: There is no universal answer. It may involve the user, model, developer and platform. Budgets, allowlists, revocable authority and complete logs are prerequisites for allocating responsibility.

Q: What does Hong Kong most need to add as a digital-asset center?
A: Incident-response capacity: on-chain forensics, responsibility allocation, exchange and issuer freeze cooperation and dispute resolution, in addition to licenses and capital.

Q: Can stolen assets be recovered?
A: It depends on traceability, identity-gated endpoints, cross-chain or mixer use, and platform and judicial cooperation. Prevention is far more reliable than any guarantee of recovery.

Content support

This article was supported by Delta & Capital's blockchain-security and compliance research team, based in Hong Kong. Its work covers account restrictions, risk-control and freeze appeals, stolen-asset tracing, blockchain data analysis, transaction forensics, KYT/AML controls, SOW reconstruction and cross-chain, multi-asset path analysis. The team also prepares evidence and technical support for police reports and judicial cooperation. This is public-interest education and does not promise recovery or unfreezing.

Risk and compliance notice

This article is security and anti-fraud education, not investment advice or a recovery guarantee. Data comes from public reporting and may change as investigations develop. Victims should report theft or fraud promptly to police and pursue lawful remedies, while remaining alert to secondary scams.