Stealing from the seizure wallet: how the NCA and CPS followed 50 Bitcoin through Bitcoin Fog

A former National Crime Agency officer stole 50 Bitcoin from cryptocurrency seized during a dark-web investigation. The coins were moved through Bitcoin Fog, a mixing service intended to make the trail harder to follow. Investigators later connected the transfers to devices, account records and card spending. Paul Chowles pleaded guilty and was sentenced to five and a half years at Liverpool Crown Court in July 2025.[1]

This case is useful because it shows what blockchain tracing can and cannot do. The ledger supplied a record of movements between addresses. The prosecution still needed evidence outside the chain to link those movements to a person and to spending.

The missing Bitcoin came from an NCA seizure

The underlying investigation concerned Thomas White, who had operated Silk Road 2.0. White was jailed for 64 months in April 2019 after the investigation, which involved the NCA and the FBI.[1]

The NCA had seized 97 Bitcoin from White’s devices. Between 6 and 7 May 2017, 50 Bitcoin left a wallet described by the CPS as White’s “retirement wallet” in two transactions. The coins went first to a public address, then were divided into smaller amounts and sent through Bitcoin Fog before moving to other public addresses.[1]

The remaining 47 Bitcoin were later sold to help meet a confiscation order against White. The CPS says those coins helped satisfy part of an order for £1,560,506, leaving £1,066,956 outstanding.[1]

At first, investigators assumed White might have accessed the wallet. He had the technical knowledge, and the missing coins were eventually written off as untraceable. White later said that someone inside the NCA must have taken them because NCA staff were the people with the private keys. That information changed the direction of the investigation.[1]

What Bitcoin Fog changed, and what it did not

A mixer takes deposits from different users and returns funds through a process intended to make the relationship between the original and later transactions harder to see. In this case, the CPS describes Bitcoin Fog as a cryptocurrency mixer used by criminals seeking to hide illicit proceeds.[1]

That did not erase the public ledger. It changed the shape of the investigation. The 50 Bitcoin no longer appeared as one simple transfer from the seized wallet to a spending account. Investigators had to examine the movements, follow the value through smaller transfers and compare that activity with evidence held elsewhere.

The distinction matters. A transaction record can show that value moved between addresses. It does not, on its own, show the name of the person controlling an address or prove why the transfer happened. The case was not solved by a public address alone.

The off-chain evidence closed the gap

Merseyside Police launched an investigation after officers learned about the missing Bitcoin. When Chowles was arrested in May 2022, police recovered an iPhone that linked him to an account used to transfer Bitcoin. They also found browser-search history connected to a cryptocurrency exchange service and notebooks in his office containing usernames, passwords and statements relating to White’s cryptocurrency accounts.[1]

The spending trail provided another set of records. The CPS says Chowles used a Cryptopay debit card for 279 transactions totalling £23,309 between 26 August 2021 and 20 May 2022. It also reported £79,884.77 in spending through a Wirex account and debit card.[1]

The CPS calculated Chowles’s financial benefit at £613,147.29. He pleaded guilty to theft, transferring criminal property and concealing criminal property at Liverpool Crown Court on 23 May 2025. The court sentenced him on 16 July 2025, and the CPS said confiscation proceedings would follow.[1]

The figures show the pattern investigators were trying to establish: the on-chain movement, access to the relevant credentials, devices and records, and later use of financial services. No single item had to answer every question.

How a tracing case is built

The public material does not name a particular chain-analytics supplier as the tool that solved the Chowles case. It does, however, describe the types of evidence that can be combined.

1. Start with a known transaction

The investigators knew the seized wallet, the approximate amount and the dates on which 50 Bitcoin left it. Those details gave them a defined starting point rather than a search across the whole Bitcoin network.[1]

A Bitcoin transaction identifier, often called a TXID, can point to a transaction and its inputs and outputs. The wider transaction history can show where value moved next, subject to the limits of the records and the interpretations applied to them. It still does not provide a person’s name by itself.[6]

2. Follow the movement, including the obfuscation step

The coins were split and routed through Bitcoin Fog. That made the path less direct, but it did not turn the activity into a private off-chain event. Investigators could continue examining the ledger and compare patterns with other evidence.[1]

The NCA has made the same general point in its public work on cryptoasset abuse: transactions leave a trace, and UK agencies use cooperation between law enforcement, regulators and private-sector partners to follow those traces.[3]

3. Identify the person with separate records

An address is not a legal identity. In this case, the alleged link to Chowles came from the wider investigation: an iPhone, account information, browser history, office notebooks and the circumstances of his access to the seized assets.[1]

The NCA’s 2026 assessment also describes cryptoasset investigations in the context of wider money-laundering networks, sanctions evasion and professional or technological enablers. Its language is an assessment of threats, not a finding about the Chowles case, so the two should not be blended.[5]

4. Trace the money into ordinary services

The Cryptopay and Wirex spending records gave the prosecution an off-chain view of what happened after the Bitcoin moved. Card transactions have dates, amounts and account relationships that can be compared with the blockchain record and with evidence from devices or witnesses.[1]

That combination is the important lesson. The blockchain supplied a sequence of transactions; other records supplied context and attribution.

Operation Atlantic shows the same model at a larger scale

In April 2026, the NCA described Operation Atlantic, an international operation focused on cryptocurrency fraud and so-called approval phishing. The operation identified more than 20,000 victims across the UK, Canada and the United States and secured and froze more than $12 million in suspected criminal proceeds.[2]

The NCA said private-sector organisations helped trace illicit transactions and identify victims, while law-enforcement agencies shared intelligence and conducted outreach. Operation Atlantic was not the Chowles investigation, and it does not prove anything about his case. It is a separate example of how public authorities and private partners can combine ledger data with intelligence about victims, accounts and suspected criminal proceeds.[2]

The Home Office Fraud Strategy 2026–2029 sets out the same public-private direction. It says the Government will improve cooperation between agencies, regulators, law enforcement, industry and non-profit organisations, and it identifies cryptoasset technologies among the financial flows that can be exploited by criminals.[4]

What this case does not prove

The Chowles case does not mean that every Bitcoin transaction can be tied to a named person. It does not mean that passing funds through a mixer automatically proves criminality. It does not show that a transaction history alone settles ownership, intent or the lawful source of funds.

It does show something narrower and more useful: when investigators begin with a known wallet and transaction, they can examine the subsequent movement of value and test that record against devices, account data and spending. The public ledger is one evidential layer, not the whole case.

For a basic explanation of hashes, transaction identifiers and their limits, see What Is a Hash in Blockchain?. The site’s crypto wallet guide explains why control of a private key is different from a person’s identity. Its blockchain consensus explainer covers the protocol rules that determine which transactions are accepted. For the privacy implications of public addresses, read Is Blockchain Private?.

This is a factual case report and general educational information, not legal, investigative or financial advice.

Sources

[1] https://cps.gov.uk/cps/news/ex-nca-officer-jailed-theft-50-bitcoin-now-worth-ps44m-during-investigation-crime-dark-web — CPS: Ex-NCA officer jailed for theft of 50 Bitcoin
[2] https://nationalcrimeagency.gov.uk/news/fraudsters-targeting-cryptocurrency-stopped-and-12-million-frozen-in-nca-led-operation-atlantic — NCA: Operation Atlantic
[3] https://www.nationalcrimeagency.gov.uk/news/ofsi-and-partners-clamp-down-on-the-abuse-of-cryptoassets — NCA: OFSI and partners clamp down on cryptoasset abuse
[4] https://assets.publishing.service.gov.uk/media/69ae77ddc78869bf8eb8a509/fraud-strategy-web.pdf — Home Office: Fraud Strategy 2026-2029
[5] https://nationalcrimeagency.gov.uk/nsa-domains-2026/nsa-soc-finance-2026 — NCA: National Strategic Assessment 2026, SOC finance
[6] https://thecoinexpert.co.uk/blog/what-is-a-hash-in-blockchain — TheCoinExpert: What Is a Hash in Blockchain?

Leave a comment