Polish Prosecutors Charge Fifth Suspect in Zondacrypto Probe
Polish prosecutors have formally charged a fifth person in their criminal investigation into Zondacrypto, one of Poland's best-known crypto exchanges. The case now involves estimated losses of at least PLN 350 million, roughly $94 million, making it one of the largest crypto-fraud investigations in Central European history. For accounting firms, auditors, and CFOs with exposure to Polish or EU crypto clients, this development is not background noise: it illustrates exactly the kind of systemic record-manipulation risk that robust crypto accounting software and internal controls are designed to detect before prosecutors arrive.
What Prosecutors Have Alleged
The fifth suspect, identified publicly only as Roman Ż. under Polish privacy conventions, was detained on 5 September 2026. Prosecutors in Katowice announced the charges the following Monday, 8 September. He faces two counts: participation in an organised criminal group, and misappropriation of approximately PLN 7.8 million (around $2.1 million) belonging to exchange users.
The Alleged Manipulation of Records
The core technical allegation is striking from an accounting-controls perspective. Prosecutors claim the group changed, deleted, and added computer records without authorisation in order to generate financial benefits. In plain terms, the alleged fraud was not simply a question of moving money: it involved the deliberate falsification of the underlying data layer that any bookkeeping or audit process would rely on. That allegation has direct implications for how firms should think about data integrity in the systems they use to serve crypto clients.
Roman Ż. has denied the charges and provided his own account to prosecutors. The prosecutor's office has applied to the Katowice Wschód District Court for pre-trial detention, citing the severity of the potential sentence, a risk of evidence tampering, and the possibility of flight. The offences as charged carry a maximum custodial sentence of ten years.
Where This Investigation Stands
Roman Ż. is the fifth person publicly named as a charged suspect. Polish prosecutors had already moved against four others: charges were filed against a further group in late August 2026, followed by additional arrests on 2 September. The investigation is active and, by prosecutors' own admission, may not yet have reached its full scope.
Scale of Estimated Losses
The PLN 350 million figure ($94 million at current exchange rates) represents the prosecutors' current estimate. Authorities noted earlier in the year that the total could rise as more alleged victims submit formal complaints, and that the number of complaints already filed is significant. In other words, the financial perimeter of this case is still being drawn.
That open-ended estimate matters for firms with any client exposure to Zondacrypto: the pool of claimants, and therefore the pool of potentially disputed transactions, has not been finalised. Any client who traded on the exchange during the period under investigation may need to revisit their own records.
Accounting and Audit Implications for Firms
Cases of this type create several distinct challenges for accounting firms and auditors working with crypto clients in Poland and across the EU.
Reconstructing Transaction History
When exchange records have allegedly been altered, the burden of reconstructing a client's true position falls on external data: blockchain transaction histories, wallet addresses, third-party exchange confirmations, and any off-chain documentation the client holds. Firms that have been relying solely on data exports from the exchange itself now face a verification problem. This is precisely where digital asset accounting software with independent on-chain data ingestion becomes operationally critical, not just a convenience.
Auditors should treat any client data sourced entirely from a single exchange API as potentially unverified, especially where that exchange is subject to ongoing criminal proceedings. Corroboration from a second source, whether a blockchain explorer, a custodian statement, or a bank record of fiat flows, is the minimum defensible standard in a contested environment.
Client Disclosure and Financial Statements
For clients who held assets on Zondacrypto, the accounting treatment depends on whether those assets are recoverable. Under IFRS 9 and IAS 37, an asset that is subject to a criminal freeze or whose recovery is genuinely uncertain may need to be impaired or disclosed as a contingent asset. Firms should not allow clients to carry Zondacrypto balances at face value in financial statements without a proper assessment of recoverability.
Where a client suffered an actual loss, the recognition question turns on when that loss became probable and measurable. If the manipulation was ongoing for an extended period, the loss crystallisation date may be earlier than the arrest dates, which has implications for the relevant reporting period and any need to restate prior-period accounts.
AML and Suspicious Activity Reporting
Accounting firms in Poland operating under the AML Act (Ustawa o przeciwdziałaniu praniu pieniędzy) are obligated reporting institutions. Where a client's exposure to Zondacrypto raises a suspicion of proceeds of crime, the obligation to file a suspicious transaction report with the General Inspector of Financial Information (GIIF) is triggered independently of whether that client is a named suspect. The fact that an investigation is already public does not remove the reporting obligation: it may in fact crystallise it.
Firms should also document their own risk assessments for any Zondacrypto-related client relationships. Regulators conducting supervisory reviews will look for evidence that firms identified the risk and took proportionate steps, rather than simply waited for prosecutors to act.
For a broader view of how organised crypto fraud schemes stress-test AML workflows at accounting firms, see what large-scale crypto fraud schemes mean for AML controls and accounting workflows.
The Regulatory Backdrop in Poland
The Zondacrypto investigation has already had a material effect on the Polish regulatory environment. The Polish Sejm's decision to uphold the presidential veto on a domestic crypto licensing bill was shaped, at least in part, by the political fallout from this case. Poland remains in the process of transposing MiCA into national law, and the KNF (Polish Financial Supervision Authority) has been under pressure to tighten its oversight of virtual asset service providers. For a full account of how the regulatory picture shifted, see how the wider Polish crypto regulatory picture shifted after the Zondacrypto scandal.
MiCA Readiness and Third-Country Exposure
Under the Markets in Crypto-Assets Regulation, exchanges operating within the EU must maintain robust governance, segregate client assets, and keep auditable records. The allegations in the Zondacrypto case, if proven, would constitute failures across multiple MiCA compliance pillars simultaneously. Firms advising clients on MiCA readiness should use this case as a live stress test: the specific controls that allegedly failed here (data integrity, authorisation controls over record amendments, client asset segregation) are exactly the controls MiCA Article 70 and related provisions require to be demonstrably effective.
For accounting firms operating crypto bookkeeping software, this is also a prompt to review whether their own platforms maintain an immutable audit trail for any data amendments. Any system that allows records to be changed without a logged, timestamped, and authorised audit entry carries an inherent risk that mirrors, at a smaller scale, what prosecutors are alleging in this case.
Practical Steps for Accounting Firms Right Now
The investigation is active and the loss estimate is still moving. Waiting for a final court outcome before acting is not a defensible position for firms with affected clients. The following steps are proportionate to the current stage of proceedings.
Client Exposure Review
Firms should identify all clients who used Zondacrypto as a trading or custody venue during the period under investigation. For each, they should obtain independent verification of balances, either from on-chain records or from any fiat withdrawal confirmations held by the client's bank. Where balances cannot be independently verified, that fact should be documented and communicated to the client in writing.
Financial Statement Review
Any Zondacrypto-related asset carried on a client's balance sheet should be subject to an impairment review. The appropriate accounting treatment will depend on the specific facts, but the default assumption of full recoverability is no longer supportable given the scale of the alleged fraud and the number of suspects charged. Directors of affected companies should be advised of their disclosure obligations under applicable accounting standards.
Internal Controls Assessment
Firms should assess their own digital asset accounting software and data workflows for equivalent vulnerabilities. Specifically: can any user amend a historical transaction record without that change being logged and flagged? If the answer is yes or unclear, the system's audit trail does not meet the standard that regulators and courts will apply when scrutinising records in an enforcement context.
Frequently Asked Questions
Does the Zondacrypto investigation affect clients who only held small balances on the exchange?
Potentially yes. The estimated loss pool is still growing as victim complaints are received. Any client with a Zondacrypto balance during the relevant period should have their position independently verified, regardless of size, because the exchange's own records are subject to an allegation of unauthorised manipulation.
What accounting treatment applies to assets held on an exchange under criminal investigation?
Under IFRS, assets whose recovery is uncertain must be assessed for impairment. If recovery is no longer probable, the asset should be written down or derecognised with appropriate disclosure. Where recovery remains possible but is not certain, the asset may qualify as a contingent asset, which is disclosed but not recognised on the balance sheet. The specific treatment depends on the facts of each client's situation and the advice of the reporting firm's technical team.
Are accounting firms in Poland required to file suspicious transaction reports in connection with this case?
Polish accounting firms are obligated entities under the AML Act. Where a client relationship gives rise to a suspicion of proceeds of crime, the obligation to report to the GIIF exists independently of whether a public investigation is already under way. Firms should take legal advice on their specific obligations and document their risk assessments thoroughly.
How does MiCA change the compliance landscape for exchanges like Zondacrypto going forward?
MiCA imposes mandatory requirements on crypto-asset service providers operating in the EU, including governance standards, client asset segregation, and auditable record-keeping. The specific control failures alleged in this case, if proven, would constitute breaches of multiple MiCA provisions. MiCA authorisation does not eliminate fraud risk, but it does create a clearer legal framework under which regulators can act and firms can assess the adequacy of an exchange's controls before placing client assets there.
What should firms do if a client's Zondacrypto records are needed for a tax filing?
Where exchange-sourced records cannot be independently verified, firms should seek corroborating evidence from the blockchain itself, from the client's bank statements showing fiat flows, or from any custodian records held separately. If records remain unverifiable, this should be disclosed clearly in the tax filing with an explanation of the limitation. Filing on the basis of unverified records from an exchange under criminal investigation for record manipulation carries significant professional and legal risk.
Source: The Block
