Public reporting on October 6, 2019 brought a significant custody failure at Algo Capital into broader view: attackers had obtained control of cryptocurrency wallets administered by the Algorand-focused investment firm’s chief technology officer, Pablo Yabo.
The event-day account placed the loss between $1 million and $2 million in Tether’s USDT stablecoin and Algorand’s ALGO token. It attributed the compromise to an attack on Yabo’s mobile phone and said Algo Capital had informed limited partners, accepted responsibility for the loss and planned to reimburse the affected amount. The surviving October 6 record did not provide wallet addresses, a transaction-by-transaction accounting or a completed forensic explanation.
What was known on October 6
CoinDesk initially reported the breach on October 5, citing an email from Algo Capital chief executive David Garcia and a source familiar with the matter. Cointelegraph and Messari carried the development on October 6, making that date the point at which the incident circulated more broadly across the cryptocurrency market.
Garcia confirmed to CoinDesk that a security breach had occurred and that the Algo Capital VC Fund’s limited partners had been notified. Contemporaneous reporting said Yabo had resigned, most of the firm’s assets remained in uncompromised cold storage and the Algorand blockchain itself had not been affected.
Those distinctions mattered. Algo Capital invested in companies building within the Algorand ecosystem, but it was legally and operationally separate from Algorand Inc. and the Algorand Foundation. The incident therefore did not demonstrate a failure of Algorand’s consensus protocol or ledger. It exposed weaknesses in the investment firm’s custody and recovery procedures.
A May 31, 2019 Form D filed with the U.S. Securities and Exchange Commission identifies Algo Capital GP LLC as a Delaware limited liability company offering pooled investment fund interests. In August, the firm announced that its Algo VC Fund had closed with $200 million in commitments, twice its original target. The size and ecosystem role of that fund made the breach institutionally important even though the reported loss represented only a fraction of the announced commitments.
A custody problem disguised as cold storage
The October 6 descriptions referred to an Algo hot wallet controlled through Yabo’s compromised phone. At that stage, however, the public record did not explain whether private keys, recovery phrases, cloud accounts or another authentication mechanism had been exposed. Calling the incident a phone compromise described the access path alleged by the firm, not a completed forensic finding.
The episode illustrated a basic limitation of custody labels. Assets described internally as being in cold storage can become remotely accessible if recovery material is exposed through a connected device. Organizational controls around backups, seed phrases and administrator privileges are therefore as important as whether the wallet application itself is ordinarily online.
The reported reimbursement commitment also reduced the expected loss to limited partners without reversing the theft. On October 6 there was no public evidence establishing that stolen assets had been recovered, that an attacker had been identified or that the proposed reimbursement had been completed.
Later clarification
On October 15, Algo Capital published a first-party incident report that refined the preliminary account. The firm said the wallets were compromised on September 26 and fixed the total theft at $1.9 million. Of that amount, it attributed $1.5 million to wallets owned by its sponsored venture fund and the balance to other Algo Capital wallets and Yabo’s personal wallet.
The report said an attacker accessed recovery-seed backup data through a remote attack on Yabo’s phone, turning wallets intended as cold storage into remotely spendable wallets. It also said the affected assets included ALGO, USDT and personally held bitcoin. These details are later context, not information that should be treated as fully established in the October 6 event-day account.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

