Summary: Leaked compliance records shatter anonymity of 291 crypto users by matching names directly to wallet activity

Published: 2 hours ago
Based on article from CryptoSlate

Pocket Bitcoin Breach: The Intersection of Identity and Blockchain Privacy

A recent data breach at the Swiss non-custodial service Pocket Bitcoin has revealed a more extensive exposure of sensitive user information than originally reported. While the incident affected a specific cohort of 291 customers, the nature of the leaked data highlights the significant privacy risks that emerge when real-world identities are linked to public blockchain activity. Although customer funds remain secure due to the service's non-custodial nature, the breach has prompted a deep dive into the vulnerabilities of support-system data storage.

Expanded Scope of Exposed Data

The initial disclosure by Pocket Bitcoin suggested the breach was limited to email addresses and support conversations. However, a follow-up forensic investigation revealed that correspondence with partner banks was also compromised. This data included varying combinations of names, postal addresses, identity-document copies, and source-of-funds records. Crucially, some of these records were linked to public Bitcoin addresses, effectively stripping away the layer of pseudonymity that usually separates a user's offline identity from their on-chain financial history.

Privacy Risks and Security Implications

The primary concern regarding this breach is the heightened risk of targeted phishing and social engineering. Because Bitcoin addresses are public, anyone with the address can view balances and transaction histories; when this is paired with a home address or a name, it creates a roadmap for potential attackers. Pocket Bitcoin emphasized that because they do not hold private keys, the attackers cannot move customer funds. Instead, the danger lies in the credibility of future scams, where bad actors might use specific transaction details or physical locations to pressure or deceive victims into voluntarily surrendering their assets.

Corporate Response and Remediation

In response to the incident, Pocket Bitcoin has successfully closed the vulnerability and completed its forensic review of the affected support systems. The company has reported the breach to the Swiss Federal Data Protection and Information Commissioner and filed a formal police report to aid in further investigation. Each of the 291 affected individuals has received a personalized notice outlining the specific data points that were leaked in their case. While the company currently sees no evidence of the information being misused, they have advised users to remain vigilant against increasingly sophisticated communication that may reference the stolen data.

Cookies Policy - Privacy Policy - Terms of Use - © 2025 Altfins, j. s. a.