Blockchain investigator ZachXBT has alleged that two U.S. cryptocurrency retirement investment platforms, BitcoinIRA and iTrustCapital, suffered separate data breaches in 2026 without publicly disclosing the incidents. In a post on Monday, he said he had reviewed evidence indicating databases linked to both companies were compromised, potentially exposing personal details, portfolio holdings, banking information, custodian information and account verification status.
Neither company had confirmed a breach at the time of reporting. ZachXBT said he contacted both platforms on Aug. 21 but had not received a response. The allegations have not been independently verified, and the investigator did not specify how many customers may have been affected, when the alleged breaches occurred, or how attackers obtained access to the information.
According to ZachXBT, the immediate risk is not necessarily that assets held by platform custodians were stolen. Instead, leaked customer information could be used to make phishing emails and fraudulent support calls more convincing. He pointed to a June case involving a BitcoinIRA customer who allegedly received a spoofed BitcoinIRA email before losing more than $1.2 million in Bitcoin and Ether from a Trezor hardware wallet. ZachXBT says the attacker used information from the database to target the victim. The funds were reportedly not stolen from BitcoinIRA's own custody infrastructure.
BitcoinIRA, founded in 2016, serves more than 200,000 Americans and supports more than 100 cryptocurrencies. It does not directly custody retirement assets; the company lists Digital Trust as custodian and says digital assets are stored using BitGo multi-signature infrastructure. iTrustCapital describes itself as a software platform rather than an exchange, broker-dealer or custodian. It uses Fortis Bank as the qualified custodian for IRA accounts, and says cryptocurrency is stored through institutional providers including Coinbase Custody, Fidelity Digital Assets and Fireblocks.
ZachXBT did not publicly provide an example of an iTrustCapital customer losing money directly as a result of the alleged database exposure. The allegations highlight a growing security problem: criminals do not necessarily need private keys or compromised blockchain infrastructure to cause large losses if they have detailed customer data that makes targeted social engineering highly credible.
The situation remains unconfirmed by the companies. Users are advised to monitor accounts for unauthorized activity, change passwords and enable two-factor authentication.