Pocket Bitcoin Data Breach Exposes 5,411 Customer Records

59 minute ago 2 sources neutral

Key takeaways:

  • Non-custodial structure contained fund losses, but exposed public addresses enable blockchain surveillance and privacy erosion.
  • This breach underscores that KYC data silos are prime hacker targets, outweighing Bitcoin's transactional security.
  • Expect targeted phishing campaigns leveraging real transaction data; verify all unsolicited bank and Bitcoin communications.

Swiss Bitcoin service provider Pocket Bitcoin has completed its forensic investigation into an August cyberattack and disclosed that the incident exposed records involving 5,411 customers in total, expanding the scope of its initial disclosure.

The company identified two distinct data groups. The larger group consisted of bank transaction lists involving 5,120 customers. Those lists, sent by partner banks for compliance checks, contained customer names, residential addresses, transfer amounts and transaction dates. Some entries also included the IBAN connected to a transfer.

The smaller group involved correspondence Pocket Bitcoin sent to partner banks and affected 291 customers. Depending on the individual, exposed material could include names, postal addresses, public Bitcoin addresses, copies of identity documents and source-of-funds records. Not every customer in this group had every data type exposed.

According to Pocket Bitcoin, the attackers did not compromise its main customer or transaction databases. The records came from correspondence and bank-generated lists stored in a copied backup within the affected support system. The service operates on a non-custodial basis, meaning customer private keys are not held by Pocket Bitcoin. The company said Bitcoin balances were never accessible to the attacker, and buying and selling services continue normally.

However, exposure of a public Bitcoin address alongside personal data creates a privacy risk. Because the Bitcoin blockchain is public, a disclosed address can allow someone to inspect its transaction history, and moving Bitcoin cannot erase existing records.

The breach stemmed from a sustained cyberattack lasting roughly one week. Pocket Bitcoin detected the intrusion while it was underway and said it completely cut off the attacker's access by August 16. By August 19, investigators established that an internal database containing email addresses and customer-support communications had been accessed and copied. The compromised support correspondence included communications through email, Telegram and WhatsApp, along with attachments customers provided.

Pocket Bitcoin initially disclosed the incident on August 21 and later contacted affected customers individually. The company said it has no current indication that the exposed information has been misused, but cautioned that this does not guarantee future misuse. It warned of heightened phishing and social-engineering risks, particularly from forged letters and other physical communications referencing genuine bank transfers or Bitcoin transactions.

The company has closed the vulnerability behind the intrusion and introduced additional safeguards. It notified Switzerland's Federal Data Protection and Information Commissioner and Liechtenstein's Data Protection Office, and filed a police report. Pocket Bitcoin said it will never ask customers to disclose a seed phrase or transfer Bitcoin through an unsolicited telephone call or letter.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.