Market desk Bitcoin Ethereum Altcoins DeFi Stablecoins Markets & Trading

Swiss Bitcoin Service Pocket Bitcoin Reveals Identity Data Linked to Wallet Addresses in 291-Customer Breach

An updated disclosure from Pocket Bitcoin confirmed that some support correspondence exposed names and addresses tied to public Bitcoin addresses, though private keys and customer funds were not compromised.
1 day ago 9 views
Swiss Bitcoin Service Pocket Bitcoin Reveals Identity Data Linked to Wallet Addresses in 291-Customer Breach

Pocket Bitcoin, a Swiss non-custodial Bitcoin service, disclosed in an August 31 update that a support-system breach affecting 291 customers exposed varying combinations of identity and transaction data that in some cases linked real-world names and postal addresses to public Bitcoin addresses.

Scope of the exposed data

According to the company, records stored within the affected support system included correspondence with partner banks containing names, postal addresses, Bitcoin addresses used for transactions, identity-document copies, and source-of-funds records. Payment amounts were frequently present in records tied to source-of-funds documents or payment discussions. The company noted that most affected customers had only a subset of these fields exposed.

These details were not drawn from a direct compromise of the customer database or the transaction database, Pocket Bitcoin stated. The data appeared within support correspondence that had been copied from the affected system.

Initial disclosure revised

The company's original breach notice on August 21 stated that Bitcoin addresses, the customer database containing know-your-customer data, and transaction history were not affected. Pocket Bitcoin later acknowledged that this wording was too broad, clarifying that while the databases themselves were not compromised, related information was present in some correspondence stored in the support system.

Funds and private keys not at risk

Pocket Bitcoin emphasized that it is a non-custodial service that never held customers' private keys and that no customer funds were placed at risk. Spending Bitcoin requires a valid signature produced with the corresponding private key, a fact confirmed in the Bitcoin developer documentation.

However, the linkage of names and addresses to public Bitcoin addresses removes a meaningful privacy barrier. Because Bitcoin addresses are publicly viewable on-chain, connecting a specific address to a person's identity exposes their transaction history and balance in a way that is personally attributable.

Risks extend beyond phishing

The company warned that details from copied support correspondence could make fraudulent emails, calls, or messages about the incident appear more credible to recipients. Exposed postal addresses introduce a separate physical-security concern, as documented by Switzerland's National Cyber Security Centre in guidance on scams that use a victim's home address to apply pressure.

Incident response status

Pocket Bitcoin reported that its forensic investigation and review of relevant partner-bank correspondence are complete. The company said the vulnerability has been closed, that it notified the Swiss Federal Data Protection and Information Commissioner, and that a police report was filed. Every affected customer received an individual notice specifying the data exposed in their particular case.

The company stated it had no indication that the copied information had been misused, while noting that current visibility does not constitute a guarantee against future exploitation of the exposed data.

Market snapshot

Top cryptocurrency prices

Explore all prices
BitcoinBTC $77,745.64+0.08% EthereumETH $2,402.60-0.78% Tether USDUSDT $1.00+0.02% BNBBNB $694.24+0.78% XRPXRP $1.37+1.27% USDCUSDC $1.00+0.01% SolanaSOL $100.70+0.59% TRONTRX $0.3263+1.03% HyperliquidHYPE $82.05-1.47% ZcashZEC $815.18-1.60%
Prices by Coinranking. Informational only.