Loading prices…
🩸BEARISH

Pocket Bitcoin Breach Links 291 Users to Their Wallets

Sensitive KYC docs paired with public Bitcoin addresses turn a non-custodial service's privacy promise into a target list, with phishing and physical safety now the live threats.

The Aug. 31 follow-up from Swiss non-custodial Bitcoin service Pocket Bitcoin revealed that compliance correspondence copied in the breach contained combinations of real names, postal addresses, Bitcoin addresses, identity-document copies and source-of-funds records for 291 customers. Most in the cohort had only a subset of those fields exposed, but for some the breach collapses the typical separation between an offline identity and on-chain activity. Pocket Bitcoin said funds remain safe because the service never held private keys, yet the disclosure now lands in a year already marked by escalating physical threats against known crypto holders.

Why it matters

The breach is not a wallet drain. Spending Bitcoin still requires a valid signature from the corresponding private key, and Pocket Bitcoin's non-custodial architecture kept the keys with the users. The damage is contextual. A name, postal address and payment amount sitting alongside a public Bitcoin address gives an attacker the inputs for credible phishing, targeted social engineering, or the kind of physical coercion the Swiss National Cyber Security Centre has already warned about. In 2025, attackers have repeatedly used breached home addresses and transaction histories to pressure victims in person.

Pocket Bitcoin's initial Aug. 21 disclosure said Bitcoin addresses, the customer database and transaction history were not affected. The company walked that back in the Aug. 31 update, clarifying that some of those data points did appear in support correspondence with partner banks even though the underlying databases were not compromised. That correction matters: it sets the disclosure language bar higher for every non-custodial service that handles regulated fiat on-ramps.

Market impact

The immediate risk is targeted attacks on the 291 affected customers, not contagion across Bitcoin self-custody more broadly. Pocket Bitcoin said it has no evidence of misuse yet, has closed the vulnerability, notified the Swiss Federal Data Protection and Information Commissioner and filed a police report, and sent each affected customer an individual notice.

Related tokens
$BTC

Frequently asked questions

  1. How many Pocket Bitcoin customers were affected by the breach?

    Pocket Bitcoin said 291 customers had compliance records exposed. Most had only a subset of the data fields copied, and every person in the cohort received an individual notice listing the fields that applied to them.

  2. Were any Bitcoin funds stolen in the Pocket Bitcoin breach?

    No. Pocket Bitcoin is non-custodial and never held customer private keys, so the breach did not give attackers the ability to move Bitcoin. The exposure was limited to identifying and contextual information held in support correspondence.

  3. What specific data was exposed in the Pocket Bitcoin breach?

    According to the Aug. 31 update, exposed records contained varying combinations of real names, postal addresses, Bitcoin addresses used for transactions, identity-document copies and source-of-funds documents held in correspondence with partner banks.

  4. Did Pocket Bitcoin change its initial disclosure of what was affected?

    Yes. The Aug. 21 disclosure said Bitcoin addresses and the customer database were not affected. The Aug. 31 follow-up clarified that those data points did appear in some copied correspondence with partner banks, even though the underlying databases were not compromised.

  5. What should affected Pocket Bitcoin customers watch for?

    The immediate risks are targeted phishing, social engineering and physical coercion, all of which have escalated against known crypto holders in 2025. Pocket Bitcoin has not seen evidence of misuse but warned that current visibility is not a guarantee.

Source attribution
Aggregated from CryptoSlate · Verified · Last refreshed 1h ago
Open original →