The personal data of 291 Pocket Bitcoin customers was exposed in a security breach, with some records directly linking real-world identities to publicly visible Bitcoin transactions.
The Swiss non-custodial Bitcoin service said the incident involved more than email addresses and customer-support conversations. In some cases, correspondence held by partner banks included customers’ names, postal addresses, Bitcoin addresses used in transactions, copies of identity documents and source-of-funds information.
Pocket Bitcoin outlined the broader extent of the breach in an update on 31 August, following its initial disclosure on 21 August. The company said most of the 291 affected customers had only some of those categories of information exposed.
The leak does not give attackers control of customers’ Bitcoin wallets, but it creates a significant privacy risk and could make phishing attempts more convincing.
Bitcoin addresses are publicly visible, allowing anyone to inspect associated balances and transaction histories on the blockchain. Linking an address to a person’s name, and in some cases to a postal address or payment amount, removes an important layer of separation between an individual’s offline identity and their on-chain activity.
However, the information exposed in the breach cannot be used by itself to move Bitcoin. Spending funds requires a valid digital signature created with the relevant private key, according to the Bitcoin developer guide.
Pocket Bitcoin said it operates on a non-custodial basis, meaning it never held customers’ private keys. It added that there was no risk to customers’ funds as a result of the breach.
The company said the more immediate threat was the possibility of targeted deception. Details copied from support correspondence could allow criminals to make emails, telephone calls or messages about the incident appear more authentic.
Switzerland’s National Cyber Security Centre has separately warned about scams and threats in which a recipient’s real home address is used to increase pressure. That guidance highlights the wider danger associated with exposed location data, but does not show that Pocket Bitcoin customers have been targeted.
Pocket Bitcoin’s first disclosure said its Bitcoin addresses, customer database containing know-your-customer information and transaction history had not been affected. The company later acknowledged that wording had been too broad.
It maintained that neither the customer database nor the transaction database had been compromised. But related information from those areas appeared in some correspondence stored within the affected support system.
Payment amounts were also present in a number of exposed records, particularly where the correspondence involved source-of-funds documents or discussions about a payment, the company said.
Pocket Bitcoin said each of the 291 customers had received an individual notification explaining which data had been affected in their case. It added that its forensic investigation, along with its review of the relevant correspondence held by partner banks, had been completed.
The company said the vulnerability had been closed, the incident reported to the Swiss Federal Data Protection and Information Commissioner, and a police report filed.
Pocket Bitcoin said it had found no indication that the copied information had been misused, while stressing that its current visibility did not guarantee that misuse had not occurred.
Bitcoin was down 1.42% over the previous 24 hours and ranked number one by market capitalisation.
Liam Wright, also known as “Akiba”, is a reporter, podcast producer and Editor-in-Chief at CryptoSlate. He believes decentralised technology has the potential to make a difference.
CryptoSlate may use AI tools to assist with research, editing and production. Its journalism remains human-led, with the editorial team responsible for every published article. The publication provides a full AI-usage disclaimer.
The opinions of its writers are their own and do not represent the views of CryptoSlate. None of the information in the article should be treated as investment advice, and CryptoSlate does not endorse any project mentioned or linked.
Buying and trading cryptocurrencies is a high-risk activity. Readers are advised to conduct their own due diligence before taking any action based on the article. CryptoSlate accepts no responsibility for losses incurred through cryptocurrency trading. Further information is available in the company’s disclaimers.
CryptoSlate also invites readers to follow its signal service for market-moving updates.
