Leaked Compliance Records Shatter Anonymity of 291 Crypto Users by Matching Names Directly to Wallet Activity

Pocket Bitcoin’s Aug. 31 update revealed that leaked support records for 291 customers contained varying combinations of names, postal addresses, Bitcoin addresses, identity-document copies and source-of-funds records.

Listen to Article — 5 min
Follow Our News on Google
Be instantly informed of developments.
Add as a preferred source on Google

Pocket Bitcoin, a Swiss non-custodial Bitcoin service, has disclosed that a data breach affecting 291 customers goes beyond stolen emails and support conversations. An Aug. 31 update reveals that some copied compliance records link real-world identities directly to public Bitcoin wallet activity. While the company says private keys and customer funds were not compromised, the leak creates a lasting privacy and phishing risk for affected users.

Breach Update Expands Initial Aug. 21 Disclosure

The Aug. 31 statement broadens the picture outlined by Pocket Bitcoin on Aug. 21. The company’s initial disclosure said Bitcoin addresses, its customer database containing know-your-customer data and transaction history were not affected. Pocket Bitcoin later said that wording was too broad.

According to the updated disclosure, correspondence with partner banks contained varying combinations of:

  • Names
  • Postal addresses
  • Bitcoin addresses used for transactions
  • Identity-document copies
  • Source-of-funds records

Most people in the affected cohort had only some of those fields exposed, the company said. The findings mean that the incident is not simply a support-ticket leak; for some customers, it is a direct de-anonymization event that ties their offline identity to blockchain activity.

Leaked Data Fields and Their Consequences

The table below summarizes the types of data found in the copied compliance records and the risk associated with each field.

Leaked Data Field What It Reveals Direct Risk
Names Real-world identity tied to a Bitcoin address Anonymity breakdown, targeted phishing
Postal addresses Physical location Potential harassment, scam pressure
Bitcoin addresses Public transaction history On-chain surveillance, link analysis
Identity-document copies Verified personal data Identity theft, fraud
Source-of-funds records Financial history and origin of assets Financial profiling, regulatory exposure

Pocket Bitcoin did not say exactly how many of the 291 customers had each combination of fields. The company said most people in the cohort did not have every field exposed, but even a partial combination can be enough to damage pseudonymity.

Why Public Bitcoin Addresses Make the Leak Sensitive

Bitcoin addresses are public by design. Anyone with an address can inspect its balance and transaction history on the blockchain. Connecting an address to a name and, for some customers, a postal address or payment amount removes the layer of separation between a person’s offline identity and public on-chain activity.

This does not give an attacker control of any wallet. Spending Bitcoin requires a valid signature made with the corresponding private key. Pocket Bitcoin said it is non-custodial, never held customers’ private keys and saw no risk to customer funds. The exposed information cannot, by itself, move Bitcoin.

Funds Safe, but Phishing and Scam Pressure Rise

The more immediate concern is deception. Pocket Bitcoin warned that details from copied support correspondence could make emails, calls or messages about the incident look more credible. An attacker who knows a customer’s name, address and Bitcoin activity can craft highly targeted phishing attempts.

Separately, Switzerland’s National Cyber Security Centre has documented scams and threats that use a recipient’s real home address to increase pressure. That guidance illustrates the broader danger of exposed location data but is not evidence that Pocket Bitcoin customers have been targeted. Pocket Bitcoin did not state that any customer had been targeted.

Regulatory and Privacy Implications

The incident highlights how off-chain compliance data can undermine on-chain pseudonymity. Bitcoin addresses are publicly readable, but they are not automatically linked to real-world identities. When a service holds both sets of data, a breach can collapse that separation.

For regulators, the leak raises questions about how financial intermediaries and crypto service providers store know-your-customer records. The exposure of identity-document copies and source-of-funds records in particular could create regulatory and legal exposure for both the company and affected users. The case also serves as a reminder that non-custodial services can still hold enough personal data to create significant privacy risks. Pocket Bitcoin’s customers may not lose funds, but they may now face long-term surveillance, phishing and social-engineering threats tied to their public wallet history.

What Data Was Leaked in the Pocket Bitcoin Breach?

Leaked support records contained varying combinations of names, postal addresses, Bitcoin addresses used for transactions, identity-document copies and source-of-funds records for 291 customers. Most affected users had only some of these fields exposed, according to Pocket Bitcoin’s Aug. 31 update.

Are Affected Users’ Bitcoin Funds at Risk?

Pocket Bitcoin said it is non-custodial and never held customers’ private keys. The company saw no risk to customer funds because spending Bitcoin requires a private key, which was not part of the leaked records.

Can Someone Move Bitcoin with a Leaked Bitcoin Address?

No. A Bitcoin address is a public destination for funds, not a credential. Spending from that address requires a valid digital signature made with the corresponding private key.

How Did the Aug. 31 Update Change Pocket Bitcoin’s Initial Disclosure?

The Aug. 21 disclosure said Bitcoin addresses, customer database data and transaction history were not affected. Pocket Bitcoin later said that wording was too broad and revealed that some copied records did include Bitcoin addresses and compliance data from partner bank correspondence.

What Should Affected Users Do to Protect Against Phishing?

Pocket Bitcoin warned that leaked details could make fraudulent emails, calls or messages look more credible. Users should treat unsolicited communications claiming to be about the incident with caution and verify requests through official channels.

This article is provided for informational and educational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice. The digital asset market is highly volatile, speculative, and subject to rapid regulatory changes. While we strive to ensure the accuracy of the information presented, market conditions change quickly, and data may become outdated. You are solely responsible for your own research (DYOR) and financial decisions. ATHPost, its owners, and its authors assume no liability whatsoever for any direct or indirect financial losses, liquidations, or damages arising from the use of this content.