Listen to Article — 5 min
Pocket Bitcoin, a Swiss non-custodial Bitcoin service, has disclosed that a data breach affecting 291 customers goes beyond stolen emails and support conversations. An Aug. 31 update reveals that some copied compliance records link real-world identities directly to public Bitcoin wallet activity. While the company says private keys and customer funds were not compromised, the leak creates a lasting privacy and phishing risk for affected users. Breach Update Expands Initial Aug. 21 Disclosure The Aug. 31 statement broadens the picture outlined by Pocket Bitcoin on Aug. 21. The company's initial disclosure said Bitcoin addresses, its customer database containing know-your-customer data and transaction history were not affected. Pocket Bitcoin later said that wording was too broad. According to the updated disclosure, correspondence with partner banks contained varying combinations of: Names Postal addresses Bitcoin addresses used for transactions Identity-document copies Source-of-funds records Most people in the affected cohort had only some of those fields exposed, the company said. The findings mean that the incident is not simply a support-ticket leak; for some customers, it is a direct de-anonymization event that ties their offline identity to blockchain activity. Leaked Data Fields and Their Consequences The table below summarizes the types of data found in the copied compliance records and the risk associated with each field. Leaked Data Field What It Reveals Direct Risk Names Real-world identity tied to a Bitcoin address Anonymity breakdown, targeted phishing Postal addresses Physical location Potential harassment, scam pressure Bitcoin addresses Public transaction history On-chain surveillance, link analysis Identity-document copies Verified personal data Identity theft, fraud Source-of-funds records Financial history and origin of assets Financial profiling, regulatory exposure Pocket Bitcoin did not say exactly how many of the 291 customers had each combination of fields. The company said most people in the cohort did not have every field exposed, but even a partial combination can be enough to damage pseudonymity. Why Public Bitcoin Addresses Make the Leak Sensitive Bitcoin addresses are public by design. Anyone with an address can inspect its balance and transaction history on the blockchain. Connecting an address to a name and, for some customers, a postal address or payment amount removes the layer of separation between a person's offline identity and public on-chain activity. This does not give an attacker control of any wallet. Spending Bitcoin requires a valid signature made with the corresponding private key. Pocket Bitcoin said it is non-custodial, never held customers' private keys and saw no risk to customer funds. The exposed information cannot, by itself, move Bitcoin. Funds Safe, but Phishing and Scam Pressure Rise The more immediate concern is deception. Pocket Bitcoin warned that details from copied support correspondence could make emails, calls or messages about the incident look more credible. An attacker who knows a customer's name, address and Bitcoin activity can craft highly targeted phishing attempts. Separately, Switzerland's National Cyber Security Centre has documented scams and threats that use a recipient's real home address to increase pressure. That guidance illustrates the broader danger of exposed location data but is not evidence that Pocket Bitcoin customers have been targeted. Pocket Bitcoin did not state that any customer had been targeted. Regulatory and Privacy Implications The incident highlights how off-chain compliance data can undermine on-chain pseudonymity. Bitcoin addresses are publicly readable, but they are not automatically linked to real-world identities. When a service holds both sets of data, a breach can collapse that separation. For regulators, the leak raises questions about how financial intermediaries and crypto service providers store know-your-customer records. The exposure of identity-document copies and source-of-funds records in particular could create regulatory and legal exposure for both the company and affected users. The case also serves as a reminder that non-custodial services can still hold enough personal data to create significant privacy risks. Pocket Bitcoin's customers may not lose funds, but they may now face long-term surveillance, phishing and social-engineering threats tied to their public wallet history. What Data Was Leaked in the Pocket Bitcoin Breach? Leaked support records contained varying combinations of names, postal addresses, Bitcoin addresses used for transactions, identity-document copies and source-of-funds records for 291 customers. Most affected users had only some of these fields exposed, according to Pocket Bitcoin's Aug. 31 update. Are Affected Users' Bitcoin Funds at Risk? Pocket Bitcoin said it is non-custodial and never held customers' private keys. The company saw no risk to customer funds because spending Bitcoin requires a private key, which was not part of the leaked records. Can Someone Move Bitcoin with a Leaked Bitcoin Address? No. A Bitcoin address is a public destination for funds, not a credential. Spending from that address requires a valid digital signature made with the corresponding private key. How Did the Aug. 31 Update Change Pocket Bitcoin's Initial Disclosure? The Aug. 21 disclosure said Bitcoin addresses, customer database data and transaction history were not affected. Pocket Bitcoin later said that wording was too broad and revealed that some copied records did include Bitcoin addresses and compliance data from partner bank correspondence. What Should Affected Users Do to Protect Against Phishing? Pocket Bitcoin warned that leaked details could make fraudulent emails, calls or messages look more credible. Users should treat unsolicited communications claiming to be about the incident with caution and verify requests through official channels.
Follow Our News on Google
Be instantly informed of developments.
Pocket Bitcoin, a Swiss non-custodial Bitcoin service, has disclosed that a data breach affecting 291 customers goes beyond stolen emails and support conversations. An Aug. 31 update reveals that some copied compliance records link real-world identities directly to public Bitcoin wallet activity. While the company says private keys and customer funds were not compromised, the leak creates a lasting privacy and phishing risk for affected users.
Breach Update Expands Initial Aug. 21 Disclosure
The Aug. 31 statement broadens the picture outlined by Pocket Bitcoin on Aug. 21. The company’s initial disclosure said Bitcoin addresses, its customer database containing know-your-customer data and transaction history were not affected. Pocket Bitcoin later said that wording was too broad.
According to the updated disclosure, correspondence with partner banks contained varying combinations of:
- Names
- Postal addresses
- Bitcoin addresses used for transactions
- Identity-document copies
- Source-of-funds records
Most people in the affected cohort had only some of those fields exposed, the company said. The findings mean that the incident is not simply a support-ticket leak; for some customers, it is a direct de-anonymization event that ties their offline identity to blockchain activity.
Leaked Data Fields and Their Consequences
The table below summarizes the types of data found in the copied compliance records and the risk associated with each field.
| Leaked Data Field |
What It Reveals |
Direct Risk |
| Names |
Real-world identity tied to a Bitcoin address |
Anonymity breakdown, targeted phishing |
| Postal addresses |
Physical location |
Potential harassment, scam pressure |
| Bitcoin addresses |
Public transaction history |
On-chain surveillance, link analysis |
| Identity-document copies |
Verified personal data |
Identity theft, fraud |
| Source-of-funds records |
Financial history and origin of assets |
Financial profiling, regulatory exposure |
Pocket Bitcoin did not say exactly how many of the 291 customers had each combination of fields. The company said most people in the cohort did not have every field exposed, but even a partial combination can be enough to damage pseudonymity.
Why Public Bitcoin Addresses Make the Leak Sensitive
Bitcoin addresses are public by design. Anyone with an address can inspect its balance and transaction history on the blockchain. Connecting an address to a name and, for some customers, a postal address or payment amount removes the layer of separation between a person’s offline identity and public on-chain activity.
This does not give an attacker control of any wallet. Spending Bitcoin requires a valid signature made with the corresponding private key. Pocket Bitcoin said it is non-custodial, never held customers’ private keys and saw no risk to customer funds. The exposed information cannot, by itself, move Bitcoin.
Funds Safe, but Phishing and Scam Pressure Rise
The more immediate concern is deception. Pocket Bitcoin warned that details from copied support correspondence could make emails, calls or messages about the incident look more credible. An attacker who knows a customer’s name, address and Bitcoin activity can craft highly targeted phishing attempts.
Separately, Switzerland’s National Cyber Security Centre has documented scams and threats that use a recipient’s real home address to increase pressure. That guidance illustrates the broader danger of exposed location data but is not evidence that Pocket Bitcoin customers have been targeted. Pocket Bitcoin did not state that any customer had been targeted.
Regulatory and Privacy Implications
The incident highlights how off-chain compliance data can undermine on-chain pseudonymity. Bitcoin addresses are publicly readable, but they are not automatically linked to real-world identities. When a service holds both sets of data, a breach can collapse that separation.
For regulators, the leak raises questions about how financial intermediaries and crypto service providers store know-your-customer records. The exposure of identity-document copies and source-of-funds records in particular could create regulatory and legal exposure for both the company and affected users. The case also serves as a reminder that non-custodial services can still hold enough personal data to create significant privacy risks. Pocket Bitcoin’s customers may not lose funds, but they may now face long-term surveillance, phishing and social-engineering threats tied to their public wallet history.
What Data Was Leaked in the Pocket Bitcoin Breach?
Leaked support records contained varying combinations of names, postal addresses, Bitcoin addresses used for transactions, identity-document copies and source-of-funds records for 291 customers. Most affected users had only some of these fields exposed, according to Pocket Bitcoin’s Aug. 31 update.
Are Affected Users’ Bitcoin Funds at Risk?
Pocket Bitcoin said it is non-custodial and never held customers’ private keys. The company saw no risk to customer funds because spending Bitcoin requires a private key, which was not part of the leaked records.
Can Someone Move Bitcoin with a Leaked Bitcoin Address?
No. A Bitcoin address is a public destination for funds, not a credential. Spending from that address requires a valid digital signature made with the corresponding private key.
How Did the Aug. 31 Update Change Pocket Bitcoin’s Initial Disclosure?
The Aug. 21 disclosure said Bitcoin addresses, customer database data and transaction history were not affected. Pocket Bitcoin later said that wording was too broad and revealed that some copied records did include Bitcoin addresses and compliance data from partner bank correspondence.
What Should Affected Users Do to Protect Against Phishing?
Pocket Bitcoin warned that leaked details could make fraudulent emails, calls or messages look more credible. Users should treat unsolicited communications claiming to be about the incident with caution and verify requests through official channels.
This article is provided for informational and educational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice. The digital asset market is highly volatile, speculative, and subject to rapid regulatory changes. While we strive to ensure the accuracy of the information presented, market conditions change quickly, and data may become outdated. You are solely responsible for your own research (DYOR) and financial decisions. ATHPost, its owners, and its authors assume no liability whatsoever for any direct or indirect financial losses, liquidations, or damages arising from the use of this content.