Pocket Bitcoin Discloses Data Breach Affecting 5,400+ Customers

TL;DR
The short version
- 1Pocket Bitcoin, a Swiss non-custodial Bitcoin service went on to complete its forensic investigation into an August security breach on September 3, verifying that 5,411 customers were affected in total.
- 25,120 customers had their bank transaction records revealed with; names, addresses, transfer amounts, dates, and in some cases IBAN numbers, extracted from partner banks’ compliance checks.
- 3A minor group of 291 customers encountered more advanced exposure: correspondence that could potentially include identity documents and source-of-funds documentation.
- 4No customer funds, private keys, core databases, or full KYC profiles were jeopardized, and Pocket Bitcoin says it has no evidence of exploits so far.
- 5The breach came exclusively from Pocket Bitcoin’s customer support system, and not its foundational transaction or identity infrastructure; a now common pattern in crypto data infringements this year.
How the Breach Unfolded
Pocket Bitcoin first revealed of a security incident on August 21, mentioning that its primary customer database, KYC database, and transaction history had not been breached. The company cut off the attacker’s access by August 16, and investigators established by August 19 that email addresses and support conversations had been duplicated from an internal database that was attached to its customer support infrastructure.
That first disclosure minimized the real scope. A follow-up post on August 31, updated on September 3, verified additional exposed data that was beyond what the company had initially described.
While Pocket Bitcoin’s core databases actually weren’t tampered with, sensitive information coming from those systems had independently popped up in correspondence stored within the breached support environment; the exposure traveled a step removed from where it had begun, but records that support staff had exchanged with outside parties as part of routine compliance work.
Two Distinct Groups, Two Different Risk Levels
Pocket Bitcoin’s completed investigation and separated the 5,411 affected customers into two categories.
The larger group, 5,120 customers, had bank transaction info jeopardized. As a regulated service, Pocket Bitcoin must confirm customer identities and, for particular transactions, the source of funds; checks that include exchanging transaction lists with the partner bank processing a given payment.
Those lists came with names, residential addresses, transfer amounts, and transaction dates, with some records also containing the IBAN attached to a specific transfer.
The minor group, 291 customers, encountered more serious exposure. Their records originated from correspondence between Pocket Bitcoin and its partner banks, which could cover postal addresses, Bitcoin public addresses used in transactions, copies of identity documents, and source-of-funds documentation.
That combination is quite noteworthy: identity documents in combination with specific Bitcoin addresses may build a direct, verifiable link between a real person’s legal identity and their on-chain financial activity.
What Wasn’t Touched
Pocket Bitcoin has been consistent on one factor: no customer funds, private keys, full KYC profiles, or complete transaction histories were jeopardized. That disparity truly matters considering the company’s business model; Pocket Bitcoin runs as a non-custodial service, which typically means it never holds customers’ Bitcoin directly.
There was never an instance where this breach could have resulted to stolen funds, since the company doesn’t custody the assets its customers buy through the platform.
Email addresses and login credentials weren’t included in the newly identified data group, resulting to Pocket Bitcoin mentioning it doesn’t see a direct, targeted email-phishing risk coming particularly from these records.
The Bigger Risk: Convincing Impersonation, Not Direct Theft
Pocket Bitcoin highlighted forged letters and other physical mail as a form of concern, since the exposed data includes real names and postal addresses. An impostor contacting an affected customer could reference a real bank transfer or Bitcoin transaction detail to make an impersonation effort look convincing, as it showcases knowledge only a legitimate party should plausibly have.
As of Pocket Bitcoin’s most recent update, the company reports zero verified cases of the exposed data being abused; promising, although it comes with the standard downside that absence of confirmed misuse so far doesn’t warrant that it won’t happen later, specifically for the 291 customers whose identity documents and source-of-funds records were exposed.
Part of a Broader Pattern
This attack fits a pattern that’s become more and more familiar across crypto in 2026: core cryptographic and custody infrastructure functions precisely as designed, while the ordinary business systems created around it; support tools, compliance correspondence, third-party partner communications tend to be the weak point.
It’s the same basic structure observed in the Trezor and SafePal attacks from earlier this year, where wallet security itself was never at risk, but shipping and order-tracking systems exposed customer identity and location data nevertheless.
Pocket Bitcoin’s case adds on a certain caveat: the exposure occurred not because the company was careless on storing sensitive data, but because compliance obligations legally required exchanging that data with partner banks in the first place, and some of that important correspondence remained in a support system that later got violated.
Regulatory compliance and data minimization pull in slightly opposite directions here; confirming source of funds requires collecting and sharing sensitive records, and every extra place those records get stored or transmitted becomes one more possible point of failure.
Conclusion
Pocket Bitcoin’s breach didn’t have access to customer funds or core account security, and the company has moved swiftly and clearly to inform affected users, report the incident to Swiss and Liechtenstein authorities, and release a detailed accounting of what was exposed and to whom.
But for 291 customers whose identity documents and financial correspondence are now out, the real risk here is: convincing impersonation attempts created on authentic transaction details, not a generic breach notification most people can safely overlook.
As with most incidents in this category, the foundational technology worked as intended; but it was the humans and business processes around it that allowed the breach to take place.
This is a developing story. We’ll update this piece if Pocket Bitcoin reports any confirmed instances of the exposed data being misused.
Atlas Editorial
Writers, Researchers, and Editors
Atlas Editorial is a dedicated team of writers, researchers, and editors committed to delivering clear, insightful, and well-researched content. Our team brings together diverse perspectives to keep readers informed on the latest developments, trends, and ideas shaping the digital world.

