Leaked support files link 291 users to Bitcoin addresses

Pocket Bitcoin support records exposed names, ID copies, postal addresses and payment details tied to public Bitcoin addresses for 291 customers; private keys and funds were not affected.

Pocket Bitcoin disclosed on Aug. 21 that copies of support records for 291 customers were exposed; an Aug. 31 update identified additional items in partner‑bank correspondence stored in the affected support system.

The exposed records included varying combinations of names, postal addresses, identity‑document copies, public Bitcoin addresses and payment or source‑of‑funds details. Most customers had only some fields exposed. The firm notified each affected person with an individual notice listing the specific data involved.

Pocket Bitcoin operates as a non‑custodial service and reported that it never held customers’ private keys. The company stated private keys and on‑chain funds were not compromised. The firm noted that moving Bitcoin requires a valid signature created with the corresponding private key.

A forensic investigation and a review of the partner‑bank correspondence are complete, according to the company. The vulnerability in the support system has been remediated. The incident was reported to the Swiss Federal Data Protection and Information Commissioner and a police report was filed.

Pocket Bitcoin warned copied support details could make phishing emails, fraudulent calls or social‑engineering messages appear more credible. The Swiss National Cyber Security Centre has documented scams that use a recipient’s real home address to increase pressure on victims; the firm reported no indication that the copied information has been misused but said current visibility cannot guarantee absence of abuse.

The company revised its initial disclosure after concluding its earlier wording overstated the breadth of unaffected systems. Neither the main customer database nor the transaction database was breached, the firm reported, but related information appeared in some stored support records. Payment amounts were often present when source‑of‑funds documents or payment discussions were included.

The exposed material consisted of support‑system copies of correspondence and partner‑bank messages rather than a breach of core account or transaction databases. The company closed the affected support system and informed regulators and law enforcement as part of its response.

The incident involved compliance and customer‑service records that contained copies of identity and source‑of‑funds documents. For users of non‑custodial services, exposure of identifying details can reduce the separation between offline identity and public on‑chain activity and may increase privacy, phishing and physical‑security risks.

Articles by this author