Pocket Bitcoin Breach Exposed Data Linking 291 Customers to Bitcoin Activity
The Pocket Bitcoin data breach exposed more than email addresses and support conversations belonging to 291 customers, the company said. Some copied records connected customers’ real-world identities with their public Bitcoin activity.
The expanded disclosure follows the Swiss non-custodial Bitcoin service’s initial announcement on Aug. 21. In an Aug. 31 update, Pocket Bitcoin said correspondence with partner banks contained different combinations of customer names, postal addresses, Bitcoin addresses used in transactions, copies of identity documents and source-of-funds records. Most affected customers had only some of those data fields exposed, the company said.
The incident creates privacy and phishing risks, but it does not give attackers control over customers’ Bitcoin wallets.
Why exposed Bitcoin addresses create privacy risks
Bitcoin addresses are public, and anyone who has an address can examine its balance and transaction history on the blockchain, according to Bitcoin.org’s privacy guidance. Linking an address to a person’s name—and, in some cases, to a postal address or payment amount—removes a layer of separation between that person’s offline identity and public on-chain activity.
The exposed data cannot independently be used to move Bitcoin. Spending requires a valid signature created with the corresponding private key, according to the Bitcoin developer guide. Pocket Bitcoin said it operates as a non-custodial service, never held customers’ private keys and found no risk to customer funds.
The more immediate threat is impersonation and deception. Pocket Bitcoin warned that information from copied support correspondence could make emails, calls or messages about the breach appear more credible.
Separately, Switzerland’s National Cyber Security Centre has documented scams and threats that use a recipient’s real home address to increase pressure. That guidance demonstrates the broader risk associated with exposed location data, but it does not show that Pocket Bitcoin customers have been targeted.
Pocket Bitcoin revises the scope of its breach disclosure
Pocket Bitcoin’s initial disclosure said Bitcoin addresses, its customer database containing know-your-customer data and transaction history had not been affected. The company later said that wording was too broad.
The company said neither the customer database nor the transaction database was compromised. However, related information appeared in some correspondence stored in the affected support system. Payment amounts were often included when exposed records involved source-of-funds documents or discussions about a payment, Pocket Bitcoin said.
Pocket Bitcoin said each customer in the 291-person group received an individual notice identifying the data affected in that person’s case. The company also said its forensic investigation and review of the relevant partner-bank correspondence were complete, the vulnerability had been closed, the incident had been reported to Switzerland’s Federal Data Protection and Information Commissioner, and a police report had been filed.
Pocket Bitcoin said it had no indication that the copied information had been misused, while adding that its current visibility did not guarantee that misuse had not occurred.

