Security Hub

Pocket Bitcoin Leak Ties 291 Customers to Their Bitcoin Wallets

Published: Sep 2, 2026By Aleksandar Dukic

Key Analysis

Swiss service Pocket Bitcoin exposed compliance records linking 291 customers' names and addresses to public Bitcoin wallets. Funds were safe, but privacy was not.

Pocket Bitcoin Leak Ties 291 Customers to Their Bitcoin Wallets

Listen To This Article

Pocket Bitcoin Leak Ties 291 Customers to Their Bitcoin Wallets

4m 56s audio

AI narration. Useful for scanning on the move. Names and tickers may be mispronounced.

Pocket Bitcoin, a Swiss non-custodial Bitcoin service, disclosed that compliance records for 291 customers were copied and exposed, matching real identities to public Bitcoin addresses and on-chain transaction activity. The company detailed the incident in a security notice, and CryptoSlate reported the expanded scope on September 2, 2026. No funds moved and no private keys were touched. What leaked was the link between a name and a wallet, which for a Bitcoin user can be the more permanent loss.

The records, not the coins

Pocket Bitcoin never holds customer private keys. That design protected balances here exactly as intended. In the company's words, "Spending requires a valid signature made with the corresponding private key," so the leaked data gave an attacker no path to move Bitcoin.

The exposed material came from support correspondence with partner banks. Affected customers had varying combinations of fields copied: names, postal addresses, the public Bitcoin addresses used for their purchases, identity document copies, source-of-funds records, and payment amounts. Most people did not have every category exposed. The through-line that matters is the pairing of a legal identity with a specific address on a public chain.

Pocket first disclosed the issue on August 21 and issued an updated, wider-scope notice on August 31. It says it has finished its forensic review, closed the vulnerability, and notified each of the 291 customers about their individual exposure. The company reported the incident to Switzerland's Federal Data Protection and Information Commissioner and filed a police report, adding there is "no indication that the copied information had been misused."

A public ledger cuts both ways

Bitcoin's transparency is a feature until a name gets attached. Once an address is tied to a person, anyone with the leaked record can walk that address backward and forward through the chain: past purchases, current balance, counterparties, and rough net worth. That data does not expire, and the blockchain does not forget. A password can be rotated. A confirmed link between "this person" and "this address holding X BTC" cannot.

The immediate risks are phishing and physical security. An attacker who knows a customer's name, home address, and approximate Bitcoin holdings has everything needed for a targeted extortion attempt or a so-called wrench attack. This is the same threat pattern that has followed other exchange and hardware-wallet data leaks, where the stolen asset was contact and balance information rather than crypto itself.

The compliance-privacy squeeze

The breach lands on a structural tension in regulated crypto. Know-your-customer rules and source-of-funds checks require services to collect and store exactly the identity data that, if leaked, deanonymizes users on a permanent public ledger. A self-custody service can keep your keys out of reach and still be forced to hold a file that maps you to your coins. Pocket Bitcoin did the custody part right and was undone by the paperwork sitting beside it.

For anyone spending Bitcoin through cards, apps, or bank-linked services, the lesson is that custody model and data exposure are separate questions. Choosing a card you can spend from your own wallet removes counterparty risk to your balance, the FTX and Wirecard style of loss where a provider's insolvency freezes funds. It does not remove the KYC records a licensed provider must keep, and those records are their own attack surface. The practical defenses are old and unglamorous: fresh receiving addresses per transaction, coin-control habits that avoid clustering, and treating any service's stored identity file as a liability you cannot fully control.

Practical takeaways for affected users

Customers who receive a notice from Pocket should assume their name-to-address link is now durable, even with no evidence of misuse yet. Moving funds to a new wallet with no history breaks the chain going forward, though it does not erase the exposed past activity. Heightened caution on phishing is warranted, since attackers now have enough to craft convincing, personalized messages. Anyone whose home address was in the leak should weigh the physical-security angle, not just the digital one.

For the wider market, the incident is a reminder that "not your keys" is only half of self-sovereignty. The other half is who holds the record of your keys, and how well they guard it. Bitcoin traded at roughly $77,217 as of September 2, 2026, down about 1.4% on the day, so this was a quiet news day for price. The privacy story is the one worth reading.

Overview

Pocket Bitcoin, a Swiss non-custodial service, exposed compliance records for 291 customers, linking names and postal addresses to public Bitcoin wallets and transaction history. Private keys and funds were never at risk. The company closed the flaw, notified affected users, and reported the breach to Swiss authorities. The real damage is deanonymization on a permanent ledger, which raises phishing and physical-security risk. The episode shows that a strong custody model does not protect the identity records that regulated services are required to keep.

DisclaimerThis article is provided for informational purposes only and does not constitute financial advice. All fee, limit, and reward data is based on issuer-published documentation as of the date of verification.

Have a question or update?

Discuss this analysis with the community on X.

Discuss on X

Comments

Comments are moderated and may take a moment to appear.