Pocket Bitcoin Breach Exposes Sensitive Customer Data on Public Bitcoin Activity
Pocket Bitcoin, a Swiss non-custodial Bitcoin service, recently disclosed that an investigation uncovered leaked compliance records containing sensitive information about 291 of its customers. The breach exposed combinations of identity, location, and compliance data, but fortunately, the private keys and customer funds remained safe.
The affected records included email addresses, support conversations, and copies of correspondence with partner banks. In some cases, real-world identities were linked to public Bitcoin activity, creating a risk of phishing and physical security breaches.
Bitcoin addresses are public by nature, but connecting them to names and postal addresses or payment amounts adds an extra layer of vulnerability. Pocket Bitcoin emphasized that the exposed information cannot move Bitcoin on its own, as spending requires a valid signature made with the corresponding private key.
The company assured customers that neither their customer database nor transaction database was compromised, but related information was included in some correspondence stored in the affected support system. An individual notice listing the affected data for each person was sent to all 291 customers, and Pocket Bitcoin reported that it had no indication of misuse.