Swiss Bitcoin Service Exposes User Data in Mid-August Breach
Pocket Bitcoin, a regulated non-custodial service in Switzerland, has disclosed a security breach affecting 5,411 customers. The incident occurred in mid-August 2026 and involved unauthorized access to an internal database tied to its customer support infrastructure.
The company says no misuse of the compromised information has been detected so far. A detailed breakdown revealed that 291 individuals had their correspondence with financial institutions exposed, including names, addresses, and documentation. For this group, the breach is particularly concerning as it could potentially link real-world identities to Bitcoin addresses.
The second group of 5,120 customers had transaction lists exposed, which contained personal data tied to bank transfers. While the service is non-custodial, meaning it never holds users' Bitcoin, there was no risk of direct financial loss from the breach itself. However, investigators determined that email addresses and support conversations were copied from the internal database.
Pocket Bitcoin completed a forensic investigation and reported the breach to relevant authorities in Switzerland and Liechtenstein. Every affected user received an individual notification about the exposure.