Editor's Pick

Pocket Bitcoin Says August Data Breach Affected More Than…

Swiss Bitcoin service Pocket Bitcoin has disclosed that an August cyberattack exposed information belonging to more than 5,400 customers, including a smaller group whose identity and financial documentation was caught in the breach. The incident affected 5,120 customers whose exposed information included email addresses and communications with Pocket Bitcoin’s support team, according to reports detailing the company’s investigation.

A further 291 customers faced more extensive exposure because correspondence between Pocket Bitcoin and its partner banks had been retained inside the affected support system. For those customers, the compromised information varied by individual but could include names, postal addresses, Bitcoin addresses used for transactions, copies of identity documents and source-of-funds documentation. Pocket Bitcoin said customer Bitcoin and private keys were never compromised.

Attackers Accessed Support System

The breach resulted from what Pocket Bitcoin described as a sustained cyberattack lasting approximately one week. The company detected the intrusion while it was underway and said it had completely cut off the attacker’s access by August 16. Three days later, on August 19, its investigation established that an internal database containing email addresses and customer-support communications had been accessed and copied. The compromised support correspondence included communications conducted through email, Telegram and WhatsApp, along with attachments that customers had provided through those channels.

Pocket initially disclosed the incident on August 21 and said its primary customer database, KYC database and transaction history had not been breached. Further investigation subsequently revealed an important distinction. Although those underlying databases remained uncompromised, some sensitive information originating from those systems had also appeared in correspondence stored within the breached support environment. Pocket said this occurred because, as a regulated company, it must verify customers’ identities and, for some transactions, their source of funds. Information required for those checks was sometimes exchanged with the partner bank processing a customer’s payment, and some of that correspondence remained within the support system.

Bitcoin and Private Keys Remained Secure

Pocket’s August 31 update identified 291 customers whose exposed correspondence contained this additional information. The company contacted each of those customers individually to explain which categories of data were involved. Pocket emphasized that Bitcoin itself was never at risk because the service operates on a non-custodial basis. Customers retain their own private keys, which Pocket does not possess. Exposure of a Bitcoin address nevertheless creates a different privacy risk. Because Bitcoin’s blockchain is public, someone who obtains both a customer’s identity and Bitcoin address could potentially connect that person with the transaction history and balances associated with the exposed address.

Pocket said moving Bitcoin cannot erase previously recorded blockchain activity, although using another address can separate future transactions from an exposed address. The company has found no evidence so far that the stolen information has been used for criminal or other malicious activity, although it cautioned that this cannot guarantee future misuse. Pocket has closed the vulnerability responsible for the intrusion and introduced additional security safeguards. It has also completed its forensic investigation, reported the incident to Switzerland’s Federal Data Protection and Information Commissioner and filed a police report. The company is now warning affected customers about heightened phishing and social-engineering risks. Information taken from genuine support conversations could allow attackers to construct messages that appear substantially more credible than ordinary phishing attempts.

Pocket therefore advises customers receiving urgent requests to independently navigate to an organization’s official communication channels rather than following links or phone numbers contained in unsolicited messages. For a Bitcoin company built around self-custody, the incident demonstrates that eliminating custodial risk does not eliminate data-security risk. Pocket’s architecture prevented the attackers from stealing customers’ Bitcoin or private keys, but personal information associated with those holdings can itself become sensitive when identities, addresses and blockchain activity are linked together.