The Pocket Bitcoin breach exposed more than email addresses and support conversations for 291 customers, the company said. Some copied records linked real-world identities to public Bitcoin activity.
The finding expands the scope described in the Swiss non-custodial Bitcoin service’s Aug. 21 disclosure. In an Aug. 31 update, Pocket Bitcoin said correspondence with partner banks contained varying combinations of names, postal addresses, Bitcoin addresses used for transactions, identity-document copies and source-of-funds records. Most people in the cohort had only some of those fields exposed, the company said.
The distinction creates a privacy and phishing risk without giving an attacker control of anyone’s wallet.
Why public Bitcoin addresses still matter
Bitcoin addresses are public. Anyone with an address can inspect its balance and transaction history on the blockchain, as Bitcoin.org’s privacy guidance explains. Connecting an address to a name and, for some customers, a postal address or payment amount removes a layer of separation between a person’s offline identity and public on-chain activity.
The exposed information cannot, by itself, move Bitcoin. Spending requires a valid signature made with the corresponding private key, according to the Bitcoin developer guide. Pocket Bitcoin said it is non-custodial, never held customers’ private keys and saw no risk to customer funds.
The more immediate concern is deception. Pocket Bitcoin warned that details from copied support correspondence could make emails, calls or messages about the incident look more credible. Separately, Switzerland’s National Cyber Security Centre has documented scams and threats that use a recipient’s real home address to increase pressure. That guidance illustrates the broader danger of exposed location data but is not evidence that Pocket Bitcoin customers have been targeted.
How the Pocket Bitcoin breach changed the disclosure
Pocket Bitcoin’s initial disclosure said Bitcoin addresses, its customer database containing know-your-customer data and transaction history were not affected. The company later said that wording was too broad.
Pocket Bitcoin said neither the customer database nor the transaction database was compromised. However, related information was included in some correspondence stored in the affected support system. Payment amounts were often present when exposed records involved source-of-funds documents or discussions of a payment, the company said.
The company said every customer in the 291-person cohort received an individual notice listing the data affected in that person’s case. It also said the forensic investigation and its review of the relevant partner-bank correspondence were complete, the vulnerability had been closed, the incident had been reported to the Swiss Federal Data Protection and Information Commissioner, and a police report had been filed.
Pocket Bitcoin said it had no indication that the copied information had been misused, adding that its current visibility was not a guarantee.





Be the first to comment