EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

ZachXBT accuses BitcoinIRA and iTrust Capital of data breach

2026-08-25 00:15:05
Bookmark

Blockchain investigators accuse two U.S. crypto investment platforms of data breaches

Blockchain investigator ZachXBT accused that two U.S. crypto investment platforms-BitcoinIRA and iTrustCapital-had data breaches this year, but were not publicly disclosed. This raises concerns that leaked customer information may be helping criminals carry out precise social engineering attacks.

ZachXBT said on Monday that he had reviewed evidence that the databases of both companies had been compromised. According to his posts, the leaked information included personal details, portfolio positions, bank information, custodian information and account verification status. As of the time ZachXBT posted, neither BitcoinIRA nor iTrustCapital had publicly confirmed the leak. The investigator said he contacted the two companies on August 21 seeking comment, but received no response. The allegations have not been independently verified, and ZachXBT has not disclosed the number of customers that may have been affected, when the leak occurred, or how the attackers obtained the information.

These unanswered questions are crucial. A database that contains information about customers and their positions does not necessarily mean that the cryptographic assets held by the two platform custodians have been compromised. Instead, the immediate threat may come from criminals using detailed customer information to make phishing emails and fake support calls more convincing.

BitcoinIRA users allegedly lost more than US$1.2 million

ZachXBT cited a case involving a BitcoinIRA customer in June this year as an example to illustrate how such information might be used. Earlier this month, the investigator released an independent investigation into the threatening actor codenamed "Tiffany", linking it to at least $5 million in thefts involving impersonating cryptocurrency companies, exchanges and hardware wallet support services. In one case, a victim allegedly received a forged BitcoinIRA email and subsequently lost more than $1.2 million in Bitcoin and Ethereum from Trezor hardware wallet in June. Therefore, these assets were not stolen from BitcoinIRA's own custody infrastructure. Instead, ZachXBT's investigation showed that the attacker pretended to be BitcoinIRA and carried out a social engineering attack on a person who held cryptocurrency alone in a hardware wallet.

This difference is important because the newly alleged database breach may explain how attackers knew about the victim's relationship to BitcoinIRA and carried out targeted attacks, but this alone does not prove that the database was the source of the information leak. ZachXBT now says the attacker used information from the database when targeting the victim. His previous investigation identified Bitcoin and Ethereum addresses related to the $1.2 million theft and described communications between suspected gang members after the attack. The information disclosed so far does not prove that other BitcoinIRA customers lost assets due to the leak.

BitcoinIRA claims that customers use external custody of their crypto assets

BitcoinIRA was established in 2016 and provides autonomous retirement accounts that allow U.S. customers to invest in cryptocurrencies. The company says it serves more than 200,000 Americans and currently supports more than 100 cryptocurrencies. BitcoinIRA does not directly custody retirement assets held through its platform. Its current account disclosure documents list Digital Trust as a custodian, while BitcoinIRA says digital assets are stored using BitGo's multi-signature infrastructure. The company's website promotes offline storage, video authentication and up to $250 million in custody insurance (depending on the assets and custody arrangements). BitcoinIRA's privacy policy states that it takes measures designed to protect personal information from unauthorized access, misuse and disclosure, while also acknowledging that no Internet transmission can be guaranteed to be completely secure.

There is currently no evidence that the alleged data incident affected BitcoinIRA's underlying cryptocurrency wallet or its custodian. This raises two different security questions: whether customer information has been compromised, and whether customer assets held through the platform hosting system have been at risk. ZachXBT's allegations involve the first issue.

iTrustCapital was also accused of being involved in the leak

The second platform ZachXBT pointed out is iTrustCapital, another U.S. service provider that focuses on investing in cryptocurrencies through autonomous retirement accounts. iTrustCapital describes itself as a software platform rather than an exchange, broker or custodian. The company uses Fortis Bank as a qualified custodian for its IRA accounts. According to iTrustCapital, cryptocurrencies held through its services are stored using institutional providers including Coinbase Custody, Fidelity Digital Assets and Fireblocks. The company said assets are held on a 1:1 ratio and are not on its balance sheet. Its security model is also different from traditional cryptocurrency exchanges because iTrustCapital says it does not use hot wallets for customer accounts and uses a closed structure designed to prevent cryptocurrency from being directly extracted to any external address.

This may make personal information disclosure a different type of threat. Attackers may not be able to steal cryptocurrency simply by obtaining the iTrustCapital password, but customer identification information, portfolio data, and bank data may still be used for phishing, account takeover attempts, identity theft, or attacks against other accounts. ZachXBT did not provide public cases of iTrustCapital customers directly causing financial losses due to database leaks.

The greater risk lies in highly targeted social engineering attacks

The allegations reveal a growing problem facing cryptocurrency investors: Security breaches do not necessarily involve a breach of private keys or blockchain infrastructure, but can also cause huge losses. Information about an individual's investment portfolio can be valuable in itself. A criminal who knows that his victim uses a specific encryption platform, holds specific assets, owns a large investment portfolio, and works with a specific custodian is more likely to create a credible impersonation attempt than someone who sends ordinary phishing emails. Attackers can cite actual account information, identify themselves as security employees, and claim unusual activity that requires immediate action. This changes the cost-effectiveness of social engineering attacks.

A compromised database of thousands of customers could allow attackers to rank potential victims based on portfolio value and focus on the accounts with the largest balances. The June case involving BitcoinIRA is significant for this reason. According to reports, the $1.2 million theft did not require an attacker to breach BitGo, hack into the Bitcoin network, or use the Trezor hardware itself. According to ZachXBT's investigation, the attacker persuaded the victim through impersonation and social engineering.

Disclosure issues may become the next focus

Based on the available information, it is not yet possible to determine whether BitcoinIRA or iTrustCapital are legally obligated to disclose any incidents. Disclosure notification requirements in the United States depend on multiple factors, including where the affected customer lives, the type of information accessed, whether the data is encrypted, and whether the incident meets the legal definition of a breach. Therefore, the mere existence of leaked information does not prove that any company has violated disclosure requirements. More information is also needed to understand when each company becomes aware of any unauthorized access.

The most important confirmations at the moment must come from BitcoinIRA and iTrustCapital themselves: whether their systems or service providers have been compromised, what data is involved, how many customers have been affected, and whether customers or regulators have been notified privately. Until these details were disclosed, the strongest conclusions based on available evidence were more limited than the original allegations. ZachXBT said he had reviewed evidence of customer data breaches involving two companies, and previous investigations provided a documented case in which a BitcoinIRA user was the target of a $1.2 million social engineering theft. However, neither company has publicly confirmed any leaks, and there is currently no evidence that the underlying cryptographic hosting infrastructure of either platform has been compromised.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP