Pocket Bitcoin: Security incidents in August exposed more customer data and expanded the scope of impact
Pocket Bitcoin announced on September 3 that its security incidents in August further exposed personal and financial information involving 5,411 customers, which made it disclose more than its original statement.
Confirmed two sets of affected data groups
Pocket Bitcoin confirmed that the two sets of data leaked this time involved a total of 5,411 customers. One group contained bank transaction records, revealing names, addresses, transfer amounts, dates, and sometimes customers 'IBAN accounts; in the other group, 291 customers could be at risk of leaking ID documents, Bitcoin addresses and sensitive financial records. Pocket Bitcoin emphasized that its customer database, trading system, private keys and customers 'Bitcoin assets were not directly affected.
Currently, relevant authorities in Switzerland and Liechtenstein have received notification, and Pocket Bitcoin has officially reported the case to the police. After completing a forensic investigation, the service provider identified two distinct data groups:
- Group 1 (larger group): Bank transaction information involving 5,120 customers.
- Group 2 (smaller group): involves communication records of 291 customers, which contain potentially more sensitive information.
Detailed leak analysis
The larger data group consists of a list of transactions sent to Pocket Bitcoin by cooperative banks during compliance reviews. These lists include the customer's name, residential address, transfer amount and transaction date. Some records are also associated with the IBAN number used for transfer.
A smaller group of data involves correspondence files sent by Pocket Bitcoin to cooperative banks. Depending on the specific customer's circumstances, the leaked materials may include names, postal addresses, public Bitcoin addresses, copies of ID documents and proof of the source of funds. The company noted that the information came in different combinations, which meant that each of the 291 customers might not have experienced all of the types of data breaches listed. Pocket Bitcoin has individually contacted affected customers to provide detailed information related to their cases.
These two sets of data together cover 5,411 customers. Although other customers may have email addresses or customer service conversation records that were exposed when the company initially disclosed it, Pocket Bitcoin stated that customers who have not received a new notification should continue to refer to the original announcement.
Core databases and user assets remain secure
Pocket Bitcoin made it clear that the attacker did not breach its main customer database or transaction database. The leaked records came from a copy backed up in the affected support system that stored the communications and bank-generated lists. This difference explains why data breaches such as transactions and identity records occur while the underlying database remains secure-the affected supporting material contains only copies of information generated or received during regulatory compliance procedures.
As an unmanaged service provider, Pocket Bitcoin does not hold customers 'private keys. The company emphasized that the attacker never accessed the Bitcoin balance and that the trading service was operating normally. Although a public Bitcoin address itself cannot authorize transfers, associating a public address with a customer's identity may cause others to view visible activity on the chain. Pocket Bitcoin reminds that transferring Bitcoin does not erase the existing transaction history of the address.
Increased risk of physical phishing
Pocket Bitcoin said there is currently no indication that the leaked information has been misused. This statement is based on available information after the investigation is concluded and does not guarantee that abuse will not occur in the future. "For now, we have not found any signs that the affected information has been misused." The company said.
Because the leaked information contained names and postal addresses, forged letters and other physical communications were considered a specific risk. Scammers may cite real bank transfers or Bitcoin transaction records to make the impersonation attempt appear more credible. However, Pocket Bitcoin pointed out that email addresses and login credentials are not associated with the two newly identified sets of data, so there is no direct risk of targeted phishing.
This incident has once again attracted attention after many recent disclosures involving customer information outside the core encryption system. Several previous leaks exposed a total of 253,487 records, raising concerns that residential and transaction data could be used for phishing or physical location years later. Another Bits of Gold incident in August may have exposed customers 'identities, bank and wallet information through third-party systems, but the investigation also found that customers' funds and passwords were not affected.
has reported to regulators and police
Pocket Bitcoin has reported the matter to the Office of the Swiss Federal Commissioner for Data Protection and Information and the Liechtenstein Data Protection Office and submitted a police report, but did not disclose the identity of the suspect or the details of the investigation. The company said the vulnerability that led to the incident has been fixed and additional security measures have been added. Currently, the company is reviewing how bank communications and related compliance records are stored and transmitted.
Pocket Bitcoin expects to release more information about these changes in the coming weeks. Although the company believes it is unlikely that other types of leaks will be discovered, customers will be notified if the results of subsequent investigations change this assessment. Affected users should pay close attention to bank account activity and be vigilant for unexpected letters, phone calls or messages. Pocket Bitcoin reiterates that it will never require customers to reveal mnemonics or make Bitcoin transfers via unsolicited phone calls or letters.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC