• Pocket Bitcoin, a Swiss non-custodial bitcoin service, says a breach affected records belonging to 291 customers.
  • Some of the copied material paired real names, and in some cases postal addresses and identity documents, with the bitcoin addresses those customers transacted with.
  • No were involved, so nobody’s coins can be moved with this data. The link between person and address is permanent all the same.

Most data breaches cost you a password and an afternoon of resets. This one is reported to have handed somebody a list of names, in some cases home addresses and copies of identity documents, sitting alongside the bitcoin addresses those people used.

A leaked password can be changed. A bitcoin address that has been publicly connected to a name cannot be disconnected, because the record it sits on is public and permanent. Anyone holding that pairing can look up the balance, every payment in and every payment out, going back to the first transaction and forward indefinitely.

For the people in this group, that raises the odds of targeted phishing, impersonation and extortion attempts, and for the smaller number whose postal address was also exposed, it means someone may be able to see both what they hold and where they live.

What has been said, and what we have not seen

Pocket Bitcoin first disclosed a breach on 21 August. In an update on 31 August, according to CryptoSlate’s account of that statement, the company said correspondence with partner banks that was caught up in the incident contained varying combinations of names, postal addresses, bitcoin addresses used for transactions, copies of identity documents and source-of-funds records. Most people in the group had only some of those fields exposed rather than all of them.

We have not read the company’s own update directly. Everything above comes from a single secondary report, and the detail that matters most here, which fields were exposed for how many people, is exactly the kind of detail that gets revised as a company works through its logs. Treat the specifics as provisional until the firm’s own notice is easy to find and read.

Pocket Bitcoin is a non-custodial service, meaning it helps customers buy bitcoin that goes straight to a wallet the customer controls rather than holding coins on their behalf. That structure is why this is not a theft story. Whoever holds these records cannot spend anyone’s money with them.

Why a name beside an address is different

Close-up of Polish passports and travel tickets symbolizing travel and adventure.
Passports and travel documents of the kind customers hand over during identity checks: once that paperwork is tied to a wallet address, the link cannot be undone. Photo by Jakub Zerdzicki on Pexels.

Bitcoin’s ledger is open by design. Every address and every transaction is visible to anyone who wants to look, which is what allows the network to be checked by strangers who do not trust each other. The privacy that ordinary users have always relied on is not secrecy but separation: the address is public, the person behind it is not, and Bitcoin.org’s own privacy guidance is blunt that this separation is the whole of it.

Compliance paperwork is where that separation is deliberately broken. Identity checks, source-of-funds records and bank correspondence exist precisely to attach a legal name to a financial trail, and they are created because regulators require them. That makes them the most sensitive documents a crypto firm holds, and the least useful ones to keep any longer than the law demands.

The consequence is that a compliance leak behaves differently from an ordinary one. An exposed email address is a nuisance that fades. An exposed name-to-address pairing gets more revealing over time, because the ledger keeps recording, and anyone who saved a copy of the file can come back to it in five years and read what happened since.

What someone in this group can do

None of this undoes the exposure, and none of it is any burden the affected customers created. It is damage limitation.

Moving coins to newly generated addresses puts a break between past and future activity, but only if the old and new coins are kept apart. Spending several inputs in a single transaction tells anyone watching that the same person controlled all of them, so combining coins from an exposed address with coins from a fresh one links the two straight back together. Our self-custody guide covers the mechanics of managing addresses and backups.

Beyond that, expect the contact attempts to be convincing. Someone with your name, your postal address and your holdings can write a far better fake support email than the usual spam, and extortion messages that quote a real balance are a known follow-on from leaks of this kind. Anyone in the UK who receives one can forward suspicious emails to report@phishing.gov.uk and report attempted fraud to Action Fraud. No legitimate firm will ask for a , ever.

The part the company has not addressed

Two things are missing from what has been reported. The first is why identity documents and source-of-funds records were sitting in email correspondence with partner banks at all, rather than in a system built to hold them. The second is retention: how long those records stay on file after a customer’s transaction is complete, and whether that period is longer than Swiss rules actually require.

The disclosure timeline is also worth noting. Ten days passed between the initial notice and the update that expanded the scope to include activity. That gap may simply reflect how long the forensic work took, but for the people affected it was ten days of not knowing which of their details were in the file.

What to watch

Whether Pocket Bitcoin publishes a field-by-field breakdown telling each customer what of theirs was exposed. A general description does not let anyone judge their own risk, and it is the difference between a notice and a useful one.

Whether Swiss data protection authorities open an inquiry, and whether the answer on retention is that the records had to be kept. If a firm can show it held only what the law required, the argument moves from the company to the rules. If it cannot, this becomes a story about paperwork nobody needed to still have.

We have not seen a primary statement from the company or from any regulator, and we will update this piece if one appears.