Skip to content

Pocket Bitcoin Support-System Breach Exposed Data From Thousands of Customers

Pocket Bitcoin disclosed that an August security incident exposed customer information stored in its support system. The company’s follow-up separated affected people into two groups and stressed that customer bitcoin and private keys were not compromised.

Two groups faced different exposure

The smaller group contained 291 customers whose correspondence with partner banks had been stored in the affected system. Depending on the case, that material included combinations of names, postal addresses, bitcoin addresses, identity-document copies and source-of-funds records.

A second group covered 5,120 customers appearing in transaction lists sent by partner banks. Those lists included names, addresses and individual bank transfers with amounts and dates. Some records also contained the bank account’s IBAN.

The figures should not be casually added and described as unique individuals unless overlap has been ruled out. Pocket presented them as two affected groups and said each person would receive an email explaining the data involved in their case.

What the incident did not expose

Pocket said its customer and transaction databases were not compromised. The affected material came from correspondence and transaction lists stored in the support environment. Private keys remain on customers’ devices, and the company said customer bitcoin was never at risk from the breach itself.

That boundary is important, but it does not make the exposed information harmless. Linking a name and address to bank transfers or a bitcoin address can give criminals context for convincing impersonation, extortion or physical-mail fraud.

Why tailored scams are the main immediate risk

Pocket said it had no indication, at the time of its update, that the data had been misused. It also said the exposed groups were not linked to email addresses or login credentials, reducing the direct risk of targeted email phishing from this data set.

The company nevertheless warned that names, addresses and genuine transaction details could make forged letters or other approaches appear credible. A scammer could cite a real payment to create urgency, then ask the target to “verify” an account, reveal recovery information or send bitcoin.

Steps affected customers can take

  • Read the personalized notice from Pocket to understand which group and fields apply.
  • Treat unexpected letters, calls and messages referencing prior transactions as untrusted.
  • Contact Pocket or a bank through a separately verified official channel, not details supplied in the message.
  • Never disclose a seed phrase or private key, and never transfer funds as part of a purported verification process.
  • Retain suspicious correspondence and report impersonation through official channels.

Pocket reported the incident to data-protection authorities in Switzerland and Liechtenstein and said it had filed a police report. Its forensic investigation was complete when the update was published, with further improvements to data handling still underway.

The episode illustrates a recurring distinction in self-custody: keeping private keys off a provider can protect direct control of funds, but personal and transaction data held by service companies remains a separate security surface.

Sources & further reading