Zurich: Swiss Bitcoin service provider Pocket Bitcoin has revealed that an August security incident exposed additional personal and financial information involving 5,411 customers, expanding the scope of the breach disclosed earlier.

The company said its forensic investigation identified two separate groups of affected records. The larger group involved bank transaction information relating to 5,120 customers, while a second group contained correspondence involving 291 customers that could include more sensitive identity and Bitcoin-related information.

Pocket Bitcoin said the incident did not compromise its core customer or transaction databases, private keys or customers’ Bitcoin. The exposed information instead came from copies of records stored in a backup within an affected support system.

Two groups of customer records exposed

The first and larger group involved transaction lists that Pocket Bitcoin received from partner banks as part of compliance procedures.

These records contained customer names, residential addresses, transfer amounts and transaction dates. In some cases, the lists also contained the IBAN associated with a transfer.

The second group consisted of correspondence that Pocket Bitcoin had sent to partner banks. Depending on the individual record, this material could contain names, postal addresses, public Bitcoin addresses, copies of identity documents and source-of-funds information.

Pocket stressed that the information was not identical for every affected customer. Customers in the 291-person group did not necessarily have every category of information exposed. The company said it has contacted affected customers individually with details about their particular cases.

Together, the two newly identified groups account for 5,411 customers.

Bitcoin and private keys remain secure

One of the most important aspects of the incident is what the attackers did not gain access to.

Pocket Bitcoin said its main customer database and transaction systems were not compromised. The exposed material consisted of copies held in a support-system backup rather than the underlying databases.

The company operates as a non-custodial Bitcoin service, meaning it does not hold customers’ private keys. Pocket said customer Bitcoin balances were therefore not accessible to the attacker and its buying and selling services continue to operate normally.

A public Bitcoin address by itself cannot be used to authorise a Bitcoin transfer. However, if a public address is connected with a person’s real identity, an attacker can potentially examine the visible transaction history associated with that address.

That creates a different kind of privacy and security concern, particularly when blockchain information is combined with residential addresses or financial records.

Physical fraud and impersonation risks

Pocket Bitcoin said it currently has no indication that the exposed information has been misused.

However, the company warned that the nature of the exposed records could make certain types of fraud more convincing.

Names and postal addresses, combined with genuine information about a bank transfer or Bitcoin transaction, could potentially be used to create fraudulent letters or other physical communications that appear legitimate.

For example, someone with access to a customer’s real transaction details could attempt to impersonate a financial institution or cryptocurrency service and use genuine information to make the communication appear credible.

Pocket Bitcoin said email addresses and login credentials were not part of the two newly identified groups. As a result, it does not currently see a direct targeted email-phishing risk specifically arising from these newly disclosed records.

Nevertheless, the exposure of identity and financial information remains significant because such information can potentially be combined with data obtained from other sources.

How the breach happened

The exposed records were not taken directly from Pocket Bitcoin’s primary customer database.

Instead, the forensic investigation found that bank-generated transaction lists and correspondence were stored as copies within the affected support infrastructure.

These documents had been created or received as part of regulatory and compliance processes. The incident therefore demonstrates how sensitive information can remain exposed even when a company’s main financial or transaction systems are not directly compromised.

The company said the vulnerability responsible for the incident has now been closed.

Pocket Bitcoin has also introduced additional safeguards and is reviewing the way bank correspondence and related compliance records are stored and transferred.

The company expects to provide more information about these security changes in the coming weeks.

Regulators and police notified

Pocket Bitcoin said it reported the incident to data protection authorities in both Switzerland and Liechtenstein.

The company notified Switzerland’s Federal Data Protection and Information Commissioner as well as Liechtenstein’s Data Protection Office. It also filed a police report.

Pocket Bitcoin has not identified the suspected attacker or disclosed further details about the police investigation.

The company said it does not currently expect to identify additional categories of exposed information, although it will notify customers if later findings change that assessment.

Customers urged to remain cautious

Pocket Bitcoin has advised affected users to monitor their bank activity and remain cautious about unexpected letters, calls or messages.

The company has also emphasised an important security rule: it will never ask customers to provide a seed phrase or transfer Bitcoin following an unsolicited telephone call or letter.

This warning is particularly relevant because a legitimate-looking scam can become more convincing when criminals possess real information about a person’s cryptocurrency activity.

Customers should therefore avoid treating knowledge of a transaction, wallet address or personal detail as proof that a communication is genuine.

Crypto industry faces growing data-security concerns

The Pocket Bitcoin incident comes amid a series of cryptocurrency-related security breaches in which attackers have obtained customer information without necessarily gaining direct access to digital assets.

Recent incidents involving crypto companies have highlighted the risks associated with third-party systems, support platforms, analytics tools and other infrastructure surrounding core blockchain services.

A previous crypto.news investigation noted that three separate breaches exposed hundreds of thousands of customer records, including combinations of names, phone numbers, addresses and purchase information. Such data can create risks even when private keys and customer funds remain secure.

For cryptocurrency users, the lesson is that security is not limited to protecting a wallet’s private key. Personal information connecting an individual to cryptocurrency ownership can itself become valuable to criminals.

What Pocket Bitcoin customers should know

The newly disclosed breach does not mean that 5,411 customers lost their Bitcoin or that their private keys were stolen.

Instead, the incident concerns exposure of personal, financial and, for a smaller group, potentially sensitive identity and cryptocurrency-related records.

The 5,120-customer group involved bank transaction information, while the 291-customer group potentially involved identity documents, public Bitcoin addresses and source-of-funds records. Not every customer in either group necessarily had every type of information exposed.

Pocket Bitcoin says it has individually contacted customers whose newly identified information was affected.

The company has also closed the vulnerability, notified regulators and police, and begun strengthening its handling of compliance-related records.

A reminder that crypto privacy goes beyond private keys

The Pocket Bitcoin breach illustrates an increasingly important issue for the cryptocurrency industry: protecting digital assets and protecting customer identity are two different security challenges.

While the company’s non-custodial structure helped prevent the attackers from accessing customer Bitcoin directly, the exposure of names, addresses, transaction information and other records can still create privacy and fraud risks.

For users, vigilance remains important even when funds themselves are safe. Unexpected requests for seed phrases, Bitcoin transfers or sensitive information should be treated as potential scams, particularly when the sender appears to know genuine details about a customer’s transactions.

Pocket Bitcoin’s investigation has expanded the known scope of the August incident, but the company says there is currently no indication that the newly exposed information has been misused.