Pocket Bitcoin Data Breach: When Name, Home Address and Bitcoin Address Circulate Together
The Swiss Bitcoin service Pocket Bitcoin closed its investigation on September 3, 2026: 5,411 people affected, and for 291 of them the Bitcoin addresses they used along with copies of identity documents. Why this one data pairing has lasting effect, and what you should check with your own provider.

Table of Contents
Table of Contents
Data belonging to 5,411 customers of the Swiss Bitcoin service Pocket Bitcoin has been exposed, according to the company. For 291 of them, the provider's breakdown says the Bitcoin addresses they used for their purchases were also included, along with copies of identity documents and evidence on the source of funds. That combination is precisely the part that reaches beyond the individual case: a name next to a Bitcoin address cannot be taken back, because the blockchain preserves every movement of that address in public view.
The coins themselves are not affected, according to the company. Even so, the incident is worth reading for anyone who buys Bitcoin through a provider and has it paid out to their own wallet. The same pairing of identity data and receiving address arises with every purchase, every withdrawal and every address authorisation, in Germany as elsewhere. The incident shows what becomes of it once it leaves the building.
What happened in the Pocket Bitcoin data breach
Pocket Bitcoin is a Swiss provider that converts incoming bank transfers into Bitcoin and sends the coins directly to the customer's wallet. By its own account the company holds no keys; it is what is known as a non-custodial service. Non-custodial means the provider can no longer dispose of the coins after payout, because the private key stays with the user.
The company first made the incident public on August 21, 2026. A detailed interim report followed on August 31, which Pocket Bitcoin revised once more on September 3, 2026, thereby closing the investigation. That final version carries the figure that resizes the incident: 5,411 people affected instead of the smaller group named initially. It can be read in the company's security incident update.
The provider names its support system as the point of entry. Documents that had arisen in the exchange with partner banks were held there. The gap has since been closed. The incident was reported to the Federal Data Protection and Information Commissioner in Switzerland and to the data protection authority of Liechtenstein, and the company has also filed a criminal complaint.
Who is affected: 5,120 customers with account movements, 291 with ID copies
The company distinguishes two groups, and the difference matters more for assessing the risk than the headline total.
The larger group comprises 5,120 people. What is affected here are transaction lists the provider had received from partner banks. They contain names, addresses and individual transfers with amount and date, and for some of those affected the IBAN as well. Anyone in this group has their purchase history exposed in euro or franc amounts, but without any link to a specific Bitcoin address.
The smaller group comprises 291 people and weighs more heavily. Here it is a matter of correspondence that had gone to partner banks. According to the company's breakdown, it could contain names, postal addresses, the Bitcoin addresses used for transactions, copies of identity documents and evidence on the source of funds, in varying combinations. Evidence on the source of funds is a document with which a provider records where deposited money came from, a payslip or a purchase contract, for instance.
These 291 records are the real core of the incident. Everything else can be contained by the usual means: an exposed IBAN gets changed, an ID document gets reissued, an address changes with the next move. A Bitcoin address once linked to a name stays linked.
Am I affected by the Pocket Bitcoin data breach? How to tell
According to the company, every affected person was contacted individually, with a description of what had been exposed in their particular case. Anyone who has not received such a personal message is, by that logic, not on either list. This information comes from the provider itself; there is no independent lookup list in which you could check your own address.
In practice that means: look in the mailbox you registered with the provider, including the spam folder and the promotions tab. Check the date. A notification from the week after September 3, 2026 belongs to the closed investigation, an older one from August to the first interim report, which named the smaller figure. Both can apply to the same person, with different scope.
What you should never do in the process: follow a link that asks you to enter a recovery phrase. No reputable provider asks for one, and Pocket Bitcoin states this explicitly in its notice. The same goes for any demand to move a balance to an unfamiliar address for safekeeping.
What an exposed Bitcoin address reveals about your balance
What a Bitcoin address is
A Bitcoin address is a string of characters to which coins are sent. It is neither an account nor a secret, but a public receiving detail, comparable to an account number whose every entry anyone can inspect. That is exactly where it differs from a bank account: at a bank, only those with access see the movements. On the blockchain, everyone sees them, permanently and without logging in.
Anyone who knows an address can look up in any blockchain explorer how much sits on it, when funds went in and out, and where they went next. As long as nobody knows whom the address belongs to, it is an anonymous string among millions of others. Add a name and the assessment flips. The string becomes a statement of assets with a timestamp.
With the 291 records, precisely that attribution exists. How much is actually visible there depends on what the affected person has done since. Anyone who never moved the coins received has their balance sitting visibly on the address. Anyone who passed them on has lengthened the trail, but not ended it.

Why changing addresses cuts the trail only halfway
The obvious reaction runs: send the coins to a new address and be done. It is not that simple. A transfer on the blockchain does not delete the old connection, it attaches a new one to it. Anyone who knows the old address sees the outgoing movement and sees the receiving address too. The attribution travels with it.
What coin control means
Coin control is the ability to select, within a wallet, which individual holdings are used for a payment. The benefit lies in separation: anyone who never merges coins from an exposed address with coins from other sources in a single transaction prevents an observer from attributing both holdings to the same person. If they are spent together, on the other hand, chain analysis works from the obvious assumption that they belong to one hand.
For those affected that means, concretely: keep holdings separate and spend them separately. Setting up a new wallet with its own recovery phrase and routing only future purchases there cleanly separates the future from the past. The wallets that offer coin control at all differ considerably; which they are and how to recognise them is set out in the software wallet comparison.
What matters is an honest assessment: none of these measures undoes an attribution once published. It limits what gets added in future. Anyone expecting complete anonymity from it overestimates the tool.
What was not affected: private keys, customer database, balances
In its notice, the company sets out explicitly which systems were not compromised according to the findings of the investigation: the customer database holding identity data, the transaction database and the system access credentials. The private keys never left the users' devices at any point, because by design the service does not hold them at all. Access to balances is therefore not possible by this route. No misuse of the exposed data is discernible so far, the provider writes.
This distinction is not a whitewash but the difference between two very different damage profiles. At a custodial exchange, an attack on the customer database would have hung directly on the balances. Here the balance lies outside the provider's reach, and the damage is data damage. It hits privacy and creates a surface for fraud, not for theft at the click of a mouse.
The price of this design sits on the other side of the ledger. Anyone holding the coins themselves also carries responsibility for securing them. The address authorisation used to set up a payout is, moreover, precisely the process in which the data pairing exposed here arises in the first place.
How to spot forged letters after a data breach
The company warns its customers about forged letters and other post. The reason lies in the nature of the exposed data. Anyone who knows a name, an address, a transfer amount and a date can compose a letter that quotes a genuine transaction correctly. That removes the marker by which attempted fraud is otherwise easiest to identify: the sender's ignorance.
Usable checks for post relating to your crypto account:
- A QR code prompting the recovery, backup or migration of a wallet is an attack. There is no legitimate process that begins that way.
- Time pressure in the subject line, or a deadline of a few days, is a warning sign, especially when a suspension is threatened.
- A correctly quoted transfer proves nothing at all now that this data is exposed. Do not treat it as evidence of authenticity.
- Queries belong on a channel you chose yourself: the provider's address typed into the browser, or a phone number from your own records.
- A form asking for a recovery phrase, whether by post, web form or telephone call, is always fraudulent.
How professional such letters now look is shown by the case we described under crypto wallet phishing by post. There the demand arrived on printed paper with a corporate look, not by email.

Home address plus purchase amount: the physical risk
With data breaches in the crypto world, the digital consequences are usually the first thing people think of. The more unpleasant consequence is a different one. A list bringing together names, home addresses and transfer amounts is an address list that can be sorted by wealth. The same concern already applied in August to the buyer data of two hardware wallet manufacturers, which leaked through a shipping provider; it can be read in our report on the Trezor data breach.
The difference from those cases: there, the order revealed that someone had bought a hardware wallet and therefore probably holds crypto assets. Here the amount stands next to it. That is considerably more precise information, and it is the reason why those affected should not dismiss this point as overblown.
What helps is unspectacular and works nonetheless. Do not talk about your holdings at home or among friends. Do not leave hardware and backup copies in the obvious place. Anyone who keeps a recovery phrase physically separate from the device has already done the essential thing against a burglary.
What rights the GDPR gives you, and where the ten-year period applies
Anyone affected has a right of access against the company responsible: on request it must state which personal data it processes and which were exposed in the specific case. That is the most sensible first step, because only afterwards can you judge whether a Bitcoin address was involved or merely an account movement.
The second point disappoints many. A request for erasure regularly comes to nothing at financial service providers, because statutory retention obligations take precedence. Pocket Bitcoin itself points out in its notice that it must retain customer and transaction data for ten years after a transaction is completed. That obligation is the price of regulation, and it applies in the same sense to every authorised provider in the EU.
With a Swiss provider, the competent supervisory body is the Federal Data Protection and Information Commissioner, not a German state data protection authority. Those affected who reside in the EU can nonetheless turn to their home supervisory authority first, which will forward the case. Anyone considering a complaint should keep the company's notification; it is the evidence that they were affected.
What German investors should now check with their own provider
The incident concerns the customers of a Swiss provider. The data pairing at issue, however, arises everywhere. Every exchange and every broker stores its customers' payout addresses, usually in the address book of the withdrawal function, often permanently. Together with the identity data from account opening, that means every provider holds exactly the attribution that leaked here. Since January 1, 2026 the tax reporting obligation has been added, which sets the same identity data in motion in any case.
Four checks that can be done in half an hour:
- Go through the address book. Log in with your provider and open the list of stored payout addresses. Anything you no longer need there can be removed. That shrinks the set of addresses that could be attributed to your name in the worst case.
- Do not reuse addresses. If you use the same address for every payout, your entire holding accumulates at one point known to the provider. Modern wallets generate a new address for each receipt; use that function instead of typing in an address you noted down once.
- Fix your contact route. Save your provider's official point of contact yourself. Anyone who does not have to search in an emergency also does not click the first link in an email.
- Check your backup. Is your recovery phrase stored separately from the device, and do you know for certain that it is complete and legible? A data breach changes nothing about that, but it raises the probability that someone will try their luck with you.
One note on placing this: with a non-custodial service, as in this case, the balance stays in your own hands even when data is damaged. That is a structural advantage over permanent storage on a trading platform, and it weighs more than the difference in convenience. Anyone who buys regularly and withdraws the coins each time should select providers according to whether they support automatic payouts to your own wallet.
Pocket Bitcoin data breach: what to take away
- Check whether a personal notification reached you, and read it for whether a Bitcoin address is named. Only then does the critical attribution exist. If an address is affected, move future purchases to a freshly created wallet and do not merge old and new holdings in a single transaction. Which wallets support that separation cleanly is shown by the software wallet comparison.
- Treat all post about your crypto account as unverified from now on, even when it names a genuine transfer correctly. Queries only through channels you chose yourself. And store your backup copy so that it survives a burglary; the differences between the devices are set out in the hardware wallet comparison.
- Look at the address book of your own provider, regardless of whether you are a customer of the affected service. Anyone who has payouts made automatically to their own wallet in future shrinks the data trail with every single purchase; which providers offer that is set out in the savings plan comparison.
The provider's investigation is closed, and by its account no misuse is discernible so far. For those affected in the smaller group, the matter nonetheless does not end there, because the attribution of their name and address is out in the world. An independent summary of the figures can be found at crypto.news.
(As of September 4, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.






























