31 August 2026

0 views

Security Incident Update: What We Have Found Since 21 August

Security incident at Pocket Bitcon

Published: Monday, 31 August 2026 · Pocket Bitcoin
Updated: Thursday, 3 September 2026

On 21 August we published information about the security incident at Pocket Bitcoin. At the time, we announced that we would contact customers personally if more than just their support correspondence was affected. Our investigation has since identified two distinct situations, which we describe separately below.

If you have not received a personal email from us, the information from our first blog post continues to apply to you.

What we have found#

Our investigation identified two separate groups of affected customers. They differ in how the data reached us, which data is affected, and what risks arise from it.

Group 1: Correspondence we sent to partner banks (291 customers)#

As a regulated company, we are required to verify identity and, for certain transactions, the origin of funds before a purchase or sale can take place. This includes the correspondence with the partner bank that processes a payment. Depending on the case, this ranges from a name to proof of identity and proof of origin. Part of this correspondence was stored in our support system, which was affected by the incident.

Our investigation has confirmed that 291 customers are affected in this way. What the correspondence contained varies from case to case: across the group, it includes names, postal addresses, bitcoin addresses used for transactions, copies of identity documents, and source-of-funds documentation in varying combinations. For most people, it is only some of these details.

Group 2: Transaction lists that partner banks sent to us (5,120 customers)#

During compliance checks, some partner banks sent us overviews: time-bounded lists of bank transfers. These lists were kept in our support system and were part of the exposed data backup.

In this group, 5,120 customers are affected. The lists contained names, addresses, as well as individual bank transfers (including amount and date). In some cases, they also contained the IBAN of the bank account from which a transaction was made.

Our investigation of both categories is complete. Everyone affected will receive a personal email setting out exactly what was affected in their case.

What was affected: more details#

Our first post listed three things as “not affected”: bitcoin addresses, the customer database including KYC data, and transaction history.

The distinction that matters is between our systems and the data itself: none of those systems were compromised, and that still holds, but data of those kinds was present in the correspondence that was exposed.

Our customers' bitcoin was never at risk. A bitcoin address is not access to funds but public information on the blockchain, and transferring bitcoin requires private keys, which never leave our customers' devices. What changes as a result of the disclosure is that details about a person, for Group 1, for example, a bitcoin address together with a name; for Group 2, a name together with an address and individual bank transfers, can be linked to one another.

Whether the data has been used#

As things stand, we have no indication that any of the affected information has been misused. That reflects what we can see today.

Am I affected?#

If you are affected, you will receive a personal email from us setting out exactly what was affected in your case and which of the two groups your case belongs to. If you have not received such an email, nothing applies to you beyond what we described on 21 August.

What we are doing#

  • Everyone affected is being contacted directly and personally.
  • The incident was reported to the Swiss Federal Data Protection and Information Commissioner (FDPIC) and, in accordance with the GDPR, to the Data Protection Office of Liechtenstein, and we have filed a report with the police.
  • The forensic investigation is complete.
  • We have already taken a number of measures and are working on further improvements, in particular regarding how data of this kind is handled and transmitted. We will share more about this over the next few weeks.

What matters most right now#

Because genuine details about affected people were disclosed, fraud attempts may appear more convincing than usual.

In both groups, the disclosed data is not linked to email addresses or login credentials. We therefore do not see a direct risk of targeted email phishing from it. However, because names and addresses were included, be particularly alert to forged letters and other mail. Fraudsters could refer to a real earlier transaction in order to appear more credible.

As a general rule, be suspicious of any message, whether by letter, phone or email, that pressures you to act quickly, demands a payment, or asks you to "verify" something. When in doubt, contact the organisation in question yourself through the official channels, rather than using the links or numbers provided in the message. Pocket Bitcoin will never ask you for your seed phrase, and will never ask you by letter or by phone to transfer bitcoin or to make a payment.

What happens next#

All further updates will be published here. We are aware that an incident like this shakes the trust you have placed in us, and to those whose data was disclosed, we offer our sincere regret.

The Pocket Bitcoin Team

Frequently asked questions#

How does this fit with what you wrote on 21 August?#

Why did you have these documents in the first place? (Group 1)#

I never sent you any documents. Why am I affected? (Group 2)#

What does the disclosed IBAN mean for me?#

Are my bitcoin affected?#

Can someone see how much bitcoin I own, and should I move it?#

What about amounts?#

Will there be more cases?#

Is my future communication with Pocket secure?#

Can I ask you to delete my documents?#

Who do I contact with questions?#