Revolut disclosed customer identity and Bitcoin data after acting on a fraudulent government request The attacker used a genuine government email domain, slipping past automated anti-spoofing
- Revolut disclosed customer identity and Bitcoin data after acting on a fraudulent government request
- The attacker used a genuine government email domain, slipping past automated anti-spoofing checks
- The leak targeted a hand-picked set of high-net-worth Bitcoin holders, not the general user base
- Passwords, private keys, customer funds and internal databases stayed secure
Revolut handed sensitive customer records to an attacker who posed as a public authority, the digital bank confirmed this week, after its compliance team acted on a data request sent from a legitimate but compromised government email domain. The material included passport copies, KYC verification selfies and complete Bitcoin transaction histories belonging to a narrow group of wealthy account holders. On-chain investigator ZachXBT first surfaced the incident in a Telegram post, noting that the disclosure appeared aimed at high-net-worth individuals with large Bitcoin positions rather than at ordinary users.

Revolut’s customer notice, shared by ZachXBT.
The forged email cleared every automated check Revolut had
The attacker never touched Revolut’s servers. Rather than probing firewalls or databases, they sent an information request from an official government agency’s email domain, signed with valid authentication credentials. Because the message carried genuine domain headers, Revolut’s automated anti-spoofing filters read it as authentic and let it through. Staff on the legal compliance team then compiled the requested files and transmitted them, without independently confirming that the individual behind the address held any real authority to demand the data.
Revolut caught the fraud only after contacting the impersonated agency through a separate channel. By then the records had already left the building.
The sequence matters, because the failure was procedural rather than technical. Every automated control that a data request is supposed to clear, this email cleared. The one check that would have stopped it, verifying the sender’s authority instead of the sender’s domain, was the check nobody ran.
Passports left the building, private keys did not
✕ Handed to the attacker
- Passports, driver’s licenses and KYC verification selfies
- Full names, dates of birth, occupations, home addresses, emails, phone numbers
- Account statements, IBANs, opening dates and withdrawal logs
- Full Bitcoin transaction histories with explicit wallet references
✓ Never compromised
- Account passwords, login PINs and private crypto keys
- Internal databases and server infrastructure
- Algorithmic biometric facial templates
- Customer funds and crypto assets
The disclosure is dangerous because of how the categories combine. Government-issued documents establish who a person is. The contact and residential details establish where to find them. The financial and Bitcoin records establish how much they are worth. Revolut has emphasised what its systems held: no passwords, PINs, private keys or funds were compromised, and the underlying database was never breached. That distinction gives little comfort to the people whose passports and wallet histories now sit in someone else’s hands, because a passport cannot be rotated the way a password can. The pattern echoes a recent hardware wallet breach that exposed the data of more than 80,000 Trezor customers without a single private key being touched, a reminder that the most damaging leaks now hit the identity layer, not the cryptography.
Blockchain’s pseudonymity collapses once a wallet meets a passport
Public blockchains run on a single trade-off. Every transaction is visible to anyone, while the wallet addresses behind them are strings of characters with no name attached. That pseudonymity is the whole privacy model. Attach a wallet address to a passport scan and a home address, and the model collapses.
The leaked material does precisely that. It maps specific Bitcoin balances and transaction histories onto named individuals at known addresses. ZachXBT and other researchers describe the incident as a hand-picked set of wealthy profiles, not a bulk data dump, and that framing changes the threat. The primary risk shifts away from routine identity theft toward tailored spear-phishing, coercion, and in the worst case physical extortion against people confirmed to hold significant crypto. Security researchers have warned for years that publicly linking wealth to a residential address invites so-called wrench attacks, where a holder is threatened in person to surrender funds that remain otherwise cryptographically secure.
Analysts covering the case read it as a structural weakness in how financial platforms process law-enforcement and government data requests, not as a Revolut-specific lapse. The 2022 wave of fake “emergency data requests” that struck Meta, Apple, Discord and Snap ran on the same logic: a trusted institutional sender, a request dressed as urgent and official, and a human on the receiving end who complied. This one lands in a year already heavy with crypto-linked losses, with protocols down at least $1.3 billion to hacks through August, though most of those drained funds directly rather than harvesting identities.
2022 Emergency legal request exploits — Meta, Apple, Discord, Snap Hacked police and government emails used to file fake emergency requests, harvesting user data without a warrant. SEPT 2022 Revolut cyberattack Social engineering gained backend database access, exposing names and contact data of
50,150 customers. FEB 2026 Internal extortion attempt A former employee threatened to leak internal KYC data for a crypto ransom before law enforcement intervened. JULY 2026 Dark web fabrication A threat actor tried to sell 75 million alleged records for $500; Revolut’s review found the sample fabricated or recycled from older leaks. SEPT 2026 Fake government request A forged request from a compromised government domain extracted passports and Bitcoin records of select high-net-worth holders.
The episode sharpens a longer-running argument for Zero-Knowledge tools, which let a company prove it has verified a customer’s identity without holding or forwarding the raw passport and selfie behind that verification. When an institution never keeps the sensitive document in a transmittable form, a forged request has far less to take. That remains an industry proposal rather than a deployed standard, and Revolut has signalled no move in that direction.
A leaked passport cannot be reset, and regulators may now act
Revolut says it has blocked the sender, placed the affected accounts under precautionary monitoring, notified data protection and financial regulators, engaged law enforcement, and begun contacting the affected individuals directly. A spokesperson described it to crypto outlets including BeInCrypto as a sophisticated external impersonation attack.
For the people on that list, the core problem is permanence. A leaked password costs an afternoon; a leaked passport tied to a wallet history is a standing exposure that no reset resolves. Some will move funds to fresh wallets, register for identity monitoring, or in extreme cases reconsider where they live, and none of that unlinks the data already in circulation. The open regulatory question is whether supervisors will now require fintechs to verify government data requests through a mandatory out-of-band callback before releasing anything, the same manual step that eventually exposed this fraud, applied before the files leave rather than after.
The post Revolut Data Breach Links Bitcoin Wallets to Real Identities appeared first on ETHNews.