Security · Data exposure
Pocket Never Held a Coin. It Held the Map
A Swiss broker built so that it structurally cannot touch customer bitcoin has disclosed that an intruder in its support system took names, home addresses, and — for 291 people — the Bitcoin addresses to go with them. Non-custodial was always a promise about funds. It was never a promise about identity.
Pocket Bitcoin is a Swiss service that exists to make buying bitcoin boring: you set up a recurring bank transfer, the coins go straight to a wallet you control, and the company never holds them. That is not a marketing posture. It is the architecture. Whatever happens to Pocket, it cannot lose your bitcoin, because at no point does it have your bitcoin.
Between roughly August 10 and August 16, someone was inside its customer support system anyway.
By the company's own account, the intruder's access was severed on Sunday, August 16. On Wednesday, August 19, during the investigation that followed, Pocket found that an internal database tied to that support infrastructure had been copied. It disclosed publicly on Friday, August 21. Then it kept counting — and the number kept getting worse. An August 31 update expanded the scope. A further update on September 3 put the total at 5,411 customers.
The two groups, and why one of them matters much more
The 5,411 split unevenly, and the split is the entire story.
The larger group — 5,120 people — appeared in bank-generated transaction lists. What leaked there was names, residential addresses, transfer amounts, transaction dates, and in some cases IBAN account numbers. That is a serious financial-privacy breach by any ordinary standard, and it is roughly what you would expect from a compromised support desk at any regulated broker.
The smaller group is 291 people, and what leaked about them is different in kind. Per the company's breakdown, that set includes names, postal addresses, copies of identity documents, source-of-funds records, and — in some cases — the public Bitcoin addresses those customers transacted with.
Put those fields next to each other. A legal name. A street address. A passport or ID scan. And a Bitcoin address whose balance and full transaction history anyone on earth can look up in about four seconds, for free, forever.
What actually left the building
| Group | People | Data exposed |
|---|---|---|
| Bank transaction lists | 5,120 | Names, residential addresses, transfer amounts, dates, some IBANs |
| Institutional correspondence | 291 | Names, postal addresses, ID documents, source-of-funds records, and in some cases public Bitcoin addresses |
| Not affected | — | Private keys, bitcoin holdings, full transaction histories; KYC profiles outside the 291 |
You can rotate a password. You cannot rotate a transaction history
Bitcoin's privacy model has never depended on addresses being secret. Every address and every amount is public by design; that is the point of a public ledger. What the model depends on is the link — the mapping between an address and a human being — not existing anywhere an adversary can reach.
A breach that hands over that mapping does not leak one data point. It retroactively de-anonymises everything the address has ever done and everything it will do next. And unlike a password, an email address, or even a bank account number, it cannot be reissued. The customer can move their coins to a fresh address, and should. The old chain of transactions stays public, stays linked to their name, and stays that way permanently.
Pocket, to its credit, has not tried to minimise this. The company flagged the practical consequence itself: with names, addresses, and genuine transaction details in hand, a fraudster can construct a phishing approach — by post, phone, or message — that references a real transfer the victim actually made. It also restated the line that matters most in that scenario, and put the emphasis in its own copy: Pocket Bitcoin is a non-custodial service and will never ask you for your seed phrase.
The company says it has notified Swiss data protection authorities and the police, and that, as things stand, it has no indication that any of the affected information has been misused.
This is the second time in three weeks
The uncomfortable part is that Pocket is not an outlier. On August 17, Israel's largest regulated crypto broker, Bits of Gold, disclosed a breach reached through a flaw at an analytics provider, and the exposed set there also paired names and national ID numbers with public wallet addresses. Two brokers, two different root causes, three weeks apart, same category of harm.
Set those beside the hardware-wallet leaks of the same month — 39,798 SafePal customers, 13,689 Trezor customers via a fulfilment partner — and a pattern is visible that the industry's vocabulary is not equipped to describe. Every one of these incidents can be, and was, announced with the sentence "no customer funds were affected." Every one of them is true. And in the Pocket and Bits of Gold cases, that sentence is describing the least important thing that happened.
Compliance built the file that leaked
There is one more thread worth pulling, because it is the part nobody has a clean answer to.
Look at what was in the 291-person set: identity documents, source-of-funds records, correspondence with partner banks. None of that exists because Pocket wanted it. It exists because anti-money-laundering rules require a regulated broker to collect it, verify it, and retain it. The source-of-funds file is a compliance artefact. So is the bank correspondence. So, frequently, is the wallet address — brokers are increasingly expected to record where customer withdrawals go.
Which means the regulatory regime designed to make crypto traceable for law enforcement also mandates the assembly, at thousands of small companies, of exactly the dossier an attacker would most want: verified identity, verified address, verified funds, and the on-chain destination. The obligation to build it is explicit. The obligation to defend it, in practice, is whatever the company's support-desk vendor happened to configure.
Pocket did the disclosure properly — fast, public, updated three times as the scope grew, with the bad news in its own words rather than a regulator's. That is better than most. It also demonstrates the limit of doing it properly: the file existed, so the file leaked.
The Take
"Non-custodial" answers exactly one question — can this company lose my coins? — and the industry has spent years letting it stand in for a much broader assurance it never made. Pocket could not lose a single satoshi and it still produced the most dangerous category of leak there is, because the threat to a bitcoin holder was never only that someone takes the coins from a server. It is that someone learns your name, your street, and how much you are holding, and decides that is worth a visit. If you were in the 291: move the coins to addresses that leak has never seen, and treat every unsolicited contact referencing a real transaction as hostile until proven otherwise. If you were not: notice that four separate companies told you this month that your funds were safe, and that in at least two of those cases the funds were never what was at stake.