Pocket Bitcoin, a Swiss non-custodial exchange, disclosed that a breach of its support system exposed personal data belonging to 291 customers. The leaked records include names, postal addresses, Bitcoin addresses, copies of identity documents, and source-of-funds information. The company said private keys were never compromised, so customer funds are not at risk — but the data links real-world identities to public Bitcoin activity, stripping away a layer of anonymity.
What was exposed
The affected data came from support correspondence stored in the exchange's helpdesk system. That's where the problem sits. The customer database and transaction database were not compromised, but related information — including payment amounts in some cases — was mixed into the support threads. When source-of-funds documents or payment discussions were involved, those details ended up in the exposed files.
Pocket Bitcoin is non-custodial, meaning it never held customers' private keys. So the breach doesn't put coins directly at risk. But the personal data is sensitive on its own. Identity documents and proof-of-funds records are exactly the kind of material that makes phishing scams harder to spot.
The correction
The initial disclosure on Aug. 21 said Bitcoin addresses and the customer database were not affected. That turned out to be too broad. An Aug. 31 update walked it back, clarifying that while the core databases were safe, related information had been included in some support correspondence. The company now says every affected customer received an individual notice listing exactly what data was exposed in their case.
Bitcoin addresses are public by design. Once a name and address are attached to one, the pseudonymity collapses. That's not a theoretical risk — it's a direct consequence of the leak. The data could also be used for phishing, since details from real support conversations make fraudulent messages look legitimate. A scammer who knows you asked about a withdrawal, or knows your source of funds, can craft a far more convincing email.
What Pocket Bitcoin did
The forensic investigation is complete, the vulnerability has been closed, and the incident has been reported to the Swiss Federal Data Protection and Information Commissioner. A police report was filed as well. The company says it has no indication the copied information has been misused, but it also notes that current visibility isn't a guarantee. That's a fair caveat — the data is out there, and the full consequences may not surface for months.




