Swiss Bitcoin trading service Pocket Bitcoin has disclosed a data breach that exposed personal information linked to more than 5,400 users. The company said the incident involved customer data stored in its internal database, with the exact scope varying from one user to another.
Pocket Bitcoin said the compromised information included email addresses, customer inquiry records, and bank transfer-related details. For some customers, the exposed data also included identification documents, residential addresses, proof-of-funds materials, and Bitcoin addresses used in transactions.
Attack detected in mid-August
According to the company, it detected the intrusion on Aug. 16 and moved to block the attacker’s access to its systems. A few days later, on Aug. 19, Pocket Bitcoin said it confirmed that personal information had been copied from its internal database.
The company said affected users were notified individually and told which categories of data were involved in their cases. It added that the compromised data set was not identical across all impacted accounts.
What was and was not exposed
Pocket Bitcoin said the breach reached a range of customer records tied to its business operations. Across the affected group, exposed information included email addresses, past inquiry records, and details related to bank transfers.
For a subset of users, the incident was more extensive. In those cases, the copied information also included document copies used for identification, home addresses, proof-of-funds materials, and Bitcoin addresses associated with transactions.
Company says funds and keys were not affected
Pocket Bitcoin stated that no users’ Bitcoin or private keys were compromised in the incident. It said this was because the platform operates as a non-custodial service and does not hold customer assets or private keys.
That distinction narrows the reported impact to personal data rather than direct access to customer funds, based on the company’s account of the breach.
Remediation and next confirmed steps
After identifying the breach, the company said it fixed the vulnerability, added further security measures, and completed a forensic investigation. It also reported the incident to Switzerland’s federal data protection authority.
Pocket Bitcoin said there is currently no evidence that the leaked personal information has been used for crimes or other malicious purposes. For now, the clearest confirmed developments are the completed internal response steps and the individual notifications already sent to affected users.
Source: en.bloomingbit.io