The event is not a network intrusion in the conventional sense, and no Bitcoin was moved on-chain.
Revolut has told reporters that customer know-your-customer records and Bitcoin transaction data were exposed to an unauthorized third party after fraudulent requests arrived from a legitimate government agency email domain, a disclosure incident that leaves account holders’ identity documents and on-chain histories in unknown hands even though the company says its systems and customer funds were untouched.
The event is not a network intrusion in the conventional sense, and no Bitcoin was moved on-chain. Instead, it is a data-disclosure failure at one of Europe’s largest fintech platforms, and it carries a specifically Bitcoin dimension: the exposed material reportedly included wallet reference numbers and transaction histories, the kind of information that can degrade the pseudonymity that underpins Bitcoin’s privacy model for individual holders. For related coverage, see Revolut Data Breach Exposes Passports and Bitcoin Records.
WHAT TO KNOW
- Revolut says customer KYC and Bitcoin transaction data were exposed to an unauthorized third party.
- The reported exposure followed a fake request that arrived from a government agency email domain.
Revolut says customer KYC and Bitcoin transaction data were exposed
Revolut confirmed to TechCrunch that it disclosed sensitive customer information to an unauthorized third party after fraudulent requests reached it through a legitimate government agency email domain. Know-your-customer, or KYC, refers to the identity-verification records financial firms are required to collect and hold on their users.
TechCrunch reviewed a notification sent to affected customers that listed identity and contact details, including birth dates, postal and email addresses, phone numbers, and copies of identity documents such as passports and driving licences. The notification said the disclosed data may also have included verification selfies, account statements and transaction histories, categories that should not be assumed present for every affected customer.
According to the customer notice as reported by crypto.news, the potentially disclosed account statements included Bitcoin wallet reference numbers and the transaction histories included Bitcoin transactions. The original notice was not independently authenticated, and crypto.news reported it was initially shared by on-chain investigator ZachXBT.
A Revolut spokesperson said a limited number of customers were affected and contacted directly, but did not disclose an exact count, the affected markets, or the government agency involved. Revolut also said its systems and customer funds were unaffected, an assurance that speaks to fund custody and infrastructure but does not establish that the disclosed personal information cannot later be misused. The parallels to earlier reporting on how KYC data and Bitcoin histories were exposed underscore that the risk here is informational rather than custodial.
Fake request from a government domain preceded the reported exposure
The exposure followed what Revolut described as a fraudulent request that arrived from a legitimate government agency email domain. According to crypto.news, Revolut characterized the request as carrying valid domain authentication credentials, and the notice did not explain how the sender obtained access to the agency domain.
The supplied context does not identify the domain, the agency, the country, the request channel, or the verification process Revolut applied before responding. A message originating from a government domain does not by itself establish government involvement, and the available reporting does not show who controlled the address or how the request succeeded. Similar uncertainty surrounded coverage of how Bitcoin activity was exposed in the fake-request incident.
Revolut said it blocked the email address and alerted the government agency, law enforcement and relevant regulators. Those are company statements rather than independently confirmed regulator findings, and reporting on how passports and Bitcoin histories were disclosed after the request did not verify the technical access method.
What remains unclear about the Revolut data exposure
Several material details are absent from the current reporting. The affected-customer count, the affected jurisdictions, the identity of the government agency, the date of the fraudulent requests, and the date Revolut became aware of the problem all remain unknown, as does whether every listed data category applied to each notified user.
Under UK data protection rules, the distinction matters. The Information Commissioner’s Office defines a personal data breach to include unauthorized disclosure or sending personal data to an incorrect recipient, so a network compromise is not required for an incident to qualify. Its guidance says a notifiable UK GDPR breach must be reported without undue delay and within 72 hours of awareness where feasible, and that Article 33(5) requires documentation of all breaches, their effects and remedial action, regardless of whether regulator notification is required.
That documentation standard is a reporting gap worth watching. Blocking the requesting address and stating that funds are unaffected do not, on their own, complete the accountability record the guidance describes; the sources do not establish the applicable jurisdiction, notification dates, or any specific regulator investigation. Details Revolut may have shared privately with customers or regulators are separate from what public reporting currently confirms. Earlier accounts of the passports and Bitcoin data reportedly obtained by attackers similarly left these questions open.
For Bitcoin holders, the enduring concern is linkage. Wallet reference numbers and transaction histories tied to verified identities can be used to cluster and de-anonymize addresses, an outcome that no difficulty adjustment or hashrate figure can reverse. Bitcoin traded around $77,168 at research time, little changed on the day, with no evidence connecting the disclosure to price action; the network’s monetary properties are intact, but the privacy exposure sits entirely off-chain, where the ledger’s immutability offers no remedy.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.