Pocket Bitcoin, a regulated non-custodial Bitcoin purchasing service based in Switzerland, disclosed that a security breach in its support system exposed personal data belonging to 5,411 customers. The company says no misuse of the compromised information has been detected so far.
The incident, which unfolded over roughly a week in mid-August 2026, involved unauthorized access to an internal database tied to Pocket Bitcoin’s customer support infrastructure. The company cut off the intruder’s access by August 16 and publicly announced the breach on August 21.
What was exposed, and what wasn’t
A detailed breakdown released on August 31 split the affected users into two groups. The first, comprising 291 individuals, had their correspondence with financial institutions compromised. That correspondence included names, addresses, and pieces of documentation, the kind of material that tends to surface during compliance exchanges with partner banks.
The second and much larger group, 5,120 customers, had transaction lists exposed. These lists, provided by partner banks, contained personal data tied to bank transfers.
The distinction matters. For the smaller group, the breach is meaningfully worse: their real-world identities could potentially be linked to their Bitcoin addresses.
Pocket Bitcoin stressed that no KYC profiles, full transaction histories, or customer funds were compromised. Because the service is non-custodial, meaning it never holds users’ Bitcoin, there was never a risk of direct financial loss from the breach itself.
How the breach happened
The unauthorized access was traced to Pocket Bitcoin’s support system, where conversations between users and support staff are stored. Investigators determined by August 19 that email addresses and support conversations had been copied from the internal database.
Pocket Bitcoin completed a forensic investigation and reported the breach to relevant authorities in both Switzerland and Liechtenstein, including law enforcement agencies. Every affected user received an individual notification about the exposure.
The privacy problem beneath the surface
As of the company’s most recent update on September 3, there have been zero confirmed cases of the exposed data being misused.
For the 291 users whose names, addresses, and documentation were compromised alongside their Bitcoin-related correspondence, the damage is potentially durable. If that information were to surface on darknet markets or be acquired by a motivated actor, it could be used to link specific individuals to specific Bitcoin transactions.
The broader group of 5,120 users faces a less acute but still meaningful concern. Transaction lists tied to bank transfers contain enough metadata to build profiles of purchasing behavior over time.

