Swiss Bitcoin services provider Pocket Bitcoin says a completed forensic investigation into its August security incident found that records involving 5,411 customers were exposed — significantly expanding the scope described in its initial disclosure — including bank transaction lists and, for a smaller group, identity documents and source-of-funds records.

The company, which operates on a noncustodial basis and does not hold customers' private keys, said its customer databases, transaction systems, and customer Bitcoin remained directly unaffected. The exposed material sat in copies of bank correspondence stored inside a compromised support system.

Two Data Groups, Two Risk Profiles

The investigation identified two distinct groups. The larger one contains transaction lists that partner banks sent to Pocket Bitcoin during compliance checks, covering 5,120 customers. Those lists included names, residential addresses, transfer amounts and dates — and in some cases the IBAN connected to a transfer.

The smaller group covers correspondence Pocket Bitcoin sent to partner banks, affecting 291 customers. Depending on the case, the exposed material included names, postal addresses, public Bitcoin addresses, copies of identity documents, and source-of-funds records. Pocket emphasized that the data appeared in different combinations, so not every customer in the group had every data type exposed. Affected customers have been contacted individually with specifics of their cases.

Customers whose email addresses or support conversations were affected under the original August disclosure should continue to rely on that notice, the company said — the two new groups are additional.

Why a Noncustodial Breach Still Hurts

No exposed Bitcoin address can authorize a transfer, and Pocket's noncustodial structure means customer coins were never accessible to the attacker. But the combination of data creates risks that custody architecture cannot solve. Linking a public Bitcoin address to a verified identity lets anyone inspect that address's visible blockchain history — and moving funds does not erase it.

The more concrete threat is physical-world phishing. Because names, postal addresses, and genuine bank-transfer details were exposed together, Pocket flagged forged letters and impersonation calls as particular risks: a fraudster can reference a real transaction to make an approach sound credible. The company said it currently has no indication that any of the affected information has been misused, while noting that this reflects the post-investigation picture rather than a guarantee about the future.

Email addresses and login credentials were not part of the two newly identified groups, so Pocket said it does not see a direct targeted email-phishing risk arising specifically from these records.

Regulators Notified, Police Report Filed

Pocket Bitcoin reported the incident to Switzerland's Federal Data Protection and Information Commissioner and to Liechtenstein's Data Protection Office, and has filed a police report. It did not identify a suspected attacker or detail the status of the investigation. The vulnerability behind the incident has been closed, additional safeguards installed, and the company is reviewing how bank correspondence and compliance records are stored and transferred, with further details promised in coming weeks.

The disclosure lands in a season of third-party data exposure across crypto's periphery: Trezor's shipping-provider breach now implies roughly 80,700 affected customers, and a separate August incident at Bits of Gold potentially exposed customer identity, banking, and wallet information through a third-party system. The common lesson is that compliance and logistics data — collected precisely because regulators require it — forms a durable targeting map long after the transactions it documents.

Affected users should monitor bank activity tied to exposed IBANs, treat unexpected letters, calls, or messages referencing real transfers with suspicion, and remember the baseline rule: Pocket says it will never ask customers to disclose a seed phrase or transfer Bitcoin through an unsolicited call or letter.

TrustGrade tracks the security posture of brokers, exchanges, and infrastructure providers — including how they handle the data around the coins. Verified, registry-backed scores arrive with TrustGrade Code Scoring in December 2026.