en

Bitcoin activity, passports exposed after Revolut falls for fake government request

image
rubric logo Security

A fake government email slipped through security controls at digital banking giant Revolut late Friday, exposing residential addresses, identity documents and bitcoin transaction histories belonging to a wide group of customers.

The request appeared to come from a legitimate government agency and carried credentials that passed Revolut’s checks. The company handed over customer information before separately contacting the agency and discovering that the request was fraudulent, according to notices sent to affected users.

The files reportedly included passports or driving licences, verification selfies, names, dates of birth, occupations, home addresses, emails, phone numbers, IBANs, account statements, withdrawal records and full transaction histories, including all bitcoin activity.

Revolut has yet to disclose how many customers were affected, and did not immediately respond to a CoinDesk request for comment on the matter.

it said in its email that customer funds remained safe and has since notified affected users and regulators and blocked the source of the request.

The weak point was authorization. Once the request cleared Revolut’s internal checks, someone posing as a government official gained access to the same deeply personal information the bank had collected to satisfy identity and compliance requirements.

Such breaches gets harder in an AI-heavy internet.

Convincing emails, documents, identities and bureaucratic requests are becoming cheaper to produce at scale, while financial companies continue to hold increasingly detailed records about who their customers are, where they live and how they move money.

The breach also gives privacy technologies such as zero-knowledge proofs a more immediate use case. ZK systems can allow someone to prove that an identity check was completed, or that a customer satisfies a particular requirement, while revealing less of the passport, address or other underlying information used to establish it.

Read More: The privacy paradox: regulating zero-knowledge finance in the EU and beyond

Bitcoin makes the contrast especially clear. Its blockchain records transactions publicly, while personal details such as a passport, home address or occupation sit outside the network. Financial intermediaries can connect those two sets of information, turning a customer database into a map linking a real person to their onchain activity.

Onchain investigator ZachXBT, who drew attention to the incident, said in a Telegram broadcast that the breach appeared limited in size and may have targeted high-net-worth users.

As AI makes impersonation easier, the security question is shifting from how well institutions protect customer data to how much sensitive information they need to collect, retain and reveal at all.