Pocket Bitcoin, a Swiss service that lets people buy Bitcoin, exposed records that linked 291 customers’ identities to their public Bitcoin addresses. That means real names could be matched directly to on-chain activity, a serious privacy problem even when no coins are stolen.
What Pocket Bitcoin exposed in the reported records
The core issue is simple. Records tied 291 individual customers to public Bitcoin addresses they used, according to Pocket Bitcoin’s own security incident notice. For related coverage, see Bitcoin Moves Above $79,000, Nearing $80,000 as BTC Momentum Builds.
Linking an identity to an address means connecting a person’s name to a string of characters that receives and sends Bitcoin. Once that link exists, anyone who sees it can tell which address belongs to which person. For related coverage, see Bitcoin Liquidation Cluster Builds Near $70.7K and $78K as Leverage Returns.
Reporting on the incident described leaked compliance records that matched names directly to wallet activity for the affected users, as detailed by CryptoSlate. This article sticks to those stated facts, because the underlying research is limited. For related coverage, see Bitcoin Traders Cheer April Gains, but One Fed Date Could Reverse the Rally.
Why linking identities to Bitcoin addresses is a serious privacy issue
Every Bitcoin address is public. Anyone can look up an address on a blockchain explorer and see its full transaction history, including balances and past transfers. For related coverage, see SEC proposes transfer agent rule changes for tokenized securities.
By design, an address is just a number, not a name. That pseudonymity is the privacy layer. When a name gets attached to an address, that layer disappears for that person.
So the danger here is exposure, not theft. No one reported stolen coins. Instead, the linkage can reveal how much someone holds and how they move money, which many holders reasonably want to keep private.
Privacy advocate Jameson Lopp has long warned about how easily on-chain data can be traced back to individuals, in his public writing on Bitcoin privacy. This incident is a concrete example of that risk.
What affected customers and Bitcoin users should watch next
The confirmed facts are narrow. We know 291 customers were affected and that their identities were tied to public addresses.
Several questions remain open. It is not clear from the available evidence exactly how the records leaked, how long they were exposed, or whether anyone misused them.
Pocket Bitcoin operates under Swiss anti-money-laundering rules, which require services to collect customer identity data, as outlined by Switzerland’s financial regulator FINMA. That is why such firms hold the identity-to-address links in the first place.
For a practical takeaway: if you buy Bitcoin through any regulated service, understand that the company keeps a record connecting you to the addresses you use. One way holders reduce exposure is by moving funds to a fresh address after buying, a step commonly discussed in cases where on-chain funds are traced.
Affected customers should watch for direct notifications from Pocket Bitcoin and any follow-up statements on remediation. Future disclosures will show whether the exposure was contained and what safeguards change next.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.