Pocket Bitcoin leak just doxxed 291 users. The chain remembers.
Pocket Bitcoin's breach went deeper than reported. Copied support records linked real names to Bitcoin activity for 291 customers. Private keys stayed safe. Anonymity didn't.
Here's the thing about Bitcoin. It's not anonymous. It's pseudonymous. And sometimes a compliance leak comes along to remind everyone of that difference.
Pocket Bitcoin's Aug. 21 breach disclosure just got a lot worse. The Swiss non-custodial service updated its story on Aug. 31. The news: copied support records exposed real-world identities for 291 customers. Some records matched names directly to Bitcoin wallet activity.
Chronology
Let's walk through this like a timeline, because the details matter.
Aug. 21. Pocket Bitcoin tells users it had a security incident. Initial read: email addresses and support conversations exposed. Annoying. Embarrassing. Not catastrophic, or so it seemed.
Then came the Aug. 31 update. That's when the picture sharpened.
The company said correspondence with partner banks contained varying combinations of identity data. Name. Location. Compliance records. Different users got different levels of exposure. Some got the full package.
And the worst part? Some of those copied records linked real-world identities directly to public Bitcoin activity.
Look, I've been saying this for weeks. Compliance data is the soft underbelly of crypto. You can secure private keys all day. But the KYC file in a support ticket? That's the target.
Impact
Let's be clear about what didn't happen. Private keys stayed safe. Customer funds stayed safe. Pocket Bitcoin is non-custodial, so there wasn't a giant pool of coins to drain.
But the damage is still permanent.
Once a name is matched to an address, you can't unmatch it. The chain doesn't lie. It doesn't forget either. Every transaction that address ever made is now part of a public record tied to a real person.
We're talking 291 people. That's not a rounding error. That's a real cohort of Bitcoin users who thought pseudonymity was enough protection.
How much of someone's life can you reconstruct from a Bitcoin address? Salary. Spending habits. Political donations. Who they transact with. All of it, if you dig long enough.
So no, the funds being safe doesn't make this okay. Real talk: money you can't lose is worth less than privacy you can't get back.
This is bigger than people realize. Because it's not just Pocket Bitcoin. Every exchange, every wallet provider, every DeFi front end with a support ticket system is sitting on the same kind of data.
Outlook
So what comes next?
For the 291 affected users? Honestly, not much they can do. The genie's out of the bottle. They can rotate addresses. They can use coinjoin. But the link between name and old activity is already public knowledge.
For the rest of us? This is a wake-up call.
If you're using a service that holds your KYC data alongside your wallet addresses, you're exposed. Non-custodial doesn't mean no data. It means no custody. Those support records are still a honeypot.
I expect we'll see more of these compliance record leaks. Not because companies are careless, but because attackers figured out where the valuable data lives.
And regulators? They're watching. A leak like this gives them cover to demand even more compliance, even more data collection. That's the irony. The response to privacy leaks is usually less privacy.
So here's my take. If you're still holding meaningful bags in addresses linked to your identity, change your setup. Privacy isn't a feature. It's a discipline.
The chain doesn't lie. But you can decide what the chain says about you.