FacebookTwitterLinkedInTelegramCopy LinkEmail
Crime

Revolut Exposes Bitcoin Activity in Fake Request Incident

Revolut Exposes Bitcoin Activity in Fake Request Incident

A reported Revolut data disclosure linked identity records with Bitcoin activity, creating a targeted-fraud risk beyond account access.

Key Takeaways

  • Revolut reportedly acted on a fake request.
  • Identity and Bitcoin-related records were included.
  • No private-key exposure has been reported.
  • The main risk is targeted impersonation.

The problem began with a fake legal request

CoinDesk reported that Revolut notified affected users after responding to an emergency government request it later determined was fraudulent when it contacted the relevant authority. The reported disclosure included personal and Bitcoin-related records.

The incident was not described as an attacker taking over a wallet or breaking into a customer account. Instead, the failure appears to have occurred while Revolut was verifying a request for customer data. That makes it different from a typical exchange hack: sensitive information may be released without an attacker first defeating a user’s password or two-factor authentication.

The notice was shared publicly on X. Revolut had not published a wider public statement or disclosed the number of affected accounts at the time of writing, so the incident’s scale remains unclear.

Why Bitcoin records raise the stakes

CoinDesk reported that the material included identity documents, account information, withdrawal records and Bitcoin-related transaction history. The customer notice did not indicate that private keys, seed phrases or direct access to customer funds had been exposed.

What the reported records could enable
Reported record Practical risk
Passport or identity document More convincing identity-verification and account-recovery scams.
Contact and account details Messages tailored to resemble a bank, exchange or compliance team.
Bitcoin activity or withdrawal history A way to identify people likely to hold crypto and refer to genuine past transactions.

Blockchain records do not contain passport details. The risk begins when a regulated platform’s records connect transactions to a verified identity. If reported wallet references, withdrawal details or transaction identifiers can be matched with public blockchain activity, that link may remain useful to attackers after an account password is changed.

Safe funds do not end the risk

This was not a custody breach in the usual sense. But a detailed identity-and-activity profile can support months of fraudulent contact. An attacker who knows a person used Bitcoin, has their contact information and can cite a genuine withdrawal has a far more credible basis for a fake support or compliance message.

That is the same risk identified after the Bits of Gold customer-data breach: even when assets and private keys remain inaccessible, identity and wallet-related records can make impersonation attempts much more convincing.

A scammer does not need a seed phrase to exploit this information. They may instead ask for a one-time code, claim a wallet must be moved to a “secure” address, or direct a victim to a clone of a legitimate support page. The useful response is caution, not a rushed transfer.

Not every Bitcoin record identifies a public wallet

Revolut says it maintains an internal ledger for customer crypto exposure. For that reason, the reported Bitcoin transaction history may refer to activity recorded inside Revolut rather than a complete list of public blockchain addresses.

The distinction matters. Revolut should clarify whether the data included external wallet addresses, transaction identifiers, destination information or only internal account history. These create very different levels of exposure and would determine how easily an attacker could connect a customer’s real identity to visible on-chain activity.

The available evidence supports a narrower conclusion: no private-key leak has been reported, but the stated combination of identity documents and crypto-related records creates a distinct security concern.

What Revolut users can do now

Users who received a Revolut notification should confirm it through the app’s support channel or by visiting Revolut directly, rather than following links in an email or social-media post. They should ask which exact data fields were disclosed and retain a copy of the response.

Revolut users who have not received a notice do not need to move assets or assume their data was exposed. They should watch for an in-app message or a notification sent through Revolut’s verified channels, review the security of their recovery email and phone number, and be especially cautious of unsolicited messages that mention crypto withdrawals or ask them to “secure” a wallet. Changing a password can protect account access, but it does not undo an identity-data disclosure, so the priority is to prevent impersonation rather than make rushed transfers.

Anyone concerned that identity-document data may be involved should treat unsolicited account-recovery, compliance and wallet-verification messages as high risk. No legitimate agent needs a seed phrase, password or one-time authentication code. The European Data Protection Board lists fraud, identity theft and financial loss among the possible consequences of personal-data breaches.

The next answer needs to be about linkability

Revolut now needs to explain whether the disclosed records included external wallet addresses, transaction identifiers or only internal account history. That distinction will determine whether affected customers face a conventional identity-fraud problem or a more durable link between their real identity and publicly traceable Bitcoin activity.


This article is for informational purposes only and does not constitute legal, financial or cybersecurity advice.

Author
Kosta Gushterov, journalist in Coindoo.com

Reporter at Coindoo

Kosta has reported on cryptocurrency markets and blockchain infrastructure since 2020, bringing over six years of hands-on experience in the crypto industry built through daily tracking of markets, trends, and emerging blockchain developments. Specializing in Bitcoin on-chain analysis, institutional ETF flows, and digital asset price action, his work at Coindoo has been cited by other news agencies and consistently covers market developments with a focus on data-driven reporting across Bitcoin, Ethereum, Solana, and XRP. Over the years, Kosta has contributed to multiple crypto media outlets in different regions, authoring over 6,000 articles across the sector. His reporting spans cryptocurrency markets and the broader fintech industry, tracking not only price action but also the technological and regulatory forces shaping the ecosystem. To support his analysis, Kosta actively leverages on-chain data and metrics from leading platforms such as Santiment, Glassnode, and CryptoQuant, enabling deeper, evidence-based market insights. He believes in the power of transparency and the data that underpins the blockchain ecosystem. His academic background in Marketing Management from Denmark further complements his analytical approach, adding a strong understanding of communication strategy and content positioning to his work.

Learn more about crypto and blockchain technology.

Glossary