Revolut, the British fintech giant that serves 80 million customers worldwide, has disclosed that it handed over sensitive customer data — including passport information and Bitcoin transaction histories — to an unauthorized party impersonating a legitimate government agency. The incident, revealed Saturday, underscores a growing vulnerability in the crypto industry: it is often not the blockchain that fails, but the humans and institutions guarding the front door.
According to the disclosure, an attacker used a fraudulent email domain designed to mimic official government correspondence, convincing Revolut staff to release know-your-customer (KYC) records and transaction data tied to affected accounts. Among those reportedly notified was Mark Karpelès, the former Mt. Gox operator, and the breach was flagged publicly by onchain investigator ZachXBT. Revolut notified affected customers on Friday, a day before the broader disclosure became public.
A Familiar Pattern of Trust Exploited
Revolut’s case is not an isolated one. It follows closely on the heels of two other data incidents in the crypto space: a breach at hardware wallet maker SafePal affecting roughly 39,798 customers, and an incident tied to Trezor’s fulfillment partner ShipMonk that exposed data for around 67,000 US customers. In each case, the attackers didn’t need to crack cryptographic keys or exploit smart-contract bugs — they exploited trusted channels, whether a shipping vendor’s systems or, in Revolut’s case, the assumption that an email from a government-looking domain is what it claims to be.
This is a meaningful distinction for readers to understand. Much of the public conversation about crypto security focuses on exchange hacks, wallet drains, or protocol exploits. But as identity verification becomes mandatory across regulated fintechs and exchanges, the KYC data collected to satisfy regulators has itself become a prime target. When that data includes a customer’s Bitcoin transaction history, an attacker doesn’t just get a name and a document scan — they get a roadmap to a person’s crypto holdings and financial behavior.
For a company like Revolut, which straddles both traditional banking and crypto trading, the stakes are especially high. The firm has been pushing aggressively into new territory: it recently received conditional approval from the US Office of the Comptroller of the Currency to form a national bank, is rolling out its EURR euro-denominated stablecoin in Denmark, Poland and Portugal, and has been expanding its Revolut X crypto trading platform with AI-driven features. Each of these moves signals ambition to become a full-spectrum financial institution — but this breach is a reminder that expansion into regulated banking does not automatically bring the security discipline that regulators, and customers, expect.
What This Means for Users and the Industry
For everyday Revolut customers, the immediate concern is exposure: if identity documents and crypto transaction histories fell into the hands of a bad actor, the risk extends beyond simple phishing. High-net-worth or high-profile crypto holders — the kind of customer whose transaction history reveals meaningful holdings — become targets for social engineering, extortion attempts, or physical security threats, a risk category the industry has increasingly had to reckon with as crypto adoption grows among wealthier individuals.
More broadly, the episode raises questions about how fintechs verify the authenticity of government requests. Unlike a phishing email sent to a retail customer, this attack targeted an internal process — the mechanism by which a regulated company responds to legal or regulatory inquiries. If that channel can be spoofed at a company with Revolut’s scale and resources, smaller platforms with fewer compliance staff may be even more vulnerable.
The timing also matters. Revolut is simultaneously trying to build trust as a fiat-crypto bridge — its stablecoin rollout and banking ambitions depend on regulators and customers believing its data-handling practices are sound. Competing narratives are playing out elsewhere in the industry, too: Nubank, for instance, has been expanding its own stablecoin-powered global account beyond Latin America, illustrating how central data integrity and regulatory trust have become to any fintech’s crypto strategy.
What to Watch Next
- Whether Revolut discloses the full scope of affected customers and markets, which remains undisclosed at this stage.
- Any regulatory response from UK authorities, given Revolut’s headquarters and its pending banking ambitions in other jurisdictions.
- Whether affected customers report follow-on attacks, such as targeted phishing or extortion attempts tied to leaked transaction histories.
- How Revolut adjusts internal verification procedures for government and regulatory requests going forward.
The broader lesson extends past Revolut. As data breaches at SafePal and Trezor’s fulfillment partner show, the crypto industry’s weakest link is increasingly not the blockchain itself but the surrounding infrastructure — customer support desks, shipping vendors, and compliance inboxes — that hold the keys to real-world identity. Readers interested in how this specific incident has been reported elsewhere can find additional coverage in earlier pieces on the exposed passport and Bitcoin data and how Revolut was tricked into leaking customer data.
Source: The Block
This content is for informational purposes only and does not constitute financial or investment advice.




Create a free account to comment and earn rewards.
Create account Log in