Key Takeaways:
- Revolut needed to share delicate knowledge about its customers after receiving a phishing request that appeared authentic from an official consultant from the federal government.
- Data revealed have been copies of a passport, a driver’s license with verification selfies, full Bitcoin transactions and residential deal with.
- Blockchain investigator ZachXBT acknowledged that the incident appears small in scale however may have focused high-net-worth crypto customers.
Revolut is claimed to have needed to reveal delicate consumer knowledge, akin to data linked to Bitcoin transactions, after a complicated impersonation try. This incident is especially vital because it reveals an incapacity for a monetary platform to stick to trust-based safety checks on a authentic authorities e-mail.

Revolut Falls for Fraudulent Authorities Request
The discover warned clients that Revolut had been despatched a request from a legitimate authorities physique, claiming to include buyer particulars.
This request was comprised of an unauthorized e-mail deal with on the company’s official area. It additionally had legitimate area authentication credentials and Revolut handled the communication as an genuine authorities request. That call led to disclosure of buyer data previous to discovery that the request was a fraud.
The information that was disclosed was in varied classes akin to private knowledge, contacts, identification and monetary knowledge. The data, based on the discover, comprised customers’ full names, postal addresses, e-mail addresses, date of delivery and occupation, and phone numbers.
Learn Extra: Revolut to Delist USDT by August amid Risk Concerns
Bitcoin Transaction Histories Amongst Uncovered Information
The monetary data is particularly noteworthy for crypto customers. The leaked paperwork contained account statements, IBANs, account standing, pockets reference numbers, withdrawal historical past and full transaction data, together with Bitcoin transactions, stated Revolut.
There have been additionally ID paperwork. Among the many uncovered data was data meant to enrich pictures and copies of passports or driver’s licenses. Particularly it acknowledged that biometric facial telemetry knowledge was not in it.
This leaves a possible vulnerability in real-world identities and cryptocurrency operations. An individual’s identification paperwork, deal with, telephone quantity and so forth. are sometimes saved off-chain whereas Bitcoin transactions are saved publicly, on-chain.

ZachXBT Flags Attainable Concentrating on of Rich Crypto Customers
Blockchain investigator ZachXBT introduced wider consideration to the incident by means of a group alert on Telegram. He stated the variety of affected customers was probably restricted however instructed the incident appeared to have been focused at high-net-worth people.
It’s a element that would additional add to the problem going through crypto customers with vital Bitcoin transactions of their Revolut accounts. Linking transaction knowledge with ID and placement would give attackers a complete profile of a consumer’s monetary and onchain historical past.
Revolut has knowledgeable the people concerned within the fraud in response to the invention. The corporate additionally claimed the occasion wasn’t linked with any clients’ funds being stolen.
As per the case, there’s one other mannequin of crypto safety threat wherein an attacker needn’t compromise a blockchain or non-public key. Accessing the offchain data linking a Bitcoin consumer to his or her exercise may also current vital risks to bitcoin holders.
Learn Extra: $5.87M Ethereum Exploit Hits TrustedVolumes as 1inch Denies Any Protocol Breach

