Key Takeaways:
- Revolut had to share sensitive data about its users after receiving a phishing request that looked legitimate from an official representative from the government.
- Information revealed were copies of a passport, a driver’s license with verification selfies, full Bitcoin transactions and home address.
- Blockchain investigator ZachXBT stated that the incident looks small in scale but could have targeted high-net-worth crypto users.
Revolut is said to have had to reveal sensitive user data, such as records linked to Bitcoin transactions, after a sophisticated impersonation attempt. This incident is particularly significant as it shows an inability for a financial platform to adhere to trust-based security checks on a legitimate government email.


Revolut Falls for Fraudulent Government Request
The notice warned customers that Revolut had been sent a request from a valid government body, claiming to contain customer details.
This request was made from an unauthorized email address on the agency’s official domain. It also had valid domain authentication credentials and Revolut treated the communication as an authentic government request. That decision led to disclosure of customer information prior to discovery that the request was a fraud.
The data that was disclosed was in various categories such as personal data, contacts, identity and financial data. The information, according to the notice, comprised users’ complete names, postal addresses, email addresses, date of birth and occupation, and telephone numbers.
Read More: Revolut to Delist USDT by August amid Risk Concerns
Bitcoin Transaction Histories Among Exposed Data
The financial information is especially noteworthy for crypto users. The leaked documents contained account statements, IBANs, account status, wallet reference numbers, withdrawal history and complete transaction records, including Bitcoin transactions, said Revolut.
There were also ID documents. Among the exposed information was information intended to complement photos and copies of passports or driver’s licenses. Specifically it stated that biometric facial telemetry data was not in it.
This leaves a potential vulnerability in real-world identities and cryptocurrency operations. A person’s identity documents, address, phone number etc. are typically stored off-chain while Bitcoin transactions are stored publicly, on-chain.




ZachXBT Flags Possible Targeting of Wealthy Crypto Users
Blockchain investigator ZachXBT brought wider attention to the incident through a community alert on Telegram. He said the number of affected users was likely limited but suggested the incident appeared to have been targeted at high-net-worth individuals.
It’s a detail that could further add to the issue facing crypto users with significant Bitcoin transactions in their Revolut accounts. Linking transaction data with ID and location would give attackers a comprehensive profile of a user’s financial and onchain history.
Revolut has informed the individuals involved in the fraud in response to the discovery. The company also claimed the event wasn’t linked with any customers’ funds being stolen.
As per the case, there’s another model of crypto security risk in which an attacker need not compromise a blockchain or private key. Accessing the offchain information linking a Bitcoin user to his or her activity can also present significant dangers to bitcoin holders.
Read More: $5.87M Ethereum Exploit Hits TrustedVolumes as 1inch Denies Any Protocol Breach

