A fraudulent government email bypassed security filters at prominent digital banking institution Revolut recently, leaking home addresses, identity verification documents, and bitcoin transaction records belonging to a broad segment of clients.
The inquiry seemed to originate from a valid state body and featured credentials that successfully cleared Revolut’s verification protocols. The business transmitted user details prior to independently contacting the agency and realizing the demand was fake, based on notifications delivered to impacted clients.
The exposed documents allegedly contained passports or driver’s licenses, confirmation selfies, full names, birth dates, professions, residential addresses, electronic mail addresses, phone numbers, IBANs, financial statements, cash-out logs, and comprehensive transaction histories alongside all bitcoin operations.
Revolut has not yet revealed the exact volume of impacted clients and did not immediately reply to a CoinDesk request for a statement.
The company noted in its communication that client funds stayed secure and has subsequently alerted impacted users and regulatory authorities while cutting off the origin point of the inquiry.
The vulnerability lay in authorization. Once the demand passed through Revolut’s internal verification, an individual acting as a state representative obtained entry to the exact intimate data the institution had gathered to comply with identity verification and regulatory rules.
Such security failures become more frequent in an internet dominated by artificial intelligence.
Persuasive emails, paperwork, personas, and official communications grow less expensive to generate extensively, whereas banking institutions continue maintaining increasingly granular archives regarding customer identities, residences, and financial movements.
The security breach also provides privacy-enhancing tools like zero-knowledge proofs an increasingly pressing application. ZK protocols enable an individual to demonstrate that a background check finished successfully, or that a user fulfills a specific criterion, while exposing less of the passport, location data, or alternative foundational records utilized to verify it.
Read More: The privacy paradox: regulating zero-knowledge finance in the EU and beyond
Bitcoin highlights this contrast quite sharply. Its ledger chronicles transfers openly, while personal identifiers such as passports, residences, or jobs remain outside the network. Financial middlemen can bridge those two datasets, converting a user repository into a blueprint connecting an actual identity with their blockchain footprint—which bad actors might exploit to single out major bitcoin owners.
On-chain investigator ZachXBT, who highlighted the event, mentioned via a Telegram broadcast that the incident seemed restricted in scope and could have focused on wealthy accounts.
As artificial intelligence simplifies impersonation, the core security dilemma moves away from how effectively companies safeguard client data toward the total volume of private information they must gather, store, and disclose in the first place.
Originally published at https://www.coindesk.com/tech/2026/09/12/bitcoin-activity-passports-exposed-after-revolut-falls-for-fake-government-request.