Security

Revolut Data Breach: What Bitcoin Miners Should Know

Revolut sent passports, selfies and Bitcoin histories to a fake government request. What leaked, why it matters on-chain, and what miners can do.

Revolut data breach thumbnail: passport, selfie, IBAN and Bitcoin history records passing an email-auth check to a fake request

What happens when a bank that holds your passport, your selfie and your full Bitcoin transaction history gets a convincing email from a government agency asking for all of it? The Revolut data breach answered that question this week. On September 12, 2026, Revolut confirmed to TechCrunch that it disclosed sensitive customer records to an unauthorized third party after receiving fraudulent requests sent from a legitimate government agency's email domain. The attacker never broke into Revolut's systems. They sent a request, and Revolut staff answered it.

If you buy hardware, pay power bills or cash out mining rewards through a regulated fintech, read this one closely. It covers what leaked, why a Bitcoin history hurts more to lose than a bank statement, and what you can control as a miner.

What did Revolut hand over in the data breach?

According to the notice Revolut emailed to affected customers, reviewed by TechCrunch, the exposed data included birth dates, postal and email addresses, phone numbers and copies of identity documents such as passports and driver's licenses. It may also have included verification selfies, account statements and transaction histories. CryptoSlate, working from the same notices, reported that occupations, IBANs, withdrawal records and Bitcoin activity were on the list as well.

Revolut said a "limited" number of customers were affected and that it had contacted them directly. It did not say how many people that is, which markets were involved, or which government agency's domain was used. Its spokesperson said "Revolut systems and customer funds are unaffected," and no report so far says passwords, card PINs or private keys were included. On-chain investigator ZachXBT, who first publicized the notice, said the incident appeared to target high-net-worth users.

How did a fake request get past the checks?

CryptoSlate reported that the fraudulent email passed SPF, DKIM and DMARC, the three standard checks that confirm a message really was sent by the domain it claims to come from. That points to an attacker using an unauthorized mailbox inside the agency's real email infrastructure, rather than a lookalike address.

Every automated check passed. Revolut skipped a step outside email: a phone call to a known number at the agency, or a check against an existing legal process, before the files left the building. Revolut says it discovered the fraud after contacting the agency separately, then blocked the sender and alerted regulators and law enforcement. It has not said whether that outside confirmation now happens before disclosure rather than after. Former Mt. Gox CEO Mark Karpelès argued that naming the compromised agency would let other banks and exchanges check whether the same mailbox had written to them too.

Why is a Bitcoin history worse to leak than a bank statement?

A bank statement describes money that has already moved. A Bitcoin transaction history describes addresses, and addresses live on a public blockchain forever. Once someone can tie a verified name, home address and face to a single withdrawal address, they can often follow that coin forward and backward through the chain and estimate what else the same person holds.

That makes phishing far harder to spot. A message that quotes your last withdrawal amount, the exact address it went to and your IBAN reads like it came from your bank. A caller who already knows your passport number sounds official. If you hold a large balance, a known home address plus an estimated balance also puts your physical safety at risk.

What should a Revolut customer who mines Bitcoin do right now?

Start with the notice itself. Revolut is contacting affected customers individually, so a security email or in-app message from Revolut is the clearest signal you were on the list. If you received one, treat any unsolicited call, email or chat that recites your account details as hostile until you have checked it inside the Revolut app, never through a link or number the message provides.

Next, look at the addresses those records could expose. Any address that received a withdrawal from a Revolut account should be considered linked to your identity from now on. Stop reusing it, and do not send new mining rewards or cold-storage deposits to it. Using a fresh address for every payout destination is standard Bitcoin hygiene, and it caps how far anyone can extend a leaked history.

Finally, if your mining payout address ever received a Revolut withdrawal or sent a deposit into Revolut, assume that address is now tied to your name in someone else's file.

What does a mining pool like NexusPool know about you?

Any record an institution holds is a record someone can trick it into handing over, so ask your mining pool the same question. Many pools ask for an account, an email address and a password, and some large custodial pools run full identity checks because they hold miners' balances and process withdrawals.

NexusPool takes a different route. There is no account and no password: you connect with a Bitcoin address as the worker username, and that address is also what the coinbase transaction pays when a block is found. There is no passport, selfie or IBAN on file, because the pool never holds a balance for anyone, so a forged request for identity documents would come back empty. The technology page explains how solo payouts go straight to the miner's own address at 0% pool fee, and Payout Preflight lets you check the coinbase output before a block exists. The pool's terms are public too, if you want to read exactly what is and is not promised.

What does a no-account pool not fix?

Privacy claims get overstated fast, so here are the limits. A payout address is public on-chain by design: anyone can see a coinbase transaction and the address it paid. Any server a miner connects to, including a pool's, sees the connection's IP address, the same as any website does. And the moment mined coins move to an exchange or fintech that verified your identity, that institution can link them to you, which is exactly the kind of record the Revolut incident exposed.

None of this changes a miner's odds either. The chance of finding a block depends only on your hashrate against the network's, identical at every pool, and this post is not financial or legal advice. A no-account pool does one narrower thing: it takes a pool off the list of places holding your passport, selfie and bank details.

Back to the opening question: when a convincing request reaches an institution, it can only hand over the records it chose to collect.

Trust nothing. Verify the request, not the email domain it came from.