
Revolut gave away the file that wrench attackers shop from
Revolut handed a complete customer file to somebody who sent a fake government request, CoinDesk reports. Onchain investigator ZachXBT raised the incident on Telegram this week. The company says customer funds are safe, that it has notified affected users and regulators, and that it has blocked the source of the request.
“The breach appeared limited in size and may have targeted high-net-worth users.”
— ZachXBT, Telegram, 11 September 2026
ZachXBT, onchain investigator
Funds being safe is the wrong measure. What left the building was the passport or driving licence, the verification selfie, the name, date of birth and occupation, the home address, email and phone number, the IBAN, account statements, withdrawal records and the full transaction history including every bitcoin movement. A bank card can be reissued in a week. A passport photograph next to a home address and a confirmed balance cannot be recalled at all.
What the file is worth
That combination is the targeting file for one specific crime, the one this industry calls a wrench attack, and somebody keeps count of those, in a public list on GitHub:
- Jameson Lopp's public log holds 302 documented physical attacks on crypto holders since 2014.
- The count ran 36 in 2024 and 78 in 2025, a rise of 117%.
- It stands at 57 through the first 255 days of 2026, a pace of about 82 for the full year.
Revolut has not said how many customers were caught. ZachXBT reads the scale as small and aimed at wealthy accounts, and that is the worse version. A broad leak dilutes attention across thousands of names. A narrow one that already sorts by balance hands over a shortlist.
A technique four years old
The technique needs no exploit. Emergency data requests let police obtain subscriber information fast, without a judge, on the argument that somebody is in danger, and platforms answer them from a police email address. Criminals worked this out years ago: in 2021 and 2022 Apple, Meta and Discord all released user data to forged requests sent from compromised law enforcement accounts, and members of the Lapsus$ group sold access to those accounts. The FBI issued a formal warning about fraudulent requests in November 2024.
A four-year-old technique with a federal advisory attached worked on a bank that is applying for a US charter.
The second list this month
This is the second time this month that a list of confirmed crypto owners has escaped through a side door. The Trezor customer leak widened to 67,000 more buyers on 4 September, and it came through a fulfilment contractor rather than the wallet maker. Neither incident touched a private key, and both produced the same asset: a verified list of people who hold coins, with addresses attached.
For a Revolut customer the practical response is short. Assume the file is out, treat any call claiming to be from the bank or the police as hostile, and change what can still be changed, which is the phone number and the email rather than the face and the flat. Everyone else is left with 57 attacks in 255 days, and with how cheaply the list behind them now gets built.
Nothing here should be taken as financial advice; treat it as information to consider.

Comments (0)
No comments yet — be the first!
The market talks all day. We write when it says something
Short, and it tells you why it came
Related news
Most readTop 7
Silicon Valley Workers Are Wearing Noise-Cancelling Masks to Dictate AI Prompts
292AI





