Loading prices...
All news
A cracked identity card with a bitcoin coin leaning against it on a dark red-lit poster background

Revolut gave away the file that wrench attackers shop from

13:00 · 13.09.2026
Source: CoinDesk
1

Revolut handed a complete customer file to somebody who sent a fake government request, CoinDesk reports. Onchain investigator ZachXBT raised the incident on Telegram this week. The company says customer funds are safe, that it has notified affected users and regulators, and that it has blocked the source of the request.

The breach appeared limited in size and may have targeted high-net-worth users.

ZachXBT, Telegram, 11 September 2026

ZachXBT, onchain investigator

Funds being safe is the wrong measure. What left the building was the passport or driving licence, the verification selfie, the name, date of birth and occupation, the home address, email and phone number, the IBAN, account statements, withdrawal records and the full transaction history including every bitcoin movement. A bank card can be reissued in a week. A passport photograph next to a home address and a confirmed balance cannot be recalled at all.

What the file is worth

That combination is the targeting file for one specific crime, the one this industry calls a wrench attack, and somebody keeps count of those, in a public list on GitHub:

  • Jameson Lopp's public log holds 302 documented physical attacks on crypto holders since 2014.
  • The count ran 36 in 2024 and 78 in 2025, a rise of 117%.
  • It stands at 57 through the first 255 days of 2026, a pace of about 82 for the full year.

Revolut has not said how many customers were caught. ZachXBT reads the scale as small and aimed at wealthy accounts, and that is the worse version. A broad leak dilutes attention across thousands of names. A narrow one that already sorts by balance hands over a shortlist.

A technique four years old

The technique needs no exploit. Emergency data requests let police obtain subscriber information fast, without a judge, on the argument that somebody is in danger, and platforms answer them from a police email address. Criminals worked this out years ago: in 2021 and 2022 Apple, Meta and Discord all released user data to forged requests sent from compromised law enforcement accounts, and members of the Lapsus$ group sold access to those accounts. The FBI issued a formal warning about fraudulent requests in November 2024.

A four-year-old technique with a federal advisory attached worked on a bank that is applying for a US charter.

The second list this month

This is the second time this month that a list of confirmed crypto owners has escaped through a side door. The Trezor customer leak widened to 67,000 more buyers on 4 September, and it came through a fulfilment contractor rather than the wallet maker. Neither incident touched a private key, and both produced the same asset: a verified list of people who hold coins, with addresses attached.

For a Revolut customer the practical response is short. Assume the file is out, treat any call claiming to be from the bank or the police as hostile, and change what can still be changed, which is the phone number and the email rather than the face and the flat. Everyone else is left with 57 attacks in 255 days, and with how cheaply the list behind them now gets built.

Nothing here should be taken as financial advice; treat it as information to consider.

Published: 13:00 · 13.09.2026
Maks

Author

Maks

Trading man

I've been interested in the cryptocurrency market for a long time, am a trader, and write articles and news about my experience and crypto in simple terms.

Comments (0)

No comments yet — be the first!

The market talks all day. We write when it says something

Short, and it tells you why it came