
Revolut Disclosed Bitcoin Records After Fraudulent Government Request
Revolut disclosed customer identities and Bitcoin transaction histories after responding to a fraudulent request that impersonated a government agency. The disclosure highlights gaps in the company's verification processes for data requests from authorities.
Written by CoinArticle’s AI Newsroom · from 2 cited sources. How we work
The Unauthorized Disclosure
Revolut disclosed customer data including Bitcoin transaction histories after acting on a fraudulent request that falsely appeared to originate from a government agency, according to a customer notice shared on Telegram by on-chain investigator ZachXBT. The company released customer identities and financial records without proper verification of the requester's legitimacy, suggesting inadequate authentication procedures for official data demands.
What Happened and Why It Matters
The incident underscores a structural vulnerability in how financial service providers validate law enforcement and regulatory requests. Revolut responded to the request as though it were legitimate, only later discovering it was fraudulent. The company's failure to verify the authenticity of the request before complying — despite having procedures theoretically in place — exposed customers' transaction data and personal information to an unauthorized third party.
For fintech firms and crypto-adjacent platforms holding customer financial records, the distinction between a real government demand and a forged one is supposed to be the foundation of data protection. Revolut's lapse suggests either those verification processes are insufficient or were not followed in this case. No statement from Revolut confirming or detailing the scope of the breach has been made public as of publication.
Why It Matters
For Traders
Users with Revolut accounts holding or trading Bitcoin should review account access logs and consider whether to move funds to self-custodied wallets until the company discloses full breach scope.
For Investors
The incident exposes operational risk at fintech platforms handling crypto assets and may prompt regulators to mandate stricter data-request verification standards across the sector.
For Builders
Platforms storing transaction data should implement multi-factor verification and signed requests for government data disclosures; self-custody and non-custodial infrastructure reduce this attack surface entirely.
This article is for information only and is not financial advice. Read the full disclaimer.



