Revolut Data Leak Exposes Bitcoin (BTC) Transaction Records via Fake Government Request

Revolut answered a fake government request, exposing user data including Bitcoin (BTC) transaction records, as a Japanese tax-office USDC post went viral.

(09:46 AM UTC)
4 min read
AI SummaryAI
  • ZachXBT says Revolut may have shared user data after a fake law-enforcement email using an official domain.
  • Exposed records include passport copies, verification selfies, IBANs, withdrawal logs and Bitcoin transaction histories.
  • Revolut's security notice said biometric face telemetry data was not affected by the incident.
  • A Japanese X post about a ¥1 million USDC tax inquiry topped 6.9 million views in two days.
k7rq2fdm

ZachXBT Flags Revolut Customer Data Disclosure

Personal data belonging to a subset of Revolut customers may have reached unauthorized third parties after the fintech firm responded to what it believed was a legitimate government records request — a disclosure flagged by on-chain investigator ZachXBT. The episode began, per the investigator's account, when a customer-information demand arrived at Revolut that appeared to come from a state authority and carried the agency's official email domain. Because the message included valid domain-authentication credentials, the company accepted it as genuine and, failing to detect the request as a forgery, is believed to have answered it — potentially granting the sender access to files covering part of its user base.

The range of exposed material is wide. Potentially affected records span customers' full names, dates of birth, occupations, home addresses, email addresses and phone numbers, together with copies of passports or driving licenses, selfie images taken during identity-verification checks, account statements, IBAN details, withdrawal records and comprehensive transaction histories that include Bitcoin (BTC) transfers. In the security notice sent to affected customers, Revolut stated that biometric face telemetry data was not touched by the incident.

The current scale looks contained, but the risk profile is uncomfortable. ZachXBT noted that holders with large balances may have been the specific targets, since a full transaction history tells an attacker exactly how much a victim is worth on-chain. Several Revolut users have received security notifications connected to the episode in recent days, suggesting the company is still working through its alert list. Notably, this was not a hack in the conventional sense — no breach of Revolut's core systems has been reported. The failure was procedural: an authentication check that a well-crafted social-engineering email managed to satisfy, turning compliance-grade identity archives into targeting data.

A ¥1 Million USDC Question Goes Viral

A separate story shows how far disclosure demands can stretch on the other side of the counter. On September 10, an X user posting under the handle @fishing_kiyogon published a reenacted dialogue between a crypto holder and a Japanese tax office over a USDC transfer worth ¥1 million, and within two days the viral X post had accumulated roughly 7 million impressions, surpassing 6.9 million views and drawing more than 500 replies.

In the exchange, the tax official first asks where the ¥1 million in USDC was sent. The poster explains he moved the funds to another wallet he owns himself. The questioning continues through progressively weaker justifications — he wanted to change wallets, he wanted to change where the funds are managed, he moved them “just in case.” The comedic peak arrives when the official asks for the destination's “address,” the poster reads out his 0x wallet address, and the official replies by requesting “an address like Tokyo or Saitama,” exposing a complete breakdown in basic terminology between the two sides.

Whether the dialogue reflects a real audit or is fiction remains unclear, but it reads as a faithful reenactment of how crypto tax questions unfold. Japan currently classifies crypto gains as miscellaneous income under comprehensive taxation: combined national and local rates reach up to 55%, crypto-to-crypto swaps are themselves taxable events, and losses cannot be carried forward. Industry practitioners note that general-purpose tax accountants and officials often lack fluency in industry terminology, so crypto businesses frequently prepare explanatory materials in advance with their advisors. Reactions under the post ranged from empathy — the harder one explains, the wider the gap grows — to pushback from users arguing that officials this uninformed are rare today. The episode also lands amid growing Japanese interest in self-custody, visible in steady demand for hardware and mobile wallet options that let holders answer such questions from their own records. Readers tracking the market in real time can follow live spot and futures prices on Bybit.

Why Self-Custody Keeps Winning Converts

Taken together, the two episodes map the same pressure point from opposite sides. The Revolut incident shows that a custodian's KYC archive — IDs, selfies, withdrawal logs, BTC histories — is itself an attack surface when a spoofed official request slips past authentication filters. The viral Japanese exchange, documented in the primary post reviewed above, shows tax authorities demanding disclosure before grasping what a 0x address even is. Our read at COINOTAG: this dual friction steadily renews the appeal of self-custody infrastructure and of stablecoin settlement rails built for direct holder control, from Tether's Stable to Circle's Arc blockchain — a migration path the self-sovereign thesis of Bitcoin maximalism anticipated long before these headlines.

COINOTAG News Desk

COINOTAG News Desk

COINOTAG's editorial and research desk.

How our News Desk works
AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.