Published: Monday, 31 August 2026 · Pocket Ethereum
Updated: Thursday, 3 September 2026
On 21 August we published information about the security incident at Pocket Ethereum. At the time, we announced that we would contact customers personally if more than just their support correspondence was affected. Our investigation has since identified two distinct situations, which we describe separately below.
If you have not received a personal email from us, the information from our first blog post continues to apply to you.
What we have found#
Our investigation identified two separate groups of affected customers. They differ in how the data reached us, which data is affected, and what risks arise from it.
Group 1: Correspondence we sent to partner banks (291 customers)#
As a regulated company, we are required to verify identity and, for certain transactions, the origin of funds before a purchase or sale can take place. This includes the correspondence with the partner bank that processes a payment. Depending on the case, this ranges from a name to proof of identity and proof of origin. Part of this correspondence was stored in our support system, which was affected by the incident.
Our investigation has confirmed that 291 customers are affected in this way. What the correspondence contained varies from case to case: across the group, it includes names, postal addresses, ethereum addresses used for transactions, copies of identity documents, and source-of-funds documentation in varying combinations. For most people, it is only some of these details.
Group 2: Transaction lists that partner banks sent to us (5,120 customers)#
During compliance checks, some partner banks sent us overviews: time-bounded lists of bank transfers. These lists were kept in our support system and were part of the exposed data backup.
In this group, 5,120 customers are affected. The lists contained names, addresses, as well as individual bank transfers (including amount and date). In some cases, they also contained the IBAN of the bank account from which a transaction was made.
Our investigation of both categories is complete. Everyone affected will receive a personal email setting out exactly what was affected in their case.
What was affected: more details#
Our first post listed three things as “not affected”: ethereum addresses, the customer database including KYC data, and transaction history.
The distinction that matters is between our systems and the data itself: none of those systems were compromised, and that still holds, but data of those kinds was present in the correspondence that was exposed.
Our customers' ethereum was never at risk. A ethereum address is not access to funds but public information on the blockchain, and transferring ethereum requires private keys, which never leave our customers' devices. What changes as a result of the disclosure is that details about a person, for Group 1, for example, a ethereum address together with a name; for Group 2, a name together with an address and individual bank transfers, can be linked to one another.
Whether the data has been used#
As things stand, we have no indication that any of the affected information has been misused. That reflects what we can see today.
Am I affected?#
If you are affected, you will receive a personal email from us setting out exactly what was affected in your case and which of the two groups your case belongs to. If you have not received such an email, nothing applies to you beyond what we described on 21 August.
What we are doing#
- Everyone affected is being contacted directly and personally.
- The incident was reported to the Swiss Federal Data Protection and Information Commissioner (FDPIC) and, in accordance with the GDPR, to the Data Protection Office of Liechtenstein, and we have filed a report with the police.
- The forensic investigation is complete.
- We have already taken a number of measures and are working on further improvements, in particular regarding how data of this kind is handled and transmitted. We will share more about this over the next few weeks.
What matters most right now#
Because genuine details about affected people were disclosed, fraud attempts may appear more convincing than usual.
In both groups, the disclosed data is not linked to email addresses or login credentials. We therefore do not see a direct risk of targeted email phishing from it. However, because names and addresses were included, be particularly alert to forged letters and other mail. Fraudsters could refer to a real earlier transaction in order to appear more credible.
As a general rule, be suspicious of any message, whether by letter, phone or email, that pressures you to act quickly, demands a payment, or asks you to "verify" something. When in doubt, contact the organisation in question yourself through the official channels, rather than using the links or numbers provided in the message. Pocket Ethereum will never ask you for your seed phrase, and will never ask you by letter or by phone to transfer ethereum or to make a payment.
What happens next#
All further updates will be published here. We are aware that an incident like this shakes the trust you have placed in us, and to those whose data was disclosed, we offer our sincere regret.
The Pocket Ethereum Team
Frequently asked questions#
How does this fit with what you wrote on 21 August?#
On 21 August, we told you what we knew at that early stage and announced that we would provide further information as the investigation progressed. This update is that follow-up. Two categories have since become clear: correspondence we sent to partner banks (291 customers), as well as transaction lists that partner banks sent to us (5,120 customers). Our systems themselves (the customer database with KYC data, the transaction database) were not compromised; the data was disclosed through this copied correspondence and these lists.
Why did you have these documents in the first place? (Group 1)#
As a regulated company, we are required to verify identity and, for certain transactions, the origin of funds before a purchase or sale can take place. As part of this compliance process, we pass certain information on to the partner bank that processes a payment. This correspondence was stored in our support system, which was affected by the incident. We are currently reviewing and improving how we handle this kind of information.
I never sent you any documents. Why am I affected? (Group 2)#
In this group, the data does not come from documents you sent us. During compliance checks, some partner banks sent us overviews: time-bounded lists of bank transfers with customers' names and addresses. These lists were kept in our support system and were part of the exposed data backup. The fact that they contained data of people who did not provide it to us themselves is one of the points we are reviewing and improving in how we work with partner banks.
What does the disclosed IBAN mean for me?#
An IBAN is an account number, not access to your account. No one can use it to dispose of your balance. The IBAN was only included for some of the people affected in Group 2. Your personal email tells you whether this is the case for you.
Are my ethereum affected?#
No. Pocket Ethereum is non-custodial. Your private keys never leave your device, and we never have access to your funds.
Can someone see how much ethereum I own, and should I move it?#
If your ethereum address was disclosed (this concerns Group 1), someone who has it can view the amount and history of that address on the blockchain. Your ethereum address is public by nature; what is new, however, is that it can be linked to your name. Moving funds does not undo what is already on the blockchain, but it separates your future activity from the disclosed address. Either way, no one can move your ethereum with the disclosed information.
What about amounts? #
Our transaction database was not compromised. However, amounts were included in two places: in the correspondence and proof-of-origin documents in Group 1, and in the list of bank transfers in Group 2. For everyone outside these two groups, no purchase or sale data was affected.
Will there be more cases?#
Both known categories have been fully analysed: the correspondence forwarded to partner banks (291 customers) and the transaction lists received from partner banks (5,120 customers). Everyone affected is being contacted personally. We do not expect further categories. Should we, contrary to expectations, identify anything further, we will inform you here on our blog and contact those affected directly.
Is my future communication with Pocket secure?#
Yes. The vulnerability behind this incident has been closed and we have added further safeguards since, so any email or chat message you send us from now on is handled through our secured systems and is not affected by this incident. Buying and selling are unaffected and work as normal.
Can I ask you to delete my documents?#
We are legally required to retain customer- and transaction-related data and documents for a period of 10 years following the termination of the business relationship or the completion of a transaction. Unfortunately, it is therefore not possible for us to delete customer data within this retention period.
Who do I contact with questions?#
Because we are contacting a very large number of affected people at the same time, we cannot answer individual enquiries personally right away. We answer the most common questions here on this page. If you do not find your answer here, you can reach us at team@pocketethereum.com. Please understand that, given the number of people affected, it may take some time for us to get back to you. Our phone lines are currently busier than usual.