Guides
Sep 15, 2026

Revolut Handed Over Passports and Bitcoin Histories. Nobody Hacked Anything.

A spoofed government email got Revolut to release KYC files and full Bitcoin transaction histories. No server was breached. The lesson is about who holds the file, not about Revolut.

Revolut Handed Over Passports and Bitcoin Histories. Nobody Hacked Anything.

On 12 September 2026, Revolut confirmed it had disclosed a set of customer records to someone who asked nicely from the right email address.

The request arrived from a mailbox operating inside a real government agency's domain, carrying valid domain authentication. It passed every automated check an email is supposed to pass, because on paper it was legitimate mail from a legitimate domain. Staff treated it as the law-enforcement order it appeared to be and released what was asked for.

What went out: passport copies, verification selfies, full names, dates of birth, contact details, IBANs, withdrawal histories — and full Bitcoin transaction histories. Reporting indicates the request was aimed at high-net-worth users rather than scraped at random. Revolut says account passcodes and login credentials were not included, blocked the sender once the request was identified as fraudulent, and notified the agency, the police, financial regulators and data protection authorities.

No server was breached. No password was cracked. No malware was involved. The data left through the front door because there was a front door, and behind it sat a file with everything in one place.

The part worth generalising

It is tempting to read this as a story about Revolut's controls, and there is a version of that story worth telling. But the more useful question is the one that applies to every custodial account you hold:

What could this company be tricked into handing over about me?

For a custodial crypto account the answer is fixed, and it is known in advance. To operate legally, the provider must collect and retain a government ID, a biometric selfie, your address, and a complete record of your transactions. That bundle is a regulatory requirement. It is not optional, and it does not expire when you stop using the account.

Which means the bundle exists whether or not anyone ever attacks it. Social engineering, an insider, a misconfigured database, a subpoena real or forged — these are different routes to the same file. Reduce the odds on one and the others remain.

What self-custody actually changes

A non-custodial position has no such file.

There is no operator holding your passport, because no operator was required to see it. There is no support desk that can be persuaded to release your account history, because there is no account in the sense that a bank means it — only a keypair you control and a contract that does not know who you are. A spoofed subpoena addressed to a smart contract accomplishes nothing, because there is nobody there to read it and nothing on file to hand over.

That is the narrow, specific claim, and it is worth being precise about it:

self-custody removes the central file, not your exposure.

Here is what it does not do:

  • It does not make you anonymous. On-chain activity is public and permanent. Anyone can read your position sizes, your counterparties and your timing, and chain-analysis firms are good at linking addresses to each other.
  • It does not remove KYC from your life. If you bought your crypto with a card or a bank transfer, an exchange or a licensed provider already holds your ID and knows the address you withdrew to. Moving on-chain afterwards does not unwind that.
  • It does not eliminate risk, it relocates it. You take on key management, and there is no password reset. Losing a seed phrase is final in a way that losing a banking password is not. Smart contracts can also fail, and a protocol exploit is its own category of loss.

Anyone who tells you self-custody makes you invisible is selling something. The honest version is smaller and still valuable: there is no single document set, sitting in one company's systems, that can be released in one mistake.

The file is the liability

Revolut is not an outlier here, and picking on any one company misses the pattern. Once identity documents are collected, they accumulate somewhere and they persist — usually with a third-party verification vendor rather than the brand you actually signed up with.

That secondary layer has its own track record. In November 2025 researchers found an identity-verification provider's database sitting on the open internet with no password, holding names, addresses, dates of birth and national ID numbers at a scale measured in hundreds of millions of records. In July 2024 a verification vendor serving crypto projects lost the passports, driving licences and facial images of tens of thousands of users to a compromised operator account, in an incident that lasted about two hours.

Neither of those companies is one most affected users had heard of. That is the point: you cannot audit a vendor you were never told about, and you did not choose it.

We have written separately about what happens to your ID after you upload it, including which incidents are documented and which are widely misreported.

What to actually do

Nothing here argues for abandoning regulated services. Fiat has to enter somewhere, and a licensed provider with real controls is the correct place for that to happen.

What it argues for is being deliberate about the split:

  1. Use custodians for what only custodians can do — converting fiat, and holding the working balance you would be annoyed but not damaged to lose.
  2. Move long-term positions to self-custody. The balance you would be genuinely hurt by losing should not depend on someone else's email hygiene.
  3. Assume anything you have already uploaded is permanent. You cannot un-send a passport scan. Plan on the basis that it exists somewhere indefinitely, because it does.
  4. Treat any unexpected contact as hostile, including contact that appears to come from an authority. The Revolut request passed authentication. Yours might too.

At JewelSwap, positions are non-custodial by construction. We do not hold your assets, we do not collect your identity documents, and we could not release either if someone asked us convincingly, because neither exists on our side. That is a design property rather than a promise about our staff — which is rather the point of this article.


Sources: The Block, CryptoBriefing, The Crypto Times, Cybernews, The Block on Fractal ID. Nothing in this article is financial advice.

About the author.