When a Phish Wears a Badge: How Revolut Handed Over Bitcoin Records to a Spoofed Inbox

By: Silas Sterling

(SeaPRwire) –   It turns out that a fancy corporate valuation and millions of global users mean very little when a basic email spoofing trick walks right through the front door. Revolut recently managed to hand over sensitive customer data, including full Bitcoin transaction histories, to an unauthorized actor simply because the incoming message wore an official government agency’s clothes. This was not some sophisticated zero-day exploit or a complex network breach. It was an email domain spoofing trick that bypassed standard authentication checks, exposing a catastrophic failure in basic verification protocols at a major digital banking platform.

The official narrative from the company notes that the disclosure happened because the fraudulent request looked entirely legitimate. The sender managed to use an official government agency’s email domain and successfully passed domain authentication checks, which apparently lulled internal compliance teams into a false sense of security. On-chain investigator ZachXBT brought the incident to light on Telegram on September 11, noting that the breach appeared relatively limited in scale and may have targeted high-net-worth users. Yet, the sheer volume of personal and financial information packed into that single compliance handover is staggering, stripping away the privacy of unsuspecting individuals in an instant.

Digging deeper into the exposed records reveals a massive privacy failure that goes far beyond a casual leak. The unauthorized party walked away with full names, dates of birth, occupations, postal addresses, email addresses, and phone numbers. Identity documents such as passports and driver’s licenses were compromised alongside verification selfies, though Revolut was quick to note that biometric facial telemetry data was excluded. On the financial side, the haul included account statements, IBANs, account-opening dates, withdrawal records, and complete transaction histories. Crucially, Bitcoin wallet reference numbers and full Bitcoin transaction histories sat right inside those leaked statements, effectively tying real-world identities to on-chain cryptocurrency movements for anyone caught in the crosshairs.

This security lapse arrives at a particularly awkward moment for the platform. Revolut secured conditional approval for a US bank charter from the Office of the Comptroller of the Currency on September 3, and recently launched its euro-backed stablecoin, EURR, to select European customers in August. While these aggressive expansions into traditional and crypto banking demonstrate rapid business growth, incidents like this expose a jarring disconnect between scaling up operations and maintaining ironclad operational security. If a financial institution cannot verify whether an inbound government email is authentic before shipping out passport copies and Bitcoin ledgers, its broader regulatory ambitions start to look remarkably fragile.

Author bio: Silas Sterling, a veteran kernel contributor and editor-in-chief of an open-source security digest, specializing in infrastructural vulnerabilities and digital privacy failures.