Revolut Fell for Fake Request and Exposed Bitcoin Records
Revolut processed what looked like an official request and turned over Bitcoin trading histories plus personal details for multiple users. The request was fake, and the company only found out after the fact.
How the Forged Demand Got Through
The notice shared by on-chain investigator ZachXBT described a letter that carried the right letterhead and language. Staff treated it as legitimate and released the records. No court order or proper verification step caught the issue before data left the building.
Why does this keep happening at firms that handle real money and crypto flows? The answer usually sits in the gap between automated compliance tools and the people who still sign off on edge cases. One forged document was enough.
Why Bitcoin Transaction Trails Matter More
Bitcoin records are not just another line in a database. They link wallet addresses to names and KYC files, creating a permanent map that can follow users across chains and counterparties. Once that map leaves Revolut, it can land anywhere.
Traders who route size through the app now face the risk that their flow history sits in the hands of whoever sent the fake letter. This kind of thing took the whole setup by surprise and shows how a single approval can undo years of careful custody.
Broader Trust Issues for Fintech Crypto
Revolut built its crypto offering on easy onboarding and quick settlement. Users accepted that convenience came with the usual data storage. The breach undercuts that trade-off without any market move or regulatory change to explain it.
Similar incidents have hit other platforms when rushed compliance teams accepted documents that looked official. The pattern repeats because the cost of double-checking every request stays high while the penalty for moving too fast stays low until something leaks.
What Happens Next for Users and the Platform
Revolut has not released numbers on how many accounts were involved or whether the fake request targeted specific wallet sizes. Customers who saw the Telegram post are already asking for confirmation on their own records. The company will likely tighten its verification checklist, but the data already sits outside its control.
Anyone watching the space knows these slips rarely stay isolated. Follow-up requests, both real and fake, tend to arrive once word spreads that one worked. Platforms that store on-chain history alongside names become obvious targets.
The episode leaves open questions about how many other fintechs would catch the same forged paperwork today. Revolut's scale makes the miss stand out, yet the underlying process flaw exists across the sector. Watch for more platforms to publish updated data-request policies in the coming weeks, even if the fixes stay mostly cosmetic.