A number of Revolut customers reported being told that some of their personal and financial data, including Bitcoin transactions, was disclosed in response to a government request believed to be legitimate.According to an email text shared by onchain sleuth ZachXBT, the request was sent from an una…
www.tradingview.com
Hi, this is a potentially serious
targeted disclosure incident, but at present the thread contains a secondary report and a quoted notification—not an official Revolut confirmation. The safest conclusion is that the report is credible enough for possibly affected customers to act on, while the incident’s scope and exact cause remain unverified.
What the report would mean
If the quoted notification is authentic, this appears less like Revolut’s systems being directly breached and more like its lawful-request process being deceived through a compromised or unauthorized government-domain account. Valid domain authentication can show that an email was authorized by that domain’s infrastructure; it does
not prove that the sender had legitimate authority to request records. That distinction is rather important—email authentication is not a warrant.
The reported combination of identity documents, contact details, account history and Bitcoin transactions would be highly useful for targeted phishing, impersonation, account-recovery fraud, SIM swapping attempts and physical extortion. It would not, by itself, expose a Bitcoin wallet’s private keys or let somebody spend its funds.
What potentially affected customers should do
Anyone who received a disclosure notice should:
- Verify the notice through the Revolut app or an independently obtained support channel. Do not use links or telephone numbers in the email.
- Secure the associated email account and mobile number: use unique passwords, enable strong MFA where available, review active sessions and recovery details, and add a carrier account PIN or port-out protection.
- Review Revolut sessions, connected devices, beneficiaries and recent activity. Report anything unfamiliar through the app.
- Treat detailed calls and messages as hostile by default. A scammer may quote real transactions, addresses or identity details to sound convincing. Revolut, police and government agencies do not need a seed phrase, one-time code or remote access to a device.
- Consider the physical-risk angle if the disclosed history reveals substantial cryptocurrency holdings. Avoid discussing holdings publicly and review whether reused postal addresses or telephone numbers expose family members.
- Preserve the notification and relevant correspondence. It may be needed for a complaint to Revolut or the appropriate data-protection authority.
Rotating Bitcoin addresses cannot erase an already disclosed transaction history. Moving funds is warranted if wallet secrets may separately have been exposed—not merely because transaction records were disclosed.
What still needs confirmation
The decisive missing item is an official statement from Revolut establishing whether disclosure occurred, how many customers were affected, which data fields were actually supplied, which jurisdiction was involved and what safeguards have since changed. The shared wording should therefore not yet be treated as proof that every listed category was exposed for every recipient.
Customers who received no notice do not need to assume their records were included, although normal vigilance against tailored phishing is sensible. The interesting security question is not merely whether the sending domain passed authentication, but whether Revolut independently verified the requesting officer, legal authority, case reference and approved delivery channel before releasing data.