Home>Blog>Revolut Leaked Passports and BTC History. Your Perp Exchange Might Be Next.
Revolut Leaked Passports and BTC History. Your Perp Exchange Might Be Next.

Revolut Leaked Passports and BTC History. Your Perp Exchange Might Be Next.

By CMM Team - 13-Sep-2026

Revolut Leaked Passports and BTC History. Your Perp Exchange Might Be Next.

On September 11, 2026, blockchain investigator ZachXBT shared a Revolut customer notification on Telegram revealing that the fintech giant had handed over passports, identity selfies, and complete Bitcoin transaction histories to hackers posing as a government agency. The attackers didn't crack a database. They sent a spoofed email from what appeared to be a legitimate government domain, and Revolut complied with the request.

For crypto traders, the breach is more than a headline. It's a reminder that every passport scan, every verification selfie, and every transaction record you upload to a centralized platform becomes a permanent liability you can't retract. When that data leaks, it doesn't just enable phishing. It can enable physical violence. Chainalysis reported that more than $30 million was stolen through violent "wrench attacks" against crypto holders in just the first half of 2026, with 46 documented incidents through late June.

This article breaks down what happened at Revolut, why KYC data is becoming the most dangerous attack surface in crypto, and what the shift toward no-KYC perpetual exchanges like Hyperliquid means for traders who want to protect their identity while keeping their edge.

What Revolut Actually Leaked

The breach wasn't a sophisticated zero-day exploit or a brute-force attack on encrypted databases. It was social engineering. An unauthorized third party sent requests from a spoofed government agency email domain that passed standard authentication checks. Revolut treated these as legitimate law enforcement requests and fulfilled them.

The data handed over included passport and driver's license copies, identity verification selfies, full names, dates of birth, occupations, postal addresses, emails, phone numbers, bank statements with IBANs, withdrawal records, and complete Bitcoin transaction histories. Revolut confirmed that private keys, login passwords, and full card numbers were not compromised, and that biometric facial telemetry was not included.

The critical detail: Bitcoin transaction histories were leaked alongside home addresses. An attacker now knows exactly how much BTC someone moved, when they moved it, and where they live. That combination is the prerequisite for a wrench attack.

Former Mt. Gox CEO Mark Karpeles publicly confirmed he was among those affected, sharing a copy of the notification Revolut sent. ZachXBT noted the breach appeared to specifically target high-net-worth users, though Revolut declined to disclose how many customers were affected or which government agency was impersonated.

Kyc Data Attack Surface

From Data Breach to Doorstep: The Wrench Attack Pipeline

The reason this breach matters more than a typical data leak is the specific combination of data types. A leaked email address enables phishing. A leaked password enables account takeover. But a leaked passport plus BTC transaction history plus home address enables a fundamentally different category of crime.

Chainalysis documented 46 violent incidents targeting crypto holders through late June 2026, with more than $30 million stolen. Home invasions now account for 37% of these attacks, up significantly from prior years. If the pace continues, 2026 will surpass the $58 million full-year record set in 2025.

France has become the epicenter, recording 30 publicly known violent crypto incidents through mid-2026. Chainalysis linked the spike to an alleged 2024 incident where a French tax official in the Paris area reportedly stole and sold dossiers on high-net-worth crypto holders, including names, addresses, holdings, and tax records. The Revolut breach creates exactly the same data package for a different set of victims: identity documents, financial records, transaction histories, and physical addresses bundled together.

The attack pipeline is straightforward. Step one: acquire leaked KYC data that links wallet activity to a physical identity. Step two: filter for high-value targets by scanning their transaction histories. Step three: visit the address. The sophistication isn't in the attack itself. It's in the target selection, and that selection is only possible because centralized platforms hoard the data that connects on-chain activity to real-world people.

Wrench Attack Pipeline

Revolut Is the Latest. It Won't Be the Last.

The Revolut breach sits in a pattern that has been accelerating. In May 2025, Coinbase disclosed that bribed overseas support contractors had stolen the personal data of 69,461 customers, including government IDs, masked Social Security numbers, bank account numbers, and account balances. Coinbase estimated remediation costs between $180 million and $400 million.

Trezor, the hardware wallet maker, recently saw a support-vendor breach widen to expose additional thousands of customers. Ledger and Trezor users began receiving physical letters at their home addresses in early 2026, sent by attackers who obtained their shipping data from previous breaches.

The pattern reveals a structural problem. Every platform that collects KYC data creates a honeypot. The regulatory mandate to verify identity means these databases must exist, and they must contain the most sensitive categories of personal information: government-issued documents, biometric selfies, financial records. The question isn't whether any given platform will be breached, because given enough time and enough attack vectors (phishing, insider bribery, social engineering), the data will eventually leak. The question is how much damage that leak enables.

What This Means for Perp Traders Specifically

Perpetual futures traders face amplified risk from KYC breaches for three reasons that don't apply to casual spot buyers.

Leverage exposes your scale

A 10x leveraged position on a centralized exchange means your notional exposure is ten times your collateral. If an attacker sees that you deposited $50,000 and traded perps with consistent leverage, they can infer that your total market activity is significantly larger than the deposit alone. Transaction histories reveal trading frequency, position sizes, and by extension, your likely net worth, all tied to your passport and home address.

Frequency creates a trail

Active perp traders generate hundreds or thousands of transactions per month. Each one is a data point in a transaction history that, once leaked, paints a detailed picture of your trading behavior, schedule, and activity patterns. That data makes you a more identifiable and predictable target than someone who bought BTC once and held it.

Cross-platform KYC multiplies exposure

Many traders use multiple CEXes for different markets, deeper liquidity, or lower fees. Each KYC'd platform is a separate database, a separate attack surface, and a separate potential leak. The Revolut breach hit users who may not have even traded crypto on Revolut, because the platform requires KYC for all financial services. One breach anywhere in the chain compromises you everywhere.

The asymmetry is clear: perp traders generate more data, that data reveals more about their wealth, and they tend to KYC across more platforms. Each additional platform is another copy of your passport sitting on a server you don't control.

The Decentralized Alternative: Trade Without a Data Footprint

Decentralized perpetual exchanges operate on a fundamentally different model. There is no company holding your passport. There is no database mapping your wallet to your home address. There is no law enforcement request queue where a spoofed email can extract your entire financial history.

Hyperliquid, the largest decentralized perpetual exchange by volume, identifies users only by wallet address. No KYC, no email, no phone number, no passport upload. Every order, cancellation, and trade executes on-chain with one-block finality. The protocol supports more than 300 markets with leverage up to 40x, and it routinely processes over $200 billion in monthly volume.

The architecture eliminates the data honeypot entirely. If there is no database linking wallet addresses to real-world identities, there is nothing for a social engineer to request, nothing for a bribed contractor to exfiltrate, and nothing for an attacker to use for target selection. You can trade with the same depth and speed as a centralized exchange while keeping your identity separate from your on-chain activity.

This isn't a theoretical advantage. It's the core reason why decentralized perp volume has been growing. Hyperliquid's all-time cumulative perpetual futures volume has surpassed $4 trillion, and the platform currently commands roughly 44% of all on-chain perpetual futures volume. The shift isn't just about ideology. It's about risk management.

Cohort Data Without Identity Data

One concern traders raise about decentralized exchanges is whether the lack of KYC means losing access to institutional-grade analytics. It doesn't. On Hyperliquid, every position, every fill, and every liquidation is recorded on-chain. The data is public by design, because the blockchain is the ledger. What's missing is only the link between a wallet address and a human identity.

Our data at HyperTracker classifies every wallet on Hyperliquid into one of 16 behavioral cohorts: eight by portfolio size (from Shrimp at under $250 to Leviathan at $5M+) and eight by all-time PnL performance (from Money Printer at +$1M to Giga-Rekt at below -$1M). These classifications are computed from on-chain data, with no need for anyone to submit a passport or a selfie. One API call returns the aggregate positioning, order flow, and bias of any cohort across any asset.

This is what privacy-preserving analytics looks like. You get the same intelligence that institutional desks use for market structure analysis, specifically which cohorts are accumulating, which are unwinding, and where the consensus is shifting, all without anyone's personal identity entering the system. The wallet is the identity. The blockchain is the source of truth. Our analytics layer sits on top.

Track Smart Money Without Touching Identity Data

HyperTracker's 16 behavioral cohorts classify every Hyperliquid wallet by size and performance. Institutional-grade analytics, zero KYC data required.

Explore the API

Kyc Vs No Kyc Comparison

Practical Steps to Reduce Your KYC Exposure

Deleting your Revolut account won't undelete your data from the attacker's possession. But there are concrete steps perp traders can take to reduce their exposure going forward.

Minimize the number of platforms holding your documents. Every KYC'd platform is a separate copy of your passport on a separate server. Audit which platforms have your data and close accounts you no longer use. Under GDPR (Article 17), EU residents can request data deletion. Under CCPA, California residents have similar rights.

Shift perp trading volume to decentralized venues. Hyperliquid offers the same depth, speed, and leverage as centralized perp exchanges without requiring identity verification. If the core reason you trade on a CEX is liquidity, test whether decentralized venues meet your execution requirements.

Separate your identity from your on-chain activity. Use fresh wallets for decentralized trading that aren't linked to any KYC'd exchange. If you've previously withdrawn from a CEX to a wallet you also use on Hyperliquid, the on-chain link between your identity and your trading activity already exists. A clean wallet breaks that chain.

Monitor for breaches proactively. Services like HaveIBeenPwned track email-level exposure. For crypto-specific breaches, follow researchers like ZachXBT who surface incidents before companies disclose them. The Revolut breach was public via ZachXBT's Telegram on September 11, before Revolut issued a formal statement.

Assume the worst for existing data. If you've KYC'd on any platform that has been breached (or might be in the future), assume your identity documents are in circulation. Consider a credit freeze, monitor for unauthorized account openings, and be aware that your physical address may be linked to your on-chain history.

The Structural Shift

The Revolut breach isn't an isolated failure. It's a symptom of a system where regulators mandate identity collection and platforms become responsible for securing data that attackers increasingly know how to extract. The attack vector wasn't a software vulnerability. It was a human process, a team that followed procedure when they should have been suspicious, and the data existed in a form that could be handed over because regulations required it to be collected in the first place.

For perp traders, the calculus is changing. Centralized exchanges offer familiar interfaces and deep fiat on-ramps, but they come with a data liability that compounds every time you KYC on another platform. Decentralized exchanges eliminate that liability entirely, and with Hyperliquid's volume, liquidity, and market coverage, the performance gap has largely closed.

Your passport scan was never meant to be a target. But as long as it sits on a server you don't control, that's exactly what it is.