Revolut Breached by Fake Government Subpoena, Exposing Bitcoin Wallet Activity
TREE NEWS reports: Revolut has disclosed a data security incident in which an employee responded to a forged legal request impersonating government law enforcement, handing over Bitcoin wallet transaction records and activity status to an unknown attacker. The fraudulent document claimed to be part of a criminal investigation and demanded the platform retrieve on-chain records for specific addresses. Because internal verification procedures were not strictly enforced, the request was fulfilled without confirming the authenticity of the legal paperwork.
What Was Exposed
The data disclosed includes what amounts to a “Bitcoin activity passport” — a transaction history that can be used to reconstruct a user’s broader financial behavior, counterparties, and timing patterns. On-chain data is public by design, but the linkage between addresses and a verified identity is the sensitive layer that exchanges and custodial platforms are expected to protect.
Why Social Engineering Keeps Working
- Trust in authority: Requests framed as criminal investigations create urgency and discourage pushback from junior compliance staff.
- Non-standard requests: Legitimate subpoenas follow formal channels; attackers exploit the gray zone of informal or partial documentation.
- Weak approval gates: Without mandatory multi-person sign-off and out-of-band verification with the issuing agency, a single employee becomes a single point of failure.
Industry Implications
The incident highlights a structural vulnerability across centralized crypto platforms: as they accumulate identity-linked on-chain data, they become high-value targets for impersonation attacks. Regulators in multiple jurisdictions are already tightening rules on data access, breach notification, and law-enforcement request handling. Firms that cannot demonstrate robust verification workflows face both regulatory scrutiny and reputational damage.
Forward-Looking Perspective
Expect a shift toward standardized legal-request intake systems, cryptographic verification of official documents, and mandatory dual-control approval for any disclosure of user-linked blockchain data. Insurance products covering social-engineering losses may also gain traction. For users, the event reinforces a familiar lesson: custodial convenience concentrates risk, and privacy in crypto depends less on the blockchain than on the operational discipline of the institutions holding the keys to identity.




