On Saturday 12 September 2026, Revolut handed a stranger passport copies, verification selfies, home addresses and full Bitcoin transaction histories. It did this deliberately, through the front door, because the stranger asked from the right email domain.
The disclosure surfaced through a customer notification circulated by the on-chain investigator ZachXBT. Per that notice, Revolut received a request for customer information that appeared to come from a government agency, sent from an unauthorised account on the agency’s own official domain. Because the message carried valid domain authentication credentials, Revolut fulfilled it believing it genuine. A spokesperson called it “a sophisticated external impersonation scam” using “a legitimate government agency domain email”, said a “limited” number of customers were affected, and declined to say how many or which agency was impersonated.
TL;DR
- Revolut disclosed passports, selfies, addresses, statements with IBAN and wallet reference numbers, and full transaction history including Bitcoin, after a fraudulent request arrived from a genuine government agency domain.
- The only cryptography in the chain was aimed at the wrong claim: domain authentication proves a message left a particular domain, and it was asked to stand in for proof that the sender held a lawful power to compel disclosure.
- A lawful disclosure and this one leave the same trace on your side of the relationship: none that you can read. The defect is architectural, not moral.
- In email the envelope is signed and the decision is not. On a blockchain the envelope is irrelevant and the decision is signed, checked by everyone before state changes.
- Satoshie’s raffles and coinflips verify a Chainlink VRF proof on-chain before the payout callback can act, and hold no passport, no selfie and no dossier to disclose to anybody’s inbox.
What the checks actually checked
Be precise about what “valid domain authentication credentials” can mean. The SPF, DKIM and DMARC machinery guarding modern email answers one question well: did this message really leave the domain it claims, through infrastructure that domain authorised. Here, yes. The mail was not spoofed. It came from the agency, sent by an account inside the agency’s domain that had no business sending it.
Notice the question that machinery never asks. It does not ask whether the sender holds a statutory power to compel a bank to disclose a customer’s file, or whether a request is scoped, proportionate or real. It authenticates the envelope. Somebody then treated an authenticated envelope as evidence of an entitlement, and the entitlement was the only part that mattered. Nor is that a Revolut-specific stupidity: requests like this reach banks, exchanges and custodians in their thousands and get assessed on plausibility, a human judgement wearing a protocol built to verify something else.
The half everybody asked
Within hours the reaction had settled into a familiar shape. Aave’s Marc Zeller, one of those notified, put it bluntly: “Sharp reminder that KYC hasn’t produced meaningful upside and has put many in harm’s way.” ZachXBT noted the incident appeared to target high net worth users, which matters given the wave of violent “wrench attacks” on known holders. Good argument, and also the consent question: should this data have been collected at all. Consent questions get asked because they come with a villain attached. The mechanism question does not.
The sixtieth unasked half of fairness
Here is the mechanism question. What artefact does a regulated firm have to verify before it hands over your file, and is that artefact something you could ever check?
The answer today is: an email, and no.
Follow that, because the consequence is worse than the incident. Revolut’s disclosure to a fraudster and a perfectly lawful disclosure to a real investigator leave an identical trace on your side: nothing. No entry, no notice, no receipt. Revolut can tell them apart because it went back and asked the agency. You can tell them apart only because somebody chose to write to you. So the honest statement of your position is not “my data was leaked once”, it is “I do not know how many times my file has been disclosed, to whom, or on what authority, and there is nowhere I can look”.
Ten days ago in this series I wrote about Tether freezing roughly $42.4m of USDT on an informal request, the seizure warrant arriving around three months later. That defect was ordering: the action permitted before the instrument. There the authority was real and late; here it never existed and nobody could tell.
Sign the thing that decides
Crypto people will reach for “this is why self-custody” and stop there, which wastes the lesson. The interesting part is an inversion. In email, the envelope is cryptographically signed and the decision is not. On a blockchain, the envelope is unsigned and irrelevant, and the decision is signed. Anyone can relay your Bitcoin transaction, including somebody impersonating your wallet provider, and it changes nothing, because the authority to move those coins is a signature over the spend itself and every node checks it before state changes. The envelope is untrusted on purpose. The entitlement is verified by everyone.
None of that is exotic, and the fix is dull. An agency could publish a key and sign its disclosure requests. A firm could publish a signed log of the fact a disclosure happened, contents withheld, so the count stayed auditable when the substance is sealed. Not hard, just not built.
None of this says law enforcement should have no route to customer records, only that the route should be a verifiable artefact rather than an email header. Nor is it an accusation against Revolut’s staff, who followed the process they had. The process passed. That is the finding.
Earlier instalments sat on other axes: Trezor’s shipping-provider breach counted the surfaces holding your data, the wrench-attack figures covered what a leak does to you afterwards. This one is about the moment of disclosure itself.
The casino knows who you are, and you do not know who it told
Every licensed online casino holds a dossier on you: identity document, selfie, address, source of funds, and every stake you have ever placed. It is more intimate than your bank’s, because a betting history is a behavioural profile. The only reason you assume it has not already gone to somebody with a convincing letterhead is that nobody has sent you a letter.
Meanwhile the site’s “provably fair” page invites you to audit the dice against a scheme the house designed. Nothing there audits the filing cabinet, and nothing can. Verifying the game while the operator holds an unauditable record of your life is auditing the one part that was never going to hurt you.
Satoshie puts both halves in the architecture instead of a promise. The raffle contract is deployed before entries open, the Chainlink VRF coordinator is named in the deployed code in public before anyone stakes, the proof is verified on-chain before the callback may act, the winner is computed in that callback, the payout lands in the same transaction, and no admin key can reassign a result. On this axis the relevant fact is duller: no passport, no selfie, no address, no dossier, because an address stakes and an address is paid. Nobody can email us for a file we never asked you for, and no inbox instruction can make the contract pay somebody else.
What we cannot claim
We run a domain and an inbox, and we could be socially engineered exactly as Revolut was. The front end is an ordinary web app and the least trustworthy thing we ship. Base has a company-operated sequencer, and we decide who can load the interface. The claim is narrow: the disclosure surface is small because the collection is small, not because we are clever.
Three questions worth asking any provider
- What is the smallest set of facts you need about me to run this service, and what do you hold beyond it?
- If a convincing request for my file arrived tomorrow, what artefact would you verify, and where could I read that a disclosure happened?
- When something here is described as cryptographically verified, is the thing verified the envelope or the decision?
Revolut says its systems and customer funds were unaffected, and that is true. The systems did exactly what they were built to do. A stamp that reads “checked” is only worth something if you know which claim it was pressed against.
📷 Photo by Markus Spiske (@markusspiske) on Unsplash


