AVA Token Surges After Bithumb Listing
AVA token surged up to 112% intraday after Bithumb opened a Korean won trading pair, later settling at a 72% gain.
Revolut confirmed fraudsters used a legitimate government email domain to obtain customer data, including passports and bitcoin records.
Revolut has acknowledged that fraudsters deceived the platform into disclosing customer information, which the company's own alerts indicate included passport details, verification selfies and bitcoin transaction records.
The request arrived from an authentic government agency email domain and carried valid credentials. Believing it was legitimate, Revolut released the data.
A Revolut representative told BeInCrypto that the bank blocked the sender as soon as it identified the issue.
“Revolut recently identified a sophisticated external impersonation attack where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information… Revolut systems and customer funds are unaffected.”
The firm stated that it alerted the agency, the police, and its data protection and financial regulators. It has contacted the individuals it calls a limited number of affected people.
Accounts remain safe, Revolut insists. That is accurate. The bank told BeInCrypto that passcodes, login details and biometric data were never exposed. No funds were moved.
The notices sent to customers tell a different story. They state that the verification selfie was included, and only rule out biometric facial telemetry — the face template a system builds from a photo. The photo itself is a separate matter.
Those notifications list the rest: passports, driving licences, home addresses and bank statements. A complete record of bitcoin inflows and outflows.
Revolut declines to say which agency's domain was used, citing the ongoing police investigation. So nobody outside the company knows whether a government mailbox was hijacked or whether someone already inside it sent the request.
Blockchain investigator ZachXBT, who traces stolen crypto for a living, flagged the breach, noting that it reached a small group of users and appeared aimed at wealthy ones.
Woke up to all my data leaked by @Revolut.
— Marc Zeller (@mzeller) September 12, 2026
Sharp reminder that KYC hasn’t produced meaningful upside and has put many in harm’s way. pic.twitter.com/RimOBQr7DW
Stolen customer lists have fed phishing risks after breaches. Leaked home addresses have preceded violent attacks on holders.
Revolut has described this as a sophisticated attack. But by its own account, the attacker used a legitimate government email system to send a fraudulent request. Revolut accepted that request as genuine and released the data.
Share to
Disclaimer: this article comes from third-party media and is provided for reference only. It does not constitute investment advice. Crypto and other financial products carry significant price volatility risk, so please make your own decisions carefully.
AVA token surged up to 112% intraday after Bithumb opened a Korean won trading pair, later settling at a 72% gain.
Dan Hillery discusses how the Bitcoin-backed digital credit market, now at $16 billion, could eventually rival Bitcoin's $1.5 trillion market cap.
Ned Davis Research outlines seven ways to value Bitcoin, from network adoption to stock-to-flow, with long-term targets of $170,000 by 2030 and $230,000 by…
Banks are issuing stablecoins to retain payments market share as non-bank tokens reach $300B supply. Regulatory clarity and transaction volume drive the shift.