WuBlockchain Weekly Outlook: The macro trade is about to be stress-tested. U.S. payrolls, ISM,...
California Bans Official Meme Coins, Cites Trump’s Crypto Venture
Big institutional money is split on Bitcoin’s next move as massive market bets shift
Vitalik: Ethereum Is Evolving Beyond a Blockchain Into a…
Apple, Nvidia and Tesla Tokenized Stocks Can Now Be Used to Borrow USDC on AaveSeven Coinbase...
American Companies Significantly Increase Mentions of Open-Source Models
Circle Internet Group Co-Founder Resigns, CFO to Depart by Year-End
U.S. spot Solana ETFs pull in record $188 million in weekly inflows, led by BitwiseRead...
Does Brad Garlinghouse See XRP As Digital Gold? Here’s What He Said
Why Is Bitcoin Price Going Down Today?
799 $BTC (66,508,104 USD) transferred from unknown wallet to Coinbase Institutional...
Circle Co-founder Sean Neville Resigns from Board; CFO Plans Departure, to Remain Until End of 2026
Chuan Dou Bao Develops Competing Product to Meta Muse in Six Days
California Bans Public Officials From Issuing Their Own Meme Coins
53 Robinhood Chain Token Launches Linked to Rug-Pull…
California's Newsom signs memecoin ban and calls it 'The Opposite of Trump'
Solana ETFs draw record $188 million in a week as Bitwise takes two-thirds of inflows
615 $BTC (51,127,057 USD) transferred from Coinbase Institutional to unknown wallet...
XRP Price Analysis for Today 28th Sept
Vitalik Buterin Says Ethereum Is Becoming a Cryptographic World Computer
Crypto Week Ahead: PCE, Jobs Report & Korea Blockchain Week
Capital B acquires 13 more bitcoins, now holding 3,538 BTC
1,700 $BTC (141,199,275 USD) transferred from Coinbase Institutional to unknown...
WTI and Brent Crude Oil Prices Increase Over 2%
Nano Labs founder's X account has been recovered
GoPlus Challenges THORChain’s Decentralization Claims Over…
Coinbase CEO Stands by His $400K Bitcoin Prediction for 2030
Scammers Launch Fake ETH L2 to Steal $2M From Crypto Traders
GoPlus: Bitget’s $387.5M Hack Exploited the…
1,700 $BTC (141,504,186 USD) transferred from unknown wallet to Coinbase...
614 $BTC (51,274,822 USD) transferred from Coinbase Institutional to unknown wallet...
Zano network restarted its blockchain after a Gateway Address vulnerability allowed
South Korea weighs crypto market makers after JPYC trades at 4 times peg
Scammers Create Fake GIWA Blockchain, Stealing Over $2 Million
999 $BTC (83,487,121 USD) transferred from unknown wallet to Coinbase Institutional...
Bitcoin Slips to $83,000 as Trump Rejects Iran Ceasefire Offer
UPBIT Introduces CASHCAT Trading with Multiple Currency Support
Binance to Facilitate Airdrop for SpaceX and Invesco QQQ Trust Holders
$CASHCAT listed on Upbit spot (KRW)・
1,700 $BTC (141,908,550 USD) transferred from Coinbase Institutional to unknown...
Analyst Exposes $18.43M Robinhood Chain Memecoin Rug Pull Ring
Upbit to list CASHCAT token on KRW, BTC, and USDT markets
Binance Will Support the SpaceX (SPCXB) Airdrop for MarsCoin (MARSCOIN) Holders and the Invesco QQQ ...
1,700 $BTC (141,865,682 USD) transferred from unknown wallet to Coinbase...
Société Générale Analyst Predicts Federal Reserve Will Avoid Repeat of 2022-2023 Rate Hike Cycle
Analyst: Bitcoin demand has not improved, but has weakened further
NEW: South Korea's FSC said it will review lifting ban on crypto market makers to improve
Painting Roofs White Cut AC Use in a Philadelphia Pilot of 340 Homes
Binance Wallet Removes Native Gas Token Requirement With USDT PaymentsBinance Wallet now allows...
Binance Wallet Introduces USDT for Gas Fees Across Major Networks
Binance Launches New USDT-Denominated Perpetual Contracts
A Huge Week Is Coming for XRP as Evernorth Nears Crucial Nasdaq Vote
OpenAI May Urgently Launch a Personal AI Assistant to Directly Take on Meta Muse
Binance to List Multiple USDT-Margined TradFi Perpetual Contracts
Bithumb to list PYUSD token on KRW market
$Q, $PYUSD listed on Bithumb spot・
Vitalik Buterin says Hegotá could be Ethereum’s last ‘normal’ fork
California Governor Gavin Newsom signed new legislation banning state officials from
614 $BTC (51,264,211 USD) transferred from Coinbase Institutional to unknown wallet...
Circle Seeks Director of Ecosystem Growth in South Korea
1,700 $BTC (141,932,974 USD) transferred from Coinbase Institutional to unknown...
1,685 $BTC (140,701,408 USD) transferred from unknown wallet to Coinbase...
Kazakhstan Turns to Flare Gas to Power Crypto Mining Revival
Study Finds Jupiter Ultra Users Experience Fewer Sandwich Attacks Than Others
CZ: A Single Tweet Could Not Have Caused FTX to Collapse On September 25, 2026, Binance founder CZ...
Bitcoin, Nasdaq futures decline as Trump won’t rule out more Iran strikes
Bitget $387.5M Hack: How Attackers Moved $185M in One Minute Without Stealing Private Keys
BTC, ETH and XRP Brace For Packed Week Of US Economic Data And Fed Clues
Gate's 7-day net inflow exceeds $118 million, ranking third among global centralized exchanges
Researchers Uncovered Scheme Involving Fake Crypto Requests on Revolut
- Analysts uncovered how Revolut shared customer data via fake requests.
- At the center of the incident was not a hack of the banking app itself, but abuse of the channel through which financial institutions interact with government agencies.
- 680 Revolut customers may have been affected by the leak.
- According to researchers, the attackers used public crypto transactions and wallet addresses to obtain KYC data on potentially wealthy users.
Fintech company Revolut faced the fallout from a data leak affecting around 680 customers after attackers used compromised Italian government email inboxes to send fake requests to the fintech firm. This was reported by FT and International Cyber Digest.
— International Cyber Digest (@IntCyberDigest) September 14, 2026
BREAKING: We're in contact with the Revolut hacker. According to them, they didn't only take Revolut data, they've also compromised multiple Italian law enforcement departments.
They say the operation targeting Revolut ran for six months, and that they used Italian law… pic.twitter.com/ZYGWZEc0tL
Amid the publication of user data and possible ransom demands, researchers are detailing the attack mechanism, while lawyers and civil rights advocates point to a systemic problem with verifying government requests in the financial sector.
In addition, some of the claims are being spread by the alleged attackers themselves. Revolut has not confirmed all of the published figures and details.
According to early Revolut investor and independent analyst Max Karpis, the company received ransom demands, and people claiming to possess the stolen files began posting copies of customer documents and selfies on Telegram.
After Revolut’s data breach, the company has reportedly received ransom demands: pay up, or they'll release customer files.
— Max Karpis (@maxkarpis) September 14, 2026
People claiming they hold the pack are posting ID copies and selfies on Telegram and saying they will drip more every day. One figure doing the rounds is…
At the same time, Karpis stressed that Revolut has not yet confirmed the claimed amount of 10,000 BTC, and that the information should be treated with caution.
“Revolut still says “limited,” and that the app and the money were not hacked. This is extortion after a Revolut employee handed KYC to an unauthorised mailbox on a real government domain. Paying would not put the passports back,” he wrote.
Karpis also urged potentially affected users to take additional security measures: freeze credit lines where possible, set a new passcode and card transaction alerts in the app, and avoid engaging with people who already know the user’s IBAN or their previous cryptocurrency transactions.
Separately, he advised considering replacing a passport, since in some countries, after a document is compromised, the old number can be canceled and a new one issued. At the same time, the expert warned about another potential scam: offers to “delete the file” for money may be an attempt to extort funds again.
How Attackers Could Have Obtained Cryptocurrency Customer Data
According to an X user under the handle Korra, an attacker using the alias IAmNotAVillain employed a so-called spray-and-pray tactic: sending Revolut hundreds of cryptocurrency transaction IDs and deposit addresses, and asking for information about the accounts associated with them.
— Korra (@korraflow) September 15, 2026
BREAKING: Duel can report that the Revolut hacker used a "spray and pray" strategy, sending hundreds of cryptocurrency transaction IDs to Revolut and asking for the associated account details. Revolut complied.
This explains the sheer volume of data the hackers were able to… pic.twitter.com/RqGsuEIkMZ
Duel claims that such requests were sent under the cover of a forged European Investigation Order — a European investigative order. Revolut allegedly responded by providing archives containing customer data.
Researchers said they obtained and verified authentic copies of emails in .eml format. One of them contained 10 folders, each dedicated to a separate customer. According to Duel, the folders contained:
- Photos of identity documents
- Verification selfies
- Account information
- Unredacted transaction data
According to researchers, the password to the encrypted ZIP archive was sent in a separate email.
This scheme also explains why the attackers may have deliberately sought information about wealthy Revolut clients. Public blockchains make it possible to see addresses and transactions, meaning a crypto transaction could be used as a kind of search key for a request to a centralized financial institution.
Researchers claim the attacker sent Revolut hundreds of transaction hashes and deposit addresses that, in their view, were linked to high-asset clients. The company then allegedly returned information about the corresponding users.
Separate claims about 147 GB of data allegedly stolen from Italian government systems, as well as about the publication of client data, are being circulated by researchers and people who say they are in contact with the attackers.
Human rights advocate and Open Dialogue Foundation President Lyudmyla Kozlovska noted that new documents confirm that on July 24, 2026, Revolut refused to directly disclose information in response to a request covering 198 hashes. According to her, 169 of them were linked to Revolut Ltd in the United Kingdom, and another 29 — to the Swiss legal entity.
New evidence shows: (1) @Revolut did apply the one refusal ground the law gives it. (2) the attackers targeted in their malicious request high-value clients using blockchain transactions.
— Lyudmyla Kozlovska
Documents show that on 24 July 2026, on a request covering 198 hashes, Revolut refused… https://t.co/Hs4eHdvBuo(@LyudaKozlovska) September 15, 2026
Kozlovska claims the company invoked a legal ground for refusal — a jurisdictional limitation. The request concerned only accounts at Revolut Bank UAB in Lithuania, while in other cases the applicant was directed to the UK mutual legal assistance procedure.
At the same time, she emphasized that European anti-money laundering rules do not impose a separate obligation on a bank to verify the true party behind an authenticated government request.
“EU AML law imposes no verification duty on the bank and provides no meaningful mechanism to check who is really behind an authenticated state request. Refusal to answer carries fines in the millions,” Kozlovska said.
What Victims Are Advised to Do, and Why the Incident Has Broader Implications
Kozlovska urged European citizens to contact their Members of the European Parliament and demand urgent hearings on the use of mass financial data collection as a tool for attacks.
She also pointed to a potentially broader issue: a similar risk may apply to banks, crypto exchanges, and payment services in jurisdictions where FATF rules and relevant AML legislation are in force.
According to her, financial institutions are required to respond to properly оформлені government requests, while the mechanisms for verifying who is actually behind such a request may be limited.
Kozlovska noted that the issue has already been raised before the European Parliament by human rights organizations, victims, and experts, with the support of the Open Dialogue Foundation. She added that this year, in a resolution dated June 18, 2026, the European Parliament separately flagged the risk of transnational financial repression.
As of the time of writing, Revolut has not published separate recommendations on its X page regarding clients’ next steps in connection with the incident.
As a reminder, Revolut recently received conditional approval to establish a national bank in the United States.
Сообщение Researchers Uncovered Scheme Involving Fake Crypto Requests on Revolut появились сначала на INCRYPTED.
Source: Incrypted
BREAKING: We're in contact with the Revolut hacker. According to them, they didn't only take Revolut data, they've also compromised multiple Italian law enforcement departments.

(@LyudaKozlovska)