BitcoinIRA and iTrustCapital allegedly suffered unreported data breaches exposing personal details, holdings, and banking information; at least one user lost $1.2M+ to targeted theft.
Regulation & Gov ·
BitcoinIRA and iTrustCapital allegedly experienced unreported data breaches that exposed customer personal information, banking details, and portfolio holdings, according to security researcher investigations. At least one user suffered theft totaling $1.2M in what appears to be a targeted attack leveraging the exposed data.
The breaches remain undisclosed by both platforms, raising questions about whether affected customers were ever notified. The exposure of banking and portfolio information created conditions for the theft, suggesting attackers may have used the leaked credentials or account details to gain unauthorized access and execute the theft.
It remains unclear how many customers were impacted, what specific data was compromised, whether the platforms have confirmed the breaches internally, or what remediation steps either company has taken. The relationship between the data exposure and the theft—whether the attacker exploited the breach directly or used information from it—has not been fully detailed.