← Trends

Compliance Data Becomes the Attack Surface

Mandated identity collection keeps concentrating name-to-address links inside brokers and their banking partners, so each breach permanently deanonymizes holders and sustains a pipeline of phishing and physical attacks, pushing users toward privacy tooling and custodial products.

weakening · confidence 66 · +24 7d · Medium term (3-9 months) · tracking since September 2, 2026 · updated September 14, 2026

Sign in to get threshold and movement alerts for this trend.

Score history

Daily conviction score, 0 to 100. Higher means the thesis is more strongly corroborated.

Sep 13 · 68Sep 14 · 66

Now 66 · -2 since Sep 13 · ranged 66 to 68

Showing the last few days. Unlock full score history.

Why the conviction moved

  • Sep 13
    Strengthened +5

    Reporting notes that buying a self-custody hardware wallet requires giving a company a name and delivery address, creating a durable record linking an identified person to the fact that they hold keys. This extends the attack surface past exchanges and brokers to the device supply chain, where the target list is holders specifically — the same pipeline that has fed phishing and physical attacks.

  • Sep 13
    Strengthened +7

    Revolut handed an attacker posing as a government agency customer passports and full bitcoin transaction histories, with no system breached and no funds taken because the bank processed the fraudulent request through its normal legal channel. The compliance channel itself was the exploit path, so no security spending closes it — the deanonymization is permanent and the name-to-address links are now in attacker hands.

  • Sep 12
    Strengthened +5

    Trezor reported a second breach of a third-party marketing platform exposing customer contact data that fed phishing attacks, disclosed the same day the ringleader of a $245 million theft that followed the same pattern pleaded guilty in the US. A repeat breach at the same vendor class, with a conviction showing the downstream loss, confirms that the durable exposure sits in customer databases held outside the security perimeter rather than in the devices themselves.

Showing the last 2 days. Unlock the full record.

Source trail

  • Supporting · September 13, 2026

    Revolut Handed Passports and Full Bitcoin Histories to an Attacker Posing as a Government Agency

    Revolut handed an attacker posing as a government agency customer passports and full bitcoin transaction histories, with no system breached and no funds taken because the bank processed the fraudulent request through its normal legal channel. The compliance channel itself was the exploit path, so no security spending closes it — the deanonymization is permanent and the name-to-address links are now in attacker hands.

    CoinDesk
  • Supporting · September 13, 2026

    The Paper Trail Behind a Hardware Wallet Undermines the Privacy the Device Promises

    Reporting notes that buying a self-custody hardware wallet requires giving a company a name and delivery address, creating a durable record linking an identified person to the fact that they hold keys. This extends the attack surface past exchanges and brokers to the device supply chain, where the target list is holders specifically — the same pipeline that has fed phishing and physical attacks.

    CryptoSlate

Unlock full source trail, score history, and daily updates.

7 more sources in the full trail.

Unlock Trends

Affected regions & assets

RegionsGlobal
Assets3 assetsUnlock Trends

Townsquare

Argue the thesis in Townsquare.