# Compliance Data Becomes the Attack Surface

Mandated identity collection keeps concentrating name-to-address links inside brokers and their banking partners, so each breach permanently deanonymizes holders and sustains a pipeline of phishing and physical attacks, pushing users toward privacy tooling and custodial products.

- Conviction: 66 / 100 (weakening)
- 7-day move: +24
- Horizon: Medium term (3-9 months)
- Tracking since: 2026-09-02T00:00:00.000Z
- Last updated: 2026-09-14T14:04:09.447Z
- Canonical: https://polylog.news/crypto/trends/kyc-data-becomes-the-attack-surface
- Publisher: Polylog
- Affected regions: Global

## Recent score history

- 2026-09-13: 68
- 2026-09-14: 66

## Recent evidence

- [confirms] Revolut Handed Passports and Full Bitcoin Histories to an Attacker Posing as a Government Agency (2026-09-13): Revolut handed an attacker posing as a government agency customer passports and full bitcoin transaction histories, with no system breached and no funds taken because the bank processed the fraudulent request through its normal legal channel. The compliance channel itself was the exploit path, so no security spending closes it — the deanonymization is permanent and the name-to-address links are now in attacker hands.
- [confirms] The Paper Trail Behind a Hardware Wallet Undermines the Privacy the Device Promises (2026-09-13): Reporting notes that buying a self-custody hardware wallet requires giving a company a name and delivery address, creating a durable record linking an identified person to the fact that they hold keys. This extends the attack surface past exchanges and brokers to the device supply chain, where the target list is holders specifically — the same pipeline that has fed phishing and physical attacks.

7 more evidence entries, the full score history, the conviction-driver timeline, and affected assets are for subscribers: https://polylog.news/pricing
