Blockchain investigator ZachXBT alleges BitcoinIRA and iTrustCapital suffered data breaches this year without public disclosure, potentially enabling a $1.2 million social-engineering theft.
Blockchain investigator ZachXBT alleges BitcoinIRA and iTrustCapital suffered data breaches this year without public disclosure, potentially enabling a $1.2 million social-engineering theft.

Blockchain investigator ZachXBT alleged Monday that BitcoinIRA and iTrustCapital suffered separate data breaches this year without publicly disclosing the incidents, raising concerns that leaked customer information may be fueling targeted social-engineering attacks.
ZachXBT said he reviewed evidence indicating databases linked to both companies were compromised, with leaked data including personal details, portfolio holdings, banking information, custodian information and account verification status. He contacted both companies for comment on Aug. 21 but had not received a response.
Neither platform has publicly confirmed a breach. ZachXBT did not disclose how many customers may have been affected, when the alleged breaches occurred, or how attackers obtained access. The allegations have not been independently verified.
The immediate risk is not necessarily to crypto assets held by either platform's custodians. Instead, criminals could use detailed customer information to make phishing emails and fraudulent support calls more convincing.
ZachXBT pointed to a June case involving a BitcoinIRA customer as an example of how such information could be used. Earlier this month, he published a separate investigation into a threat actor known as "Tiffany," linked to at least $5 million in alleged thefts involving impersonation of crypto companies and hardware-wallet support services.
One victim allegedly received a spoofed BitcoinIRA email before losing more than $1.2 million in Bitcoin and Ether from a Trezor hardware wallet in June. The assets were not stolen from BitcoinIRA's custody infrastructure — the attacker impersonated the platform and used social engineering against a person holding crypto separately.
BitcoinIRA, founded in 2016, serves more than 200,000 Americans and supports more than 100 cryptocurrencies. The company uses Digital Trust as custodian, with digital assets stored via BitGo multi-signature infrastructure and custody insurance of up to $250 million. iTrustCapital uses Fortis Bank as qualified custodian, with crypto held through Coinbase Custody, Fidelity Digital Assets and Fireblocks in a closed-loop structure without hot wallets.
Whether either company had a legal obligation to disclose any incident cannot yet be determined. U.S. breach-notification requirements depend on where affected customers live, what information was accessed, whether data was encrypted, and whether the incident meets the legal definition of a breach.
The most important confirmation must come from BitcoinIRA and iTrustCapital themselves: whether their systems or service providers were compromised, what data was involved, how many customers were affected, and whether customers or regulators were notified privately.
Until those details emerge, the strongest conclusion is narrower than the initial allegation. ZachXBT says he reviewed evidence of customer-data breaches involving both companies, and an earlier investigation documents a BitcoinIRA user targeted in a $1.2 million social-engineering theft. But neither breach has been publicly confirmed, and there is no evidence that either platform's underlying crypto custody infrastructure was compromised.
This article is for informational purposes only and does not constitute investment advice.