Blockchain investigator ZachXBT has alleged that two U.S. crypto investment platforms, BitcoinIRA and iTrustCapital, suffered separate data breaches this year without publicly disclosing the incidents, raising concerns that leaked customer information may be helping criminals carry out targeted social-engineering attacks.
ZachXBT said Monday that he had reviewed evidence indicating databases linked to both companies had been compromised. According to his post, the leaked information included personal details, portfolio holdings, banking information, custodian information and account verification status.
Neither BitcoinIRA nor iTrustCapital had publicly confirmed a breach at the time of ZachXBT’s post.
The investigator said he contacted both companies for comment on Aug. 21 but had not received a response.
The allegations have not been independently verified, and ZachXBT did not disclose how many customers may have been affected, when the alleged breaches occurred or how attackers obtained access to the information.
Those unanswered questions are important. A database containing information about customers and their holdings would not necessarily mean that crypto assets held by either platform’s custodians had been compromised.
Instead, the immediate risk could come from criminals using detailed customer information to make phishing emails and fraudulent support calls more convincing.
BitcoinIRA User Allegedly Lost More Than $1.2 Million
ZachXBT pointed to a June case involving a BitcoinIRA customer as an example of how such information could allegedly be used.
Earlier this month, the investigator published a separate investigation into a threat actor known as “Tiffany,” whom he linked to at least $5 million in alleged thefts involving impersonation of cryptocurrency companies, exchanges and hardware-wallet support services.
One of the cases involved a victim who allegedly received a spoofed BitcoinIRA email before losing more than $1.2 million in Bitcoin and Ether from a Trezor hardware wallet in June.
The assets were therefore not reported stolen from BitcoinIRA’s own custody infrastructure. Instead, ZachXBT’s findings indicate that the attacker allegedly impersonated BitcoinIRA and used social engineering against a person who held cryptocurrency separately in a hardware wallet.
That distinction matters because the newly alleged database compromise could potentially explain how an attacker knew enough about the victim’s relationship with BitcoinIRA to carry out a targeted attack, but it does not by itself establish that the database was the source of the information.
ZachXBT now says the attacker used information from the database when targeting the victim.
His earlier investigation identified Bitcoin and Ethereum addresses allegedly connected to the $1.2 million theft and described communications between members of the suspected group after the attack.
No information disclosed so far establishes that other BitcoinIRA customers lost assets because of the alleged breach.
BitcoinIRA Says Customer Crypto Uses External Custody
BitcoinIRA was founded in 2016 and offers self-directed retirement accounts that allow U.S. customers to invest in cryptocurrencies.
The company says it serves more than 200,000 Americans and currently supports more than 100 cryptocurrencies.
BitcoinIRA does not directly custody the retirement assets held through its platform. Its current account disclosures identify Digital Trust as custodian, while BitcoinIRA says digital assets are stored using BitGo multi-signature infrastructure.
The company’s website advertises offline storage, video-based authentication and custody insurance of up to $250 million, subject to the asset and custody arrangement involved.
BitcoinIRA’s privacy policy says it uses measures designed to protect personal information against unauthorized access, misuse and disclosure, while also acknowledging that no internet transmission can be guaranteed as completely secure.
There is currently no evidence that the alleged data incident affected BitcoinIRA’s underlying cryptocurrency wallets or its custodian.
That leaves two distinct security questions: whether customer information was exposed and, separately, whether customer assets held through the platform’s custody system were ever at risk.
ZachXBT’s allegation concerns the first issue.
iTrustCapital Also Named in Alleged Leak
The second platform identified by ZachXBT is iTrustCapital, another U.S. service focused on cryptocurrency investing through self-directed retirement accounts.
iTrustCapital describes itself as a software platform rather than an exchange, broker-dealer or custodian. The company uses Fortis Bank as the qualified custodian for its IRA accounts.
According to iTrustCapital, cryptocurrency held through its service is stored using institutional providers including Coinbase Custody, Fidelity Digital Assets and Fireblocks.
The company says assets are held 1:1 and off its balance sheet.
Its security model also differs from a conventional cryptocurrency exchange because iTrustCapital says it does not use hot wallets for customer accounts and operates a closed-loop structure designed to prevent crypto from being withdrawn directly to arbitrary external addresses.
That could make a leak of personal information a different type of threat.
An attacker might not be able to drain cryptocurrency simply by obtaining an iTrustCapital password, but customer identity details, portfolio information and banking data could still potentially be useful for phishing, account takeover attempts, identity theft or attacks against accounts held elsewhere.
ZachXBT did not provide a public example of an iTrustCapital customer losing money as a direct result of the alleged database exposure.
The Bigger Risk Is Highly Targeted Social Engineering
The allegations illustrate a growing problem for cryptocurrency investors: security failures do not have to involve private keys or compromised blockchain infrastructure to produce large losses.
Information about a person’s portfolio can itself be valuable.
A criminal who knows that a victim uses a specific crypto platform, owns particular assets, holds a large portfolio and works with a particular custodian can create a much more credible impersonation attempt than someone sending generic phishing emails.
The attacker can refer to actual account information, present themselves as a security employee and claim there is suspicious activity requiring immediate action.
That changes the economics of social engineering.
A leaked database containing thousands of customers may allow attackers to rank potential victims by portfolio value and concentrate their efforts on the accounts with the largest balances.
The June BitcoinIRA-related case is important for exactly that reason. The reported $1.2 million theft did not require attackers to break BitGo, compromise Bitcoin’s network or exploit the Trezor hardware itself. According to ZachXBT’s investigation, the attacker instead persuaded the victim through impersonation and social engineering.
Disclosure Questions Could Become the Next Issue
Whether BitcoinIRA or iTrustCapital had a legal obligation to disclose any incident cannot yet be determined from the information available.
U.S. breach-notification requirements depend on factors including where affected customers live, what information was accessed, whether the data was encrypted and whether the incident meets the applicable legal definition of a breach.
The existence of leaked information alone therefore does not establish that either company violated disclosure requirements.
More information would also be needed about when each company became aware of any unauthorized access.
The most important confirmation would now have to come from BitcoinIRA and iTrustCapital themselves: whether their systems or service providers were compromised, what data was involved, how many customers were affected and whether customers or regulators were notified privately.
Until those details emerge, the strongest conclusion supported by the available evidence is narrower than the initial allegation.
ZachXBT says he has reviewed evidence of customer-data breaches involving both companies, and an earlier investigation provides a documented example of a BitcoinIRA user being targeted in a $1.2 million social-engineering theft. But neither alleged breach has yet been publicly confirmed by the companies, and there is currently no evidence that either platform’s underlying crypto custody infrastructure was compromised.







