सामग्री पर जाएँ

समाचार

The safest place for your passport scan is nowhere

इस लेख का अनुवाद अभी नहीं हुआ; अंग्रेज़ी मूल दिखाया जा रहा है।

On 16 August 2026 the wallet maker SafePal disclosed a breach exposing the names, physical addresses and contact details of 39,798 customers who had placed orders between March 2025 and April 2026. The same week, Israel's largest regulated crypto broker, Bits of Gold, was reported to have leaked data on as many as 200,000 customers — names, phone numbers, ID numbers, bank details, IP addresses and wallet addresses. That second figure is a reported estimate, not an audited count, and the company was still investigating.

Neither is unusual, and that is the point. Coinbase's 2025 incident did not involve a hacked server at all: criminals bribed overseas support contractors to copy customer records out of internal tools. The weakest part of a KYC file is rarely the encryption. It is the number of people whose job requires them to be able to read it.

There is a structural asymmetry here that no amount of security spending fixes. A company can rotate a leaked password in a day. You cannot rotate your face, your passport number or where you live. The file outlives the company that collected it, and it is copied every time that company is bought, audited, subpoenaed or breached.

What this means in practice: every KYC form is a bet that the counterparty will out-live and out-secure its attackers for as long as the data stays sensitive — which is forever. Ask whether the service needs the document before you ask whether it will keep it safe.

Sources: CoinDesk — SafePal reveals a data breach exposing nearly 40,000 customers, crypto.news — Bits of Gold probes customer data breach

The safest place for your passport scan is nowhere · nokyc.watch