How do I limit the personal data that links me to my crypto holdings?
Confirmed Published 5 min read
Short answer
Don’t post about your holdings or wallet addresses, keep your phone number, home address and birth date off public profiles, and treat every company that holds your ID as a possible leak. Registered Canadian platforms must still collect your identity by law. Coinbase and two hardware-wallet makers have had customer data exposed, and Chainalysis links leaked data to violent attacks.
The full answer
Targeted attacks on crypto holders often start with information. Hacking comes later, if at all. Chainalysis, a blockchain analysis firm, wrote in August 2026 that “publicly disclosing cryptocurrency holdings, whether through social media, conference appearances, or on-chain activity linked to known identities, can make individuals targets.”[1] The data that links a person to their crypto comes from three places. They are company records, the public ledger, and what people say about themselves. You control the last two fully and the first only in part.
Where does the link between a person and their crypto come from?
Company records have leaked repeatedly. In May 2025 Coinbase told the SEC that a threat actor appeared to have paid support staff or contractors outside the US to collect customer data. It said the data, still under investigation, included “Name, address, phone, and email” and “Account data (balance snapshots and transaction history),” and that the incident did not involve passwords or private keys.[2] Coinbase preliminarily estimated remediation and voluntary customer reimbursement costs at “approximately $180 million to $400 million.”[2] Hardware-wallet makers have had leaks too. In December 2020, Ledger’s CEO said a leaked shop database exposed the postal addresses and phone numbers of “approximately 272,000” customers, and that “many of you have been targeted by e-mail and SMS phishing campaigns.”[3] In January 2024, a breach of Trezor’s third-party support portal may have exposed the names and emails of 66,000 users who had contacted Trezor support since December 2021. Trezor confirmed 41 cases where the data was used to try to trick people out of their recovery phrases.[4]
The records need not come from a crypto company. Chainalysis calls a data breach “the likeliest culprit” for a wave of violent attacks in France. In 2024 a tax official is alleged to have sold dossiers that “included their names, addresses, holdings, phone numbers, and tax records.”[1] It says a January 2026 breach of about 50,000 users at a crypto tax-reporting firm “may be fueling” the rise as well.[1] Those attacks are described on physical attacks on crypto holders.
Accounts can leak location as well as identity. TRM Labs describes a July 2024 burglary in New Mexico that was coordinated with a man accused of “remotely monitoring the victim’s physical location by accessing the victim’s iCloud account.”[5] In May 2025, TRM said personal details found online, “from addresses to family details,” make victims easier to find and follow.[5]
Why does a public ledger matter?
Every XRP Ledger payment can be seen by anyone. XRPL.org says “all transactions are publicly visible.”[6] NIST, describing Bitcoin, calls its users pseudonymous: “users are anonymous, but their account identifiers are not; additionally, all transactions are publicly visible.”[7] Our reading applies the same logic to the XRP Ledger. An address carries no name. Once someone ties it to you, through a post, a screenshot or a payment request, they can read its whole history. XRPL.org even warns businesses that numbering customer tags in order can let outsiders “derive information about users’ accounts based on the tags used.”[8] How tags work is on what is a destination tag.
A new address can be created offline “without communicating to the XRP Ledger or any other party.”[9] Each new address has a cost: receiving XRP there the first time locks up the account reserve, “currently 1 XRP” when checked on September 29, 2026.[10] Our reading: a fresh address still stays linked to an old one if funds move between them on the public record.
What should I stop sharing?
The FBI’s 2022 advice is direct: “Do not advertise information about financial assets, including ownership or investment of cryptocurrency, on social media websites and forums,” and “avoid posting personal information online, such as mobile phone number, address, or other personal identifying information.”[11] In 2024 the FBI also said North Korean hackers “scout prospective victims by reviewing social media activity, particularly on professional networking or employment-related platforms.”[12] The FTC advises against security questions with answers “someone could find online or in public records.”[13] Canada’s Cyber Centre adds advice in its SIM-security guidance. It says to keep information tied to account security questions, such as “date of birth, home address and mother’s maiden name,” private and “using separate and unique email addresses for financial accounts and social media.”[14]
That advice covers posts showing balances, gains or wallet screens, and public profiles that list a phone number or home address. Separate email addresses should also make a leaked address from one company less useful at another.
What can I do about data that companies must collect?
Not much, and the law is the reason. In Canada, the identity check comes from the Proceeds of Crime (Money Laundering) and Terrorist Financing Act. FINTRAC’s guidance says the requirement “applies to all reporting entities.”[15] The OSC says a registered crypto trading platform must meet Know your Client and FINTRAC requirements before opening an account, and that they “have a legal obligation to keep this information private and confidential.”[16] Why platforms ask is covered on why exchanges ask for ID.
Every company that holds your ID and your balance is another copy that could leak, so the number of such accounts matters. The Ledger and Trezor leaks were followed by phishing aimed at the affected customers,[3][4] so a breach notice is a reason to be wary of anyone claiming to be the company. The FTC advises reaching a company only through “a phone number or website you know is real.”[13] Account settings that slow down a stolen login are on securing a platform account.
What does this not fix?
Privacy does not undo a leak that has already happened, and required ID collection means some records will always exist. There is also a company counter-argument. After its leak, Ledger’s CEO said “there is no way to make any correlation between the data that has leaked and the funds on your wallet.”[3] The fields Ledger listed were names, postal addresses and phone numbers, with no balances among them.[3] Coinbase’s May 2025 filing said the affected data included balance snapshots, and, according to Chainalysis, the dossiers allegedly sold in 2024 by a French tax official included holders’ crypto holdings.[2][1] How much risk a leak creates depends partly on whether it links a person to an amount, though a hardware-wallet order alone marks someone as a likely holder.
What we know
- May 2025: Coinbase told the SEC that a threat actor appeared to have paid support staff or contractors outside the US to collect customer data. The data, still under investigation, included names, addresses, phone numbers, emails, government ID images and balance snapshots. Coinbase said the incident did not involve passwords or private keys.
- Ledger’s CEO said a leaked shop database exposed the postal addresses and phone numbers of about 272,000 customers, and that many were then targeted by email and SMS phishing (statement dated December 21, 2020, about the company’s July 2020 data breach).
- January 2024: a breach of Trezor’s third-party support portal may have exposed names and emails of 66,000 users who had contacted support since December 2021; Trezor confirmed 41 cases where the data was used to phish for recovery seeds (BleepingComputer).
- August 6, 2026: Chainalysis called a data breach the likeliest cause of France’s rise in violent attacks, pointing to tax dossiers an official allegedly sold in 2024, and said a January 2026 breach of about 50,000 users at a crypto tax firm may be adding to it.
- Checked September 29, 2026: XRPL.org says all XRP Ledger transactions are publicly visible.
- FINTRAC guidance, checked September 29, 2026, says the identity-verification requirement applies to all reporting entities, and the OSC says Canadian crypto trading platforms must keep clients’ personal information confidential.
What we reason Analysis
- Each company that holds your identity and your crypto balance is one more copy that can leak, so fewer such accounts means fewer copies. This comes from the Coinbase, Ledger and Trezor incidents and Chainalysis’s account of French tax data. No source measures the effect of holding fewer accounts.
- An XRP Ledger address becomes personal data the moment it is tied to your name, because every past and future transaction of that address is public. This rests on XRPL.org’s statement that all transactions are publicly visible and NIST’s description of Bitcoin account identifiers as not anonymous.
- Using a fresh address does not erase the link if funds move between the old and new address on the public ledger. This rests on XRPL.org and NISTIR 8202 on public transaction histories. No XRPL-specific study has been published as of September 29, 2026.
What's still open
- No guidance on shipping hardware wallets to a pickup point instead of a home address was found as of September 29, 2026. Sources read: FBI, FTC, Canadian Cyber Centre, FINTRAC, OSC and NIST.
- Trezor’s own January 2024 statement could not be loaded on September 29, 2026, so the page cites press coverage of it.
- No regulator has published a dataset of customer-data breaches at crypto businesses, as far as the SEC EDGAR filing, FINTRAC, OSC, FBI and FTC materials show as of September 29, 2026.
In plain English
Criminals who target crypto owners often start with a list of names and addresses taken from a company that was hacked or had a dishonest employee. Several crypto companies, including Coinbase, have had customer details exposed. In Canada you cannot avoid giving your ID to a registered crypto platform, because the rules require it. You can avoid telling the world what you own by not posting about your crypto or your wallet addresses, and by keeping your phone number and home address off public profiles. Every XRP Ledger payment is public, so an address tied to your name shows everything that address does.
Key terms
Sources
- Estimated $30 Million Stolen in Violent Crypto Attacks in 2026 as France Records Emerges as Hotspot — Chainalysis (company research), August 6, 2026 Company-reported
- Coinbase Global, Inc. Form 8-K (Item 1.05, Material Cybersecurity Incident) — U.S. Securities and Exchange Commission (EDGAR), May 15, 2025 Primary
- Message by Ledger's CEO: Update on the July data breach — Ledger, December 21, 2020 Company-reported
- Trezor support site breach exposes personal data of 66,000 customers — BleepingComputer, January 22, 2024 Secondary
- The Rise of Wrench Attacks and Crypto-related Violent Crime — TRM Labs (company research), May 23, 2025 Company-reported
- FAQ — XRPL.org, undated (checked September 29, 2026) Primary
- Blockchain Technology Overview (NISTIR 8202) — National Institute of Standards and Technology, October 2018 Primary
- Source and Destination Tags — XRPL.org, undated (checked September 29, 2026) Primary
- Addresses — XRPL.org, undated (checked September 29, 2026) Primary
- Accounts — XRPL.org, undated (checked September 29, 2026) Primary
- Criminals Increasing SIM Swap Schemes to Steal Millions of Dollars from US Public (I-020822-PSA) — FBI Internet Crime Complaint Center, February 8, 2022 Primary
- North Korea Aggressively Targeting Crypto Industry with Well-Disguised Social Engineering Attacks (I-090324-PSA) — FBI Internet Crime Complaint Center, September 3, 2024 Primary
- Protect Your Personal Information From Hackers and Scammers — Federal Trade Commission, November 2024 (checked September 29, 2026) Primary
- Security considerations for SIMs (ITSAP.10.021) — Canadian Centre for Cyber Security, February 2026 Primary
- Methods to verify the identity of persons and entities — FINTRAC, undated (checked September 29, 2026) Primary
- Understanding crypto asset trading platforms — Ontario Securities Commission (GetSmarterAboutMoney.ca), September 8, 2025 Primary
Update log
- — Published.
I keep this site free, with no ads, paywall or affiliate links; gifts cover hosting and research time. Support the project, or report an error.
