A data breach at Revolut, in which hackers claim to have stolen the details of nearly 700 “crypto whale” accounts and are now demanding a $2m ransom, has reignited concerns about the traceability of digital assets and the risks of holding them.
On Wednesday, a note on the website of the hacker group iamnotavillain ordered the bank to pay “6,000 XMR” – shorthand for a notoriously hard-to-trace cryptocurrency called Monero – “otherwise all the data will be sold, and the blood will be on your hands”. Revolut said it had received no direct contact from the group, and it is not clear whether a ransom has been paid.
Despite the colourful threat, the attack on Revolut, which happened days before the bank announced that it would be seeking a dual stock market listing, in New York and London, is not likely to result in any bodily harm. However, physical attacks on cryptocurrency holders are no joke.
Data compiled by the Bitcoin security expert Jameson Lopp shows physical attacks on crypto-holding persons increased by 32% year on year in the first half of 2026, to 50 globally. They include a case in April when four men invaded a family home in Maidenhead, Berkshire, to demand crypto; and a case where armed men broke into the home of a crypto company chief executive near Nantes, in western France, and struck him on the head before being driven off by the alarm system.
These are extreme examples, but they highlight crypto’s enduring appeal among criminals, thanbks chiefly to its liquidity and the anonymity it confers. Partly for these reasons, it has also become a major conduit for fraud.
The Home Office’s fraud strategy explicitly names cryptocurrency fraud as a growing threat. A report from Frontier Economics found the value of such fraud – where consumers are duped into authorising payments to another account – has grown significantly, from around £59m in 2023 to £153m in 2025.
“The UK is facing a scams epidemic, and fraud involving cryptocurrencies is a growth area for criminals,” said Sam Richardson, editor of Which? Money. “Unfortunately, reimbursement rules protecting scam victims who send money between banks do not cover transfers involving crypto wallets or exchanges, so consumers who are tricked in this way face losing all their money.”
Consumer protections are attempting to keep up. From the end of this month, crypto firms can apply for full authorisation from the Financial Conduct Authority (FCA) for the same kind of licences that banks need – a much higher bar than the basic controls on money laundering that are currently required. That authorisation will become mandatory in October next year.
“Firms will have to safeguard customer assets,” said Dominic Cashman, director of authorisation at the FCA. “There are rules around governance, and rules around their financial resilience. They will have to hold capital if they’re doing certain activities. They will have obligations for market integrity. Their leaders will become subject to the senior manager regime. It’s a much more comprehensive framework.”
But this is not certain to stop the scams. “There is a risk that a potential regulatory ‘halo effect’ creates a false sense of security among some investors,” Richardson warned.
Sign up to newsletters from The Observer
For information about how The Observer protects your data, read our Privacy Policy
The FCA has already banned certain types of crypto derivatives – including “crypto perps”, an asset that Reform UK donor Ben Delo claims to have pioneered – and says it is stepping up enforcement. Last week, in a joint operation with HMRC and the Metropolitan police, it issued cease-and-desist orders at three London premises suspected of illegal peer-to-peer crypto trading.
Regardless of its reputation, crypto remains popular. Roughly 8% of UK adults generally hold cryptocurrency, but the proportion rises to 11% among men, and 15% among 18-34-year-olds, according to the FCA.
Revolut, which was recently valued at $115bn in a private share sale, is a prime example of the wealth that can be accrued from offering crypto services, which have been available on its app since 2017. But its recent run-in with hackers – who, according to the Financial Times, posed as Italian law enforcement to obtain their information – is an awkward moment. No doubt the FCA, and, eventually, investors in the public market will be studying its bid for authorisation carefully.
Photograph by NurPhoto via Getty Images
Click Here For The Original Source.
