Cryptocurrency wallet addresses leaked: what it means and what to do

Risk level: high. Can you change it: yes. Found in 2 breaches in this directory.

What this data is

The public address used to receive cryptocurrency, such as a Bitcoin or Ethereum address, stored by an exchange, a hardware wallet seller, a payment service or a crypto app.

The risk on its own

An address is public by design and cannot be used to spend your funds. The problem is that blockchains are public ledgers: anyone with the address can see its balance and every transaction it has made. A leak that ties an address to you turns an anonymous ledger entry into your personal financial record.

The risk combined with other data

With your name, email, phone or home address it tells criminals how much you hold and how to reach you. Holders of large balances have been targeted with convincing phishing, fake support calls and, in some cases, threats of violence at home. Past leaks of hardware wallet customer lists were followed by fake replacement devices posted to buyers.

How criminals use it

  • A fake exchange support email reports a security incident and directs you to enter your recovery phrase on a phishing site.
  • A parcel arrives with a replacement hardware wallet and a letter asking you to move your funds onto it, and the device is controlled by the sender.
  • Address poisoning sends a tiny transaction from a lookalike address so you copy the wrong one next time you send funds.
  • Fake airdrop tokens appear in your wallet with a claim link that asks you to sign an approval that drains it.
  • Criminals who can see a large balance and your home address threaten you in person to force a transfer.

What to do now

  1. Never type or share your recovery phrase anywhere except the wallet itself. No company, support agent or replacement device ever needs it.
  2. For a meaningful balance, move funds to a new wallet created with a fresh recovery phrase, so the leaked address no longer shows your holdings.
  3. Review and revoke old token approvals using the token approval checker on Etherscan or the equivalent explorer for your chain.
  4. Check the full address before every send, not just the first and last characters, and ignore tiny unexpected incoming transactions.
  5. Treat unexpected devices, letters and emails claiming to come from a wallet maker or exchange as fraud until you confirm them through the company's official site.
  6. Keep your holdings private: do not discuss amounts online, and consider a PO box for hardware wallet deliveries.

Frequently asked questions

Can someone steal my crypto with just my wallet address?

No. Spending requires your private key or recovery phrase. The address shows what you hold, which makes you a target for scams that try to get those secrets.

Should I move my crypto to a new wallet?

If the balance is meaningful, yes. A new wallet with a fresh recovery phrase breaks the link between your identity and your holdings.

What is address poisoning?

A scammer sends a tiny transaction from an address that looks like one you use, hoping you copy it from your history next time and send funds to them instead.

Breaches that exposed this data

  • Z-lib: 2024-06-20, 9.7M accounts, Cryptocurrency wallet addresses, Email addresses, Geographic locations, Passwords, Purchases, Usernames
  • Altenen: 2022-06-24, 1.3M accounts, Cryptocurrency wallet addresses, Email addresses, Passwords, Usernames

Tools that help

Related guides

Breach data sourced from Have I Been Pwned, used under CC BY 4.0. Additional breach metadata provided by XposedOrNot. DataExposed is an independent service and is not affiliated with or endorsed by either.