This page is updated on an ongoing basis (changes are dated at the bottom of the page).
A security incident occurred at Canny, an external software provider we used for a feedback board and data of 21bitcoin users was exposed in the process.
Our own systems were not and are not affected at any time, and your Bitcoin and euro balances were and are secure.
What happened
On 28 August 2026, “Canny”, a feedback tool connected to our customer support system (Intercom) via an interface, was targeted in a cyber attack. In the course of the attack, the access key for this interface was stolen and used to read data from our support system. The connection was cut the same day by the provider and the key was invalidated. After that, the complete access logs show no further access.
We found out about the incident on 29 August and have carried out a forensic review of its exact scope over the past hours. Every statement in this post comes from that analysis.
When it comes to your data, it is important to us not to speculate or cause unnecessary worry. That is why we analysed and traced the incident together with the providers involved, so that we could give you complete information at the earliest possible point about whether and to what extent you are affected.
We're sorry this happened
Security, personal responsibility and data protection are core values in the bitcoin community and values we live by every day at 21bitcoin. Even though the attack did not target our own systems, you entrusted us with your data and some of it was exposed through an external provider. We are sincerely sorry. With this post we want to be as transparent as possible, and we will keep you up to date here on any further developments.
What data was affected
The affected data comes from our support system. A large part of contacts (42.6%) consists of purely technical entries without names or contact details. Depending on the person, the following may be included:
Name, email address, phone number, date of birth, device-related data (such as language, country, operating system) (no addresses or place of residence)
Account status (active or inactive) and for some users, the account balance stored in our support system at that time
The first message or the subject of your support conversations; no further messages, no replies, no internal notes, no attachments or documents
What data was NOT affected
We have verified the following points against our access and service system logs:
Your bitcoin and euro balance: were not affected or at risk at any point. They are held on a completely separate, technically isolated infrastructure.
Your transaction history: transaction data, including bitcoin addresses, was not affected.
Passwords, 2FA codes, session data: these are not stored in the affected systems.
Residential addresses or any addresses: were not exposed at any point.
Identity documents and KYC data or documents: were not part of the affected data.
File attachments: verifiably not affected, even if you sent them to us in support conversations.
Payment and bank account details from our systems.
Our own platform and infrastructure: not compromised at any point.
What we have done so far
Permanently removed the connection to the affected provider, invalidated the stolen access key and rotated all related credentials (28/29 August).
Completed a full forensic review: analysis of all access logs, plus written confirmation of the scope from the security team of our support provider.
Directly notified everyone affected who we can reach and published this public report.
Introduce a personal security code within the next app update in our emails to protect our customers against phishing and fraud attempts.
Improved monitoring for account takeover attempts.
Requested a forensic report and root cause analysis from Canny.
What this means for you
The realistic risk is targeted phishing: criminals could use the data to write convincing emails, text messages or make phone calls in the name of 21bitcoin. Therefore, please be aware:
We will never ask you for your password, 2FA codes, or to "verify" your account via a link.
Be suspicious of any message that creates urgency (e.g. "act immediately").
Check your personal security code once you have updated the app: from 2 September 2026, genuine emails from us contain your personal code, which you can find in the app under Profile → Security → Email Security. If the code is missing → don't open it, forward it to [email protected] instead.
If you're unsure, open the 21bitcoin app directly instead of using links in messages.
Is 21bitcoin safe?
Yes. Our systems were not and are not affected and the exposed data alone cannot be used to access your account, that would require your password and second factor, which were never part of the affected data. Your bitcoin are held in segregated custody. Buying, selling and savings plans continue without restriction.
What happens next
We will update this information and this post if anything new comes up. We are also drawing the following structural conclusions:
We have introduced a new security feature: a personal security code in the 21bitcoin app that is included in every email we send, to protect our customers against phishing and fraud attempts. You can see your code in the 21bitcoin app under Profile → Security → Email Security.
We are reducing the data stored in all third-party tools to the operational minimum and tightening the requirements for external integrations.
You do not need to change your 21bitcoin login credentials or take any other action regarding your account. What we do recommend: enable app-based two-factor authentication (Profile → Security → 2FA) if you haven't already. Not because there is an immediate threat, but because it is generally the best protection against phishing.
FAQ
Are my bitcoin safe?
Yes! Your bitcoin and euro balance were not at risk at any point as a result of this incident. 21bitcoin's own systems were never compromised or affected. Custody is separate from the affected systems, and no access credentials were exposed.
Do I need to change my password?
No, your password was not affected. It isn't stored in the affected systems at all. What matters is staying alert to phishing and as a general recommendation, using app-based two-factor authentication.
How do I know if I'm affected?
We have sent a notification to everyone we were able to reach who is affected.
Were my identity documents affected?
No. KYC files and identity documents were not part of the affected data, and any file attachments in conversations were verifiably not retrieved, we confirmed this using the logs.
I received a suspicious message, what should I do?
Don't reply, don't click anything, and don't share any codes. Forward the message to [email protected]. You can recognise genuine emails from us by your personal security code.
I'm no longer a customer, why did you still have my data?
As a supervised financial services provider, we are legally required to retain certain data even after the business relationship ends for a certain time. Once those retention periods expire, the data is deleted.
Who can I contact?
Please contact our support via the in app chat or at [email protected]. Please understand that we can only share personal information through verified channels.
Our Data Protection Officer can be reached through heyData GmbH, Schützenstraße 5, 10117 Berlin, www.heydata.eu, email: [email protected].
Updates: 02.09.2026, initial publication.
