FTX, Genesis, and BlockFi customer data is compromised after a SIM swap against an employee of Kroll, which manages creditor claims for the bankrupt companies
A ‘cybersecurity incident’ affected Kroll, which gathers customer claim data on behalf of bankrupt companies. — Register Now
CoinDeskJack Schickler
Context & Ripple Effects
The incident sits within the operational fallout of several crypto bankruptcies: Kroll was handling creditor claims for FTX, Genesis, and BlockFi, concentrating sensitive customer records in a third-party workflow. Follow-up coverage identified the event as a SIM-swap breach affecting the three creditor groups.
For FTX customers, the exposure adds a privacy and fraud risk alongside an already difficult recovery process. Later reporting on FTX customer information provided to the FBI illustrates how widely such data can circulate during a large bankruptcy, even when disclosure is legally required.
First-order effects
Customers whose claims data was held by Kroll face heightened phishing and identity-fraud risk, while Kroll and the affected estates must manage incident response and creditor communications.
The breach makes a single employee’s mobile-number security a point of failure for claim-administration systems serving multiple bankruptcies.
Second-order effects
Bankruptcy administrators and crypto firms handling creditor records face pressure to reduce reliance on phone-based account recovery and tighten access controls around customer-data repositories.
Creditors may become more cautious about communications that appear to come from an estate or claims agent, making legitimate recovery updates harder to distinguish from scams.
Third-order effects
If similar incidents persist, custodians of insolvency data may be judged as core risk holders rather than back-office vendors, raising the security expectations attached to outsourced claims administration.
The episode reinforces a broader credibility challenge for crypto markets: failures at exchanges can continue to expose customers through the legal and administrative processes that follow collapse.
The trend: Crypto failures are increasingly creating long-tail security risks as customer data moves through third-party restructuring and claims systems.
After all the legal drama around whether the names of FTX's customers should be released unredacted, the customer info ended up getting hacked from the company that handles the customer data for a bunch of bankrupt crypto firms. 🤦🏾♂️
(1/3) FTX learned that Kroll, the claims agent in the bankruptcy, experienced a cybersecurity incident that compromised non-sensitive customer data of certain claimants in the pending bankruptcy case.
I signed up to FTX three months before it collapsed only to find out that I couldn't trade what I wanted there as a UK resident, so never used it and they still leaked my details lmao I'm gonna get back more from Kroll from a class action than I am from the liquidators
it's a little rich for FTX to describe names, addresses, and account balances as “non-sensitive customer data” after arguing at great length in court that that very same data was so sensitive it needed to be filed under seal
client data of everyone who used blockfi and ftx has leaked from kroll. this is the exact consequence of kyc. kyc stands for amassing lucrative datasets for hackers.
and this explains why i got a bunch of emails today telling me i could pull out funds finally. so not only has ftx stolen from us, they now gave our data to scammers.