/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

FTX, Genesis, and BlockFi customer data is compromised after a SIM swap against an employee of Kroll, which manages creditor claims for the bankrupt companies

A ‘cybersecurity incident’ affected Kroll, which gathers customer claim data on behalf of bankrupt companies.  —  Register Now

CoinDesk Jack Schickler

Context & Ripple Effects

The incident sits within the operational fallout of several crypto bankruptcies: Kroll was handling creditor claims for FTX, Genesis, and BlockFi, concentrating sensitive customer records in a third-party workflow. Follow-up coverage identified the event as a SIM-swap breach affecting the three creditor groups.

For FTX customers, the exposure adds a privacy and fraud risk alongside an already difficult recovery process. Later reporting on FTX customer information provided to the FBI illustrates how widely such data can circulate during a large bankruptcy, even when disclosure is legally required.

First-order effects

  • Customers whose claims data was held by Kroll face heightened phishing and identity-fraud risk, while Kroll and the affected estates must manage incident response and creditor communications.
  • The breach makes a single employee’s mobile-number security a point of failure for claim-administration systems serving multiple bankruptcies.

Second-order effects

  • Bankruptcy administrators and crypto firms handling creditor records face pressure to reduce reliance on phone-based account recovery and tighten access controls around customer-data repositories.
  • Creditors may become more cautious about communications that appear to come from an estate or claims agent, making legitimate recovery updates harder to distinguish from scams.

Third-order effects

  • If similar incidents persist, custodians of insolvency data may be judged as core risk holders rather than back-office vendors, raising the security expectations attached to outsourced claims administration.
  • The episode reinforces a broader credibility challenge for crypto markets: failures at exchanges can continue to expose customers through the legal and administrative processes that follow collapse.

The trend: Crypto failures are increasingly creating long-tail security risks as customer data moves through third-party restructuring and claims systems.

Discussion

  • @carnage4life Dare Obasanjo on threads
    After all the legal drama around whether the names of FTX's customers should be released unredacted, the customer info ended up getting hacked from the company that handles the customer data for a bunch of bankrupt crypto firms.  🤦🏾‍♂️
  • @blockfi @blockfi on x
    Regarding recent third-party data incident: [image]
  • @ftx_official @ftx_official on x
    (1/3) FTX learned that Kroll, the claims agent in the bankruptcy, experienced a cybersecurity incident that compromised non-sensitive customer data of certain claimants in the pending bankruptcy case.
  • @davidgerard @davidgerard on x
    this is the same creditor data that FTX previously argued to the court was so not “non-sensitive” that they wanted it all sealed permanently
  • @functi0nzer0 Laurence on x
    I signed up to FTX three months before it collapsed only to find out that I couldn't trade what I wanted there as a UK resident, so never used it and they still leaked my details lmao I'm gonna get back more from Kroll from a class action than I am from the liquidators
  • @molly0xfff Molly White on x
    it's a little rich for FTX to describe names, addresses, and account balances as “non-sensitive customer data” after arguing at great length in court that that very same data was so sensitive it needed to be filed under seal
  • @bennetttomlin Bennett Tomlin on x
    There's a lot of bankruptcies that use Kroll, going to be a lot of data floating around
  • @bantg @bantg on x
    client data of everyone who used blockfi and ftx has leaked from kroll. this is the exact consequence of kyc. kyc stands for amassing lucrative datasets for hackers.
  • @cryptoparadyme @cryptoparadyme on x
    What customer data is non-sensitive?
  • @angelclarksays @angelclarksays on x
    and this explains why i got a bunch of emails today telling me i could pull out funds finally. so not only has ftx stolen from us, they now gave our data to scammers.
  • @corpseinorbit @corpseinorbit on x
    The Kroll Corporation “losing” FTX's customer database is the best evidence yet that I'm right and crypto is primarily an intelligence scheme
  • r/CryptoCurrency r on reddit
    Kroll Employee SIM-Swapped for Crypto Investor Data
  • r/ThePPShow r on reddit
    Looks like Kroll got hacked 🔥😬🔥