- On-chain investigator ZachXBT alleged that BitcoinIRA and iTrustCapital suffered data breaches in 2026 without notifying customers.
- Threat actors accessed personal details including portfolio holdings, banking info, and custodian details, according to a Telegram post.
- iTrustCapital denied the breach on X, stating it is unaware of any recent third-party vendor incidents.
- California’s tightened data breach registry does not list either company, though both have California ties.
- ZachXBT dated at least one attack to June 2026, linking it to spoofed BitcoinIRA emails.
On-chain investigator ZachXBT alleged this morning that BitcoinIRA and iTrustCapital suffered data breaches this year without disclosing them to customers. Threat actors accessed personal details such as customers’ portfolio holdings, banking details, custodian details, and verification status, according to the Telegram post.
After ZachXBT emailed both platforms on August 21 and received no response for three days, he published the alert publicly. iTrustCapital responded on X, writing, “ITrustCapital has not experienced and is not aware of any recent third-party vendor data breaches affecting our platform.” The company added that its multi-step closed-loop system is designed to mitigate losses for clients who may be compromised at a personal level.
BitcoinIRA was founded a decade ago in Sherman Oaks, California, and claims more than $14 billion in assets, according to a Bitcoin-ira-1216-1082697″>BBB listing and a profile. iTrustCapital, founded in 2018 and based in Long Beach, California, raised a $125 million Series A round in January 2022 and now claims over $17 billion in transactions across more than 300,000 accounts.
California’s Senate Bill 446, which took effect in January, gives companies 30 days to notify residents after a significant data breach. Neither BitcoinIRA nor iTrustCapital appears in the state’s breach registry, though BitcoinIRA also lists a Nevada base that may exempt it. The exact breach date is unknown, but ZachXBT dated at least one attack to June 2026, when a threat actor used spoofed BitcoinIRA emails allegedly acquired through that breach.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
