A data breach at blockchain identity provider Fractal ID has exposed sensitive know-your-customer (KYC) information for roughly 0.5% of its user base, affecting tens of thousands of users whose identities were verified for multiple Web3 projects including Gnosis Pay. According to Fractal’s incident notice, an external attacker gained unauthorized access to an operator account on July 14, 2024 and ran an API script for about two hours, accessing stored personal data such as names, email addresses, wallet addresses, phone numbers, physical addresses, and images of uploaded KYC documents like passports and driver’s licenses. Fractal said the breach was contained within its own environment and did not compromise client systems, but users of partner platforms reported receiving warning emails, including from Gnosis Pay, advising them to be cautious of unsolicited communications. The incident matters because Fractal ID is a major Web3 KYC and compliance vendor used by prominent crypto and blockchain projects, including Gnosis Pay, Polygon ID, Acala, Lukso, Ripple-related ecosystems and several other networks and companies. The breach underscores systemic privacy and security risks in centralized KYC providers serving crypto platforms, where mandated identity checks concentrate large volumes of sensitive user data that can be targeted for identity theft, phishing, and financial fraud. Fractal has reported the incident to data protection authorities and cybercrime police, and says it has implemented additional security measures, but the exposure of high-value identification documents and contact data is likely to keep scrutiny on KYC practices and vendor risk management across the broader crypto and Web3 sector.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on Gnosis Pay

Comments