Skip to main content
Should You Tell Customers Their Crypto Holdings Make Them Targets?Virtual Assets & RegTech
5 min readFor FinTech Compliance Teams

Should You Tell Customers Their Crypto Holdings Make Them Targets?

The question at hand

You're a compliance officer at a crypto exchange. Your customer database contains addresses, holdings, transaction histories, and KYC records for tens of thousands of users. Some hold seven figures. Some post about their positions on social media. Some do both.

A data breach at the French tax agency in 2024 led to over 70 violent attacks on crypto holders by mid-2026. Stolen tax dossiers contained names, addresses, phone numbers, and holdings. Criminals bought the lists and went door-to-door. France went from a handful of incidents historically to 30 documented attacks in the first half of 2026 alone.

The question: Do you have an obligation to warn customers about physical security risks tied to their digital assets? And if you do warn them, are you admitting your own data is a liability?

The case for proactive customer warnings

The argument for disclosure starts with duty of care. You hold information that makes your customers targets. Home invasions now account for 37% of violent crypto incidents in 2026, up from 26% in 2023. Attackers increasingly target family members, accounting for 25-30% of cases by early 2026. In France, that figure exceeds 40%.

Your customers may not understand this risk. They think about phishing and SIM swaps, not armed intruders. A clear, specific warning about operational security (don't post holdings, don't link social media to wallet addresses, consider custody arrangements) could prevent harm.

From a regulatory perspective, you're already required to protect customer data under frameworks like GDPR, PCI DSS, and various national data protection laws. But those frameworks focus on preventing breaches, not mitigating the consequences when breaches happen elsewhere. If a tax authority or third-party service provider leaks customer information, your users face the same physical threat.

Some compliance teams argue that customer education is part of a risk-based approach. If you've identified a material threat to customer safety, staying silent could expose you to negligence claims if an attack occurs and the victim can demonstrate you knew about the pattern but said nothing.

There's also a competitive angle. Exchanges that proactively warn customers and offer guidance on secure custody, privacy practices, and operational security may build trust. Customers who feel protected are less likely to move assets elsewhere after a breach.

The case for staying silent

The counterargument is equally straightforward: warning customers about physical attacks implies your data is a target, which undermines confidence in your security posture.

If you send a mass communication saying "violent attacks are rising, here's how to protect yourself," customers will ask why you're telling them this now. The subtext is that you believe your own database could be compromised. Even if your controls are strong, the warning itself creates doubt.

There's also a legal risk. If you warn customers and an attack still occurs, you may face claims that your warning was inadequate or that you should have done more than issue guidance. Conversely, if you don't warn customers and no attack occurs, you've avoided creating unnecessary alarm.

From a compliance workflow perspective, customer warnings are hard to standardize. What threshold triggers a warning? If violent attacks are concentrated in France, do you warn only French customers? What about customers who travel frequently or have listed French addresses in the past? Do you warn all high-balance accounts, or only those above a certain threshold?

These questions don't have clean answers, and inconsistent warnings could create discrimination claims or regulatory scrutiny.

Some compliance officers also point out that physical security is outside their remit. Your job is to prevent money laundering, sanctions violations, and fraud. Physical security is a personal responsibility. You're not a bodyguard service. Warning customers about wrench attacks sets a precedent that you're responsible for threats beyond your control.

Where practitioners actually land

Most exchanges do nothing, at least publicly. There's no widespread practice of sending physical security warnings to customers, even in jurisdictions where violent attacks have spiked.

The exceptions are reactive, not proactive. After the French tax breach became public in early 2026, some French exchanges quietly updated their privacy policies and terms of service to include language about physical security risks. A few sent targeted emails to high-net-worth customers recommending hardware wallets and advising against public disclosure of holdings.

But these were outliers. The default industry position is that physical security is the customer's problem. Exchanges focus on securing their own infrastructure and complying with data protection laws. What happens after a breach at a third party is treated as outside their control.

Law enforcement is starting to push back. In France, Interior Minister Laurent Nuñez announced plans for a rapid identification and alert system for at-risk figures in the crypto sector. That suggests a regulatory expectation that someone, whether exchanges or authorities, should be warning potential targets.

Our take

You should warn customers, but narrow the scope.

The French tax breach proves that data you don't control can still put your customers at risk. If a tax authority, a third-party reporting service, or even a social media platform leaks information that links identities to holdings, your customers become targets. You can't prevent that, but you can prepare them.

The warning doesn't need to be alarmist. Frame it as operational security guidance tied to industry trends. Reference the fact that home invasions targeting crypto holders increased from 26% to 37% of incidents between 2023 and 2026. Recommend specific practices: don't link social media profiles to wallet addresses, don't post about holdings, consider multi-signature custody, and review who has access to recovery phrases.

Target the warning to high-risk segments. Customers with balances above a certain threshold, customers in jurisdictions with recent attack clusters, and customers who've opted into public-facing features should receive tailored guidance.

Document everything. If you issue warnings, keep records of what you sent, when, and to whom. If you decide not to warn customers, document the risk assessment that led to that decision. Either way, you need a defensible position if an attack occurs and regulators ask what you knew and when.

The tradeoff is real: warning customers may create anxiety and undermine confidence in your security. But the alternative is worse. If a customer is attacked and later discovers you had data showing a pattern of incidents but stayed silent, the liability and reputational damage will exceed whatever short-term confidence you preserved.

Physical security is outside your technical control, but it's not outside your duty of care.

You Might Also Like