Crypto Finance Users Exposed: The Nexo Breach Leaked 1.65 Million Email Addresses and Phone Numbers
Nexo, the Switzerland-based cryptocurrency financial services platform, had 1,652,793 user records stolen from its database in October 2024. The breach exposed email addresses and partial phone numbers for over 1.6 million accounts. For a fintech platform where users hold cryptocurrency assets, these two data points are far more dangerous than they appear. Email and phone are the two primary recovery channels for crypto accounts, and attackers with access to this list are positioned to launch SIM-swap attacks and phishing campaigns specifically engineered to drain digital wallets.
Why This Is Dangerous
Cryptocurrency is irreversible. Unlike a fraudulent bank transfer, funds moved out of a crypto wallet cannot be recalled or reversed. An attacker who successfully takes over a Nexo account, or compromises the email and phone linked to it, can initiate withdrawals that are final within minutes. The combination of email addresses and phone numbers from this breach gives attackers both vectors needed to bypass account recovery systems. Phone numbers enable SIM-swap attacks that transfer a victim's mobile number to an attacker-controlled SIM card, immediately defeating SMS-based two-factor authentication. Email addresses enable phishing campaigns that impersonate Nexo security alerts to trick users into handing over login credentials.
What Was Exposed
- Email Address
- Phone Number (partial)
Why This Matters
In the crypto fintech sector, contact details are attack vectors, not just identifiers:
- Credential stuffing: Email addresses from this breach are tested against passwords sourced from other leaks across Nexo and any platform where the user reused credentials, including other crypto exchanges.
- Account takeover: Successful credential stuffing on a Nexo account gives an attacker access to crypto lending balances, withdrawal permissions, and linked bank accounts.
- Identity theft: Email and phone together are sufficient for fraudsters to impersonate victims with mobile carriers, financial institutions, and other crypto platforms during account recovery attempts.
- Fraud: Targeted phishing messages impersonating Nexo security teams, using the victim's real email and referencing their account, drive users to credential-harvesting sites at a much higher success rate than generic scams.
How a Database Breach Works
A database breach occurs when an attacker gains unauthorized access to a company's user data systems. In fintech and crypto platforms, this typically happens through exploited application vulnerabilities, compromised internal credentials, or attacks on third-party services with API access to customer data. Once inside, the attacker exports user account tables and exfiltrates the data. The records are then sold on dark web forums or used directly in follow-on attacks. Given the high value of crypto accounts, fintech user databases command premium prices among cybercriminals and the buyer pool includes both credential stuffers and targeted fraud operators.
Check If You Are Affected
Heroic indexes over 400 billion compromised records, including data from the Nexo breach. If you have an account with Nexo or used your email to register for any cryptocurrency financial service, search now to see if your information is in the database.
Breach Breakdown
1,652,793 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds