QuiverCrypto QUIVERCRYPTO SUBSCRIBE
QuiverCrypto
← Blog

Allegations of hidden data breaches at BitcoinIRA and iTrustCapital

ZachXBT claims BitcoinIRA and iTrustCapital concealed data breaches affecting customers. Explore the details behind this troubling allegation.

22 September 2026 · 5 min read
Allegations of hidden surveillance/">data breaches at BitcoinIRA and iTrustCapital

Investigations by on-chain security analyst ZachXBT have raised serious concerns about potential data breaches at two prominent cryptocurrency retirement account services: BitcoinIRA and iTrustCapital. The allegations suggest that both companies failed to disclose breaches that compromised sensitive customer information, leading to victimization by malicious actors who accessed stolen data.

Background on the companies involved

Founded a decade ago in Sherman Oaks, California, BitcoinIRA has positioned itself as the original service that allows individuals to hold Bitcoin (BTC) within a retirement account. The platform touts over $14 billion in asset holdings.

In contrast, iTrustCapital emerged in 2018, founded by Todd Southwick and Blake Skadron. Initially based in Long Beach, California, it achieved significant recognition after raising $125 million in a Series A funding round in January 2022. iTrustCapital claims to have processed more than $10 billion in cumulative transactions, and its homepage now boasts figures of over $17 billion across more than 300,000 accounts.

Details of the allegations

On August 21, ZachXBT disclosed that he had pinpointed potential breaches involving both companies. He asserted that threat actors had accessed a range of personal customer information, including portfolio holdings, banking details, and verification statuses. His investigations indicated that at least one attack may have occurred as early as June 2026. Following his findings, he reached out to both companies for clarification but received no response within three days, prompting him to make the information public.

iTrustCapital issued a statement via social media, denying any awareness of recent data breaches and asserting that their multi-layered system is designed to mitigate risks for clients potentially targeted by hackers. On the other hand, BitcoinIRA had not provided any comment or denial at the time of this report.

The implications of California's data breach laws

Both companies are headquartered in California, where laws governing data breach disclosures have recently become more stringent. Senate Bill 446, enacted in 2025 and effective early this year, mandates businesses to notify customers within 30 days of discovering a significant breach. If the breach affects over 500 residents, firms must also notify the state attorney general within an additional 15 days.

Interestingly, BitcoinIRA and iTrustCapital do not appear in the state registry of reported data breaches—this despite the fact that data breaches involving fewer than 500 individuals may also be unreported. BitcoinIRA’s operations extend to Nevada, potentially complicating its obligations under the California registry.

Understanding the risks to customers

While both companies continue to assert they are not aware of any breaches, the absence of transparency can raise concerns for users entrusting their sensitive information to these platforms. The ramifications of data breaches in the cryptocurrency sector can be severe, often leading to financial losses through identity theft and various types of fraud.

ZachXBT's findings, coupled with an apparent increase in attacks on crypto platforms, underscore the necessity for rigorous cybersecurity measures within the industry. iTrustCapital has stated that the integrity of funds is protected against external threats, even if the user’s email or login information has been compromised. This highlights a ‘closed-loop’ system designed to enhance customer security against common threats in the digital asset space.

The growing concern for data security in crypto

As the cryptocurrency market expands and more individuals seek to invest through innovative platforms like BitcoinIRA and iTrustCapital, the exposure to data breaches becomes a pressing issue. Customer trust is paramount, and any suggestion of hidden breaches is likely to erode confidence in these companies.

As crypto services proliferate, users must be vigilant, staying informed about the security measures surrounding their digital assets. The incidents surrounding BitcoinIRA and iTrustCapital serve as a powerful reminder of the importance of transparency and accountability in the crypto industry.

Looking forward in data security and customer trust

The investigations into BitcoinIRA and iTrustCapital’s alleged data breaches highlight the critical need for transparent and timely reporting in the cryptocurrency industry. With regulations tightening and consumer awareness growing, companies in this space must prioritize security to retain customer trust and adhere to evolving legal standards.

The response from iTrustCapital illustrates an awareness of the challenges presented by cyber threats. However, ongoing vigilance and proactivity will be necessary as the ecosystem continues to mature. Customers must remain aware and informed regarding their chosen platforms, demanding accountability to ensure their investments remain safe.

Frequently asked questions about the allegations

What are BitcoinIRA and iTrustCapital?

Both companies offer platforms for holding cryptocurrencies within retirement accounts, allowing customers to invest in digital assets as part of their retirement savings strategy.

What data breaches are alleged against these companies?

ZachXBT alleges that BitcoinIRA and iTrustCapital suffered data breaches this year, compromising customer information such as banking details and portfolio holdings.

How should customers protect themselves during such incidents?

Customers should remain vigilant by monitoring their financial accounts, utilize strong passwords, and enable two-factor authentication. It's also wise to stay informed about potential security breaches and the response from the companies involved.