security

The Privacy Risk of Uploading Your ID to a Crypto Exchange

KYC verification requires your photo ID, selfie, and sometimes your home address. What exchanges store, who can access it, and what happens after a breach.

Know Your Customer — KYC — is the identity verification process that most centralised cryptocurrency exchanges require before you can make significant transactions. The regulatory origin is anti-money laundering law: financial services companies must verify the identity of their customers.

In practice, for a crypto exchange user, KYC typically means uploading a government-issued photo ID, taking a real-time selfie, and providing your home address — often verified with a utility bill or bank statement. Some platforms require additional documentation for higher transaction limits.

What you’ve given the exchange is a complete verified identity dossier. Understanding what happens to it is worth the time before you submit it.


What Exchanges Do With KYC Data

Compliance and Verification

The primary stated use is regulatory compliance. The exchange verifies your identity against databases to screen for sanctions, politically exposed persons lists, and adverse media. This processing typically involves passing your documents through a third-party identity verification service — Jumio, Onfido, Persona, or similar providers — rather than verifying in-house.

Your documents touch multiple systems as part of a single KYC submission: the exchange’s platform, the identity verification vendor, and any sub-processors they use.

Retention Requirements

Identity verification documents are retained by exchanges for extended periods. Regulatory requirements in many jurisdictions mandate that financial services companies retain KYC records for five years or more after the end of a customer relationship.

This is not optional for regulated exchanges: they are legally required to keep the data. This means that even after you close your account, your government ID, selfie, and address verification continue to exist in the exchange’s systems for years.

Internal Access

Your KYC data is accessible to exchange staff for compliance purposes. The scope of internal access — who can see KYC documents, under what circumstances — varies by company and is rarely disclosed in detail. A breach at Coinbase in late 2024, involving rogue customer service agents, demonstrated how internal access can be exploited: KYC data for tens of thousands of users, including government IDs and home addresses, was accessed and reportedly sold.


What Makes KYC Data Uniquely Dangerous to Lose

KYC data combines elements that are separately sensitive but become particularly dangerous together.

Government-issued ID: Unlike credit card numbers or passwords, a government ID cannot be cancelled after it’s compromised. A stolen passport scan is useful for identity fraud indefinitely.

Biometric selfie: A selfie matched to a government ID is a biometric record. It defeats selfie-based identity verification systems — the very mechanism used by exchanges and other financial services to verify identity remotely. After a breach, your selfie can be used to open accounts in your name on platforms that use the same verification process.

Home address: An address tied to a verified identity and known crypto holdings is a physical targeting risk, not just a digital one.

Linked to financial holdings: KYC data submitted to an exchange establishes a connection between a verified identity and crypto holdings. Leaked exchange data mapping verified identities to wallet sizes provides the information needed to physically locate and target holders.

Security researchers documented approximately 60 physical assaults on cryptocurrency holders in 2025, a significant portion attributed to leaked KYC data enabling attackers to identify and locate victims.


Recent Breaches

The period from 2024 through early this year saw significant KYC-related incidents.

The Coinbase incident in late 2024 involved insider access by compromised customer service agents, with government IDs and home addresses of tens of thousands of users accessed and reportedly offered for sale on criminal markets. Coinbase notified affected users but the damage to the underlying documents — which cannot be recalled — is permanent.

Researchers identified an estimated 8.2 terabytes of financial app user data exposed in what was described as the largest single KYC data leak to date. The dataset included complete KYC document packages from multiple platforms.

The NCX Exchange breach exposed more than 2 million records including passport scans and selfies.

The pattern is consistent: KYC data is collected by exchanges as a regulatory requirement, stored for extended periods, and represents a high-value target for sophisticated attackers. When a breach occurs, the data’s value to bad actors is long-lived in a way that financial credentials — which can be changed — are not.


The Trust You’re Extending

When you submit KYC to a crypto exchange, you’re making trust decisions that extend beyond the exchange itself.

The exchange’s security practices: How they store your documents, who internally has access, and how they’ve historically handled security. Track records vary considerably. The absence of a known incident is not the same as strong security.

The verification vendor: The third-party service that processes your documents during submission. This is a company you’ve likely never heard of, whose security practices you cannot evaluate at the time of submission, and whose data retention practices may differ from the exchange’s.

The regulatory relationship: Your KYC data may be shared with financial intelligence agencies, law enforcement, or foreign regulators as part of legal requirements. The scope of compelled disclosure varies by jurisdiction.

Future ownership of the exchange: The exchange you submit KYC to today may be acquired, merge with another entity, or go bankrupt. Your KYC data follows the asset. The organisation that ends up holding your identity documents might be one you would not have voluntarily provided them to.


Practical Steps to Reduce Risk

Submit Only What Is Required

Not every exchange requires the same level of verification for all activities. Some platforms offer limited functionality — smaller transaction volumes, specific asset types — with less intensive verification. If you don’t need the highest tier of account access, don’t provide the documentation required for it.

Research the Platform’s Security Track Record

Before submitting KYC to any platform, check whether the exchange has a history of security incidents specifically involving user data — not just custody failures or operational issues. Exchanges with prior KYC breaches represent elevated risk for this specific data type.

Understand the Verification Vendor

The primary vendor involved in your KYC submission is often disclosed in the exchange’s privacy policy or terms of service. Researching that vendor’s security certifications and data practices independently gives you a more complete picture of where your documents are going.

Watermark Your Documents

A practice recommended by security researchers: when uploading a government ID for KYC, add a visible watermark to the document image indicating the specific platform and approximate submission date (for example, “For [Platform Name] — [Month/Year]”).

This doesn’t prevent your document from being used in identity fraud if it’s stolen, but it adds friction. A watermarked ID is less useful for creating accounts on other platforms and more clearly identifies where a leak originated. The watermark is easy to apply with basic image editing tools before uploading.

Keep Records of Your KYC Submissions

Maintain a record of which platforms hold your KYC data, when you submitted it, what document versions you used, and any breach notifications you receive relating to each platform. This inventory is useful for monitoring, for data deletion requests, and for understanding your exposure if a specific platform reports a breach.

That record is itself sensitive information — it’s a list of places that hold your identity documents. Store it accordingly.


If a Platform You’ve Used Is Breached

Treat a KYC breach differently from a password breach. The response set is different.

Assume the documents are compromised permanently: Unlike passwords that can be changed, a government ID cannot be recalled. A passport or driver’s licence scan that has been stolen will remain useful to bad actors for as long as the document format is accepted as verification.

File an identity theft report: In the United States, report to the FTC at IdentityTheft.gov. This creates an official record and provides structured next steps. For a passport specifically, the State Department has reporting processes for compromise.

Consider fraud alerts and credit freezes: A compromised government ID is most often used to open new financial accounts rather than access existing ones. Fraud alerts with the major credit bureaus and a credit freeze provide meaningful protection against new account fraud.

Take physical security seriously if your address was included: If your home address was part of the breach and you hold meaningful crypto assets, the address risk is real given the documented pattern of physical targeting using KYC data. Post-breach physical security considerations are not hypothetical for this specific threat model.


The Trend Toward Decentralised Exchanges

The volume of crypto trading on decentralised exchanges — where no KYC is required because there’s no central operator — reached a record share of total spot trading volume in late 2025. The DEX-to-CEX spot ratio hit approximately 21%, an all-time high, with non-custodial swap volume up significantly year over year.

This trend reflects, in part, accumulated concern about centralised exchange KYC data practices and breach risk. Decentralised exchanges aren’t without risk — smart contract vulnerabilities, liquidity limitations, and the complexity of self-custody introduce different problems. But they remove the central accumulation of identity documents that makes centralised exchange breaches so consequential.


Keeping KYC Records Privately

The records you should maintain — which platforms hold your identity documents, what you submitted, breach notifications, deletion request correspondence — are worth storing somewhere that isn’t another third-party service with its own data practices.

daftei stores files with AES-256 encryption at rest, TLS 1.3 in transit, no advertising, no data selling, and no AI training on your content. Account deletion triggers a 30-day grace period followed by permanent, irreversible erasure. GDPR and CCPA compliant. Available on iOS, Android, and web at /app, with 5 GB free and unlimited storage on Pro.

Your crypto exchange submitted your identity to their systems. What you keep privately is still within your control.

Your memories deserve better than an ad platform.

Try daftei free →
← All posts