Who Knows You Own Bitcoin? The UK Crypto Privacy Trail
By Simon Bumford, Founder · · 13 min read
From exchanges and banks to couriers, advisers and data breaches, here is everyone who can link you to your bitcoin, and the legal steps UK holders can take.
More people than you think
Ask a bitcoin owner who knows about their coins and most will say nobody, that being the point. Then walk the paper trail. The exchange that verified your passport knows. The bank that processed your transfers knows. The company that posted your hardware wallet to your front door knows, and so do its courier and its fulfilment contractor, which is exactly how 13,689 Trezor customers, including UK buyers, had personal details exposed in August 2026, with full home addresses among them for 11,742. Your email inbox knows, your cloud photo library might, your accountant should, and one day your executor must. Debates about bitcoin privacy usually obsess over the blockchain itself. For an ordinary UK holder the chain is the strong link. The weak links are the perfectly mundane records that connect your real name to the fact of ownership, and they are held by more organisations and people than almost anyone realises. This guide maps every link in that trail, explains which ones you can shorten and which the law requires you to leave in place, and finishes with the awkward question privacy creates for inheritance: if nobody knows your coins exist, what happens to them when you are gone?
Pseudonymous is not anonymous
Bitcoin's ledger is public. Every transaction ever made is permanently visible to anyone, tied not to names but to addresses. That is pseudonymity, and it protects you only while nothing connects an address to you. The connection only has to be made once. Withdraw coins from an exchange that holds your passport scan, and that exchange, and anyone it lawfully reports to, can associate the destination address with your name. Pay a merchant and the merchant can do the same. Post an address in a forum signature or a social media profile and anyone can. Specialist firms such as Chainalysis, Elliptic and TRM Labs exist to industrialise those connections. They cluster addresses that behave as if commonly owned, label the wallets of exchanges and services, and sell the results to compliance teams, police forces and tax authorities worldwide. None of that machinery is secret, and none of it expires: analysis routinely unmasks transactions years after the event, because the ledger never forgets. The honest working assumption for a UK holder is that anything you do on-chain can eventually be attached to your name, so the real privacy battle is fought in the real-world records this article now walks through.
The register you signed: exchanges, KYC and HMRC
If you bought through any mainstream platform, you completed Know Your Customer checks: photo ID, home address, sometimes source of funds. UK anti-money-laundering rules require cryptoasset firms to keep that file, together with your full trading history, for years. It is the single richest record of your ownership anywhere, and closing your account does not delete it. From 1 January 2026 that record is also gathered for the tax authority by law. Under the UK's implementation of the Cryptoasset Reporting Framework, reporting platforms must collect each customer's name, date of birth, home address and National Insurance number or Unique Taxpayer Reference, along with transaction details, and file the first annual reports with HMRC by 31 May 2027. Platforms face penalties of up to £300 per customer for failing to report accurately, so they will report. Alongside this, the Self Assessment capital gains pages have carried a dedicated cryptoassets section since the 2024-25 tax year. Our CARF guide covers the regime in detail. Draw the obvious conclusion and act on it: privacy from HMRC is not on the menu, and this guide is not about seeking it. Report your gains and income accurately, keep proper records, and treat tax compliance as settled. The privacy that is actually available, and actually worth having, is privacy from criminals, data brokers and casual observers. The rest of this article deals with that.
Your bank statement tells the same story
Every faster payment to an exchange, every card purchase of crypto, every withdrawal landing back in your current account is a permanent line in your banking history: visible to the bank, retained for years, and reproducible in mortgage applications, credit disputes and legal proceedings. Banks also profile crypto activity for fraud and risk purposes, which is why some question or block transfers to exchanges. None of this is improper, and none of it is avoidable if you use the banking system at all. Just be aware of the asymmetry it creates: even if you later move everything into self-custody and never touch an exchange again, the record that you funded crypto purchases, and roughly to what value, lives on in ordinary financial plumbing with your name attached.
The parcel trail: wallet makers, shops and couriers
Buying a hardware wallet is one of the strongest ownership signals there is: nobody buys a dedicated signing device for fun. The purchase leaves your name and delivery address with the manufacturer's shop, its payment processor, its fulfilment partner and its courier. In 2026 alone that trail has leaked three times: Ledger customers' contact details through the commerce provider Global-e in January, 13,689 Trezor customers' details through the fulfilment company ShipMonk in August, and around 39,800 SafePal customers through an order-tracking flaw disclosed the same week. Ledger's 2020 breach remains the canonical case: approximately 272,000 names, home addresses and phone numbers were eventually dumped publicly, fuelling years of phishing and extortion attempts against people whose only mistake was buying a security device. The mitigations are simple and worth the small friction. Have devices delivered to a collection point, a locker or a work address rather than home. Use a dedicated email address for crypto purchases. Favour vendors that minimise data retention: Trezor's 90-day deletion policy is the reason its 2026 exposure covered three months of orders rather than years. We analysed the Trezor incident, and the response checklist for UK owners, in our guide to the Trezor data breach.
Email, phone and cloud: the quiet archive
Search your inbox for the name of any exchange or wallet maker you have used. Order confirmations, statements, withdrawal notices: an intruder in your email learns your entire crypto footprint from one search, which is why your email account deserves your strongest authentication rather than your oldest password. The NCSC now recommends passkeys wherever they are available, and an authenticator app over text-message codes elsewhere, because a criminal who takes over your phone number intercepts SMS codes wholesale. That attack is growing quickly in the UK: Cifas recorded nearly 3,000 unauthorised SIM swap cases in 2024, a rise of over 1,000 per cent in a single year. The cloud deserves equal suspicion, mostly for what reaches it by accident. A phone photo of a recovery phrase syncs silently to an account protected by a reused password. A screenshot of a balance does the same. A note titled 'crypto' is indexed and searchable. Password managers are excellent for passwords, and the NCSC endorses them, but a seed phrase is not a password: it belongs on paper or steel, offline, full stop, as our seed phrase storage guide explains. If any copy of your seed has ever touched a phone camera or a cloud note, treat moving to a fresh wallet as overdue maintenance rather than paranoia.
The professionals: accountants, advisers, solicitors and executors
Some people must know, and should. Your accountant needs your transaction history to file accurate returns, and since the platforms now tell HMRC directly under CARF, hiding holdings from your own adviser buys risk and nothing else. A financial adviser cannot plan around assets they do not know exist. A solicitor drafting your will needs to know digital assets are part of the estate. These are appropriate, confidential disclosures. The right approach is to make them deliberate: give each professional what they need in documents designed for the purpose, and remember that no legitimate professional ever needs a seed phrase. Estate paperwork needs the most care, because it is where private information is designed to surface eventually. A will becomes a public document once probate is granted, so wallet details, addresses and, catastrophically, seed phrases have no place in it. The will should acknowledge that digital assets exist and point to a separate, private process, which is exactly the structure in our guide to leaving crypto in a UK will. Executors and beneficiaries will learn of your holdings one day by design. The planning question is whether they learn from a clear, verified document set you prepared, or from a shoebox of clues and a probate delay; our executor checklist shows what they will actually need.
Family, friends and the feed
Then there is everyone you have simply told. The colleague from the last bull market. The group chat. The relative you helped set up a wallet. Each disclosure is small, human and irreversible, and criminals understand the value of talk: Chainalysis notes that attackers identify targets through exposed information including social media activity, and that a growing share of physical attacks on crypto holders, roughly a quarter to three in ten recent cases, target family members or acquaintances rather than the holder. The London kidnapping case that ended in convictions in August 2026 involved victims whose crypto wealth was known to their attackers. None of this argues for living in secrecy. It argues for noticing that 'who knows' is a decision you make repeatedly, in small moments, and mostly cannot unmake. A sensible household policy: the people closest to you should know that crypto exists and that a recovery plan exists, without amounts and without technical detail, and nobody else needs anything at all. Balance screenshots stay off the feed permanently. Our social engineering playbook shows what a motivated persuader can do with small fragments of personal information, and it is sobering reading.
When the records leak
Every organisation named so far is a database, and databases leak. The recent record in this industry alone: Ledger in 2020, with approximately 272,000 detailed records dumped publicly. Coinbase, disclosed in May 2025: overseas support contractors were bribed over months to steal customer records, including names, home addresses, government ID images, masked identifiers and account balance snapshots, for 69,461 customers; Coinbase refused the $20 million extortion demand that followed and estimated remediation costs of $180 million to $400 million in its SEC filing. Then 2026's run of supply-chain leaks at Ledger, Trezor and SafePal. Balance snapshots deserve particular attention: a breach that pairs your home address with how much you hold is this entire article's worst case in a single file. You cannot prevent other people's breaches, but you can drain their value in advance. Assume the link between your name and your coins will leak eventually, and arrange your affairs so that when it does, the breach is an annoyance rather than an emergency: your seed touches nothing digital, your accounts use passkeys, your family hangs up on urgent callers, and any theft would alert you within minutes, which is precisely the job of Bitzo's watch-only Watchtower: monitoring the addresses you choose from our own UK node rather than a public block explorer. Check what has already leaked about your email addresses at Have I Been Pwned, and learn the standard scam patterns in our guide to crypto scams in the UK.
Cutting the trail down to size, legally
A realistic privacy posture for a UK holder, in rough priority order, looks like this. Move your key accounts, email first, to passkeys and an authenticator app. Stop new records forming: collection-point delivery for hardware, a dedicated crypto email address, no balance talk online or off. Starve the chain analysts of free wins: let your wallet generate a fresh receive address for every transaction, which good wallets do by default, and never publish an address you also use for savings. Keep seeds strictly offline on paper or steel, stored where a burglar will not casually find them. Check your breach exposure periodically, and consider Cifas protective registration if a breach has already caught you. None of this is exotic, and none of it conflicts with any UK obligation: you are practising the same data hygiene the ICO and NCSC recommend to everyone, applied to an asset class where the stakes are higher. Know the limits too. Deliberately concealing cryptoassets from HMRC, from anti-money-laundering checks or from a court is not privacy, it is an offence, and the reporting architecture now in force makes it a losing strategy anyway. Equally, aggressive measures that break every link between your identity and your coins can backfire when you later need to prove legitimate ownership to a bank, a solicitor or your own executor. The target is narrower and better: full visibility for the people and authorities entitled to it, and as close to zero as possible for everyone else.
The tension nobody warns you about: privacy versus inheritance
Follow every step above perfectly and you create a new problem: holdings that nobody around you can find, recover or even prove exist. Bitcoin on a hardware wallet with a well-hidden seed is unrecoverable by design once the one person who knows everything is gone, and no court order can decrypt it. Total privacy and total continuity are opposites. Every crypto holder lives somewhere on the line between them, and most have never chosen their position deliberately. Privacy and continuity are two faces of the same personal risk layer; our four layers of crypto risk framework shows how they fit into the whole picture. The resolution is structure, not secrecy or broadcast. Keep operational details private while you are alive, and make sure a documented, verified route exists for the specific people who will need it, triggered only when it should be. That is precisely the model Bitzo runs. A non-custodial inheritance plan documents what exists and how recovery works without Bitzo, or anyone else, holding your keys or ever seeing your seed, and trusted contacts are verified in advance, so an impersonator meets a verification process rather than an open door. If you want a fast, honest measure of where your own arrangements stand, the free Bitcoin inheritance scorecard takes five minutes and asks for nothing sensitive. This guide is general information, not legal or tax advice; speak to a qualified adviser about your own circumstances. Last reviewed 18 August 2026.
Frequently Asked Questions
Is bitcoin anonymous?
No. Bitcoin is pseudonymous: transactions are public forever and tied to addresses rather than names. The moment any record links an address to you, a KYC exchange withdrawal, a delivery, a forum post, your activity on that address and anything clustered with it can be attributed to you. Assume on-chain activity can eventually be connected to your identity.
Does HMRC know I own crypto?
If you have used a regulated platform, assume yes. UK platforms hold your identity under anti-money-laundering rules, the Self Assessment form has had a dedicated cryptoassets section since 2024-25, and under the Cryptoasset Reporting Framework platforms must collect your name, date of birth, address and NI number or UTR from January 2026, with first reports filed to HMRC by 31 May 2027. Accurate reporting is the only sensible strategy.
Can my bank see that I buy crypto?
Yes. Transfers to and from exchanges appear in your account history and are retained for years, and banks profile crypto activity for fraud and risk purposes, which is why some question or restrict such payments. Buying crypto is lawful and the record is not a problem in itself; it is simply one more place where your ownership is documented.
Can someone tell how much bitcoin I own from one address?
From a single address they can see only that address's balance and history. The danger is clustering: analysts group addresses that move funds together, so one identified address can unravel a whole wallet. Good wallets generate a fresh address for every receipt, which keeps casual observers to fragments. Never publish an address that holds, or transacts with, your savings.
Is it legal to keep my crypto ownership private in the UK?
Privacy from the public, criminals and data brokers is entirely legal and sensible. What is not legal is concealment from those with a right to know: HMRC, anti-money-laundering checks when platforms request information, and courts. Privacy measures should reduce your visibility to attackers while leaving your tax and legal position fully compliant and provable.
What will UK exchanges report under CARF?
From 1 January 2026, reporting cryptoasset service providers must collect each individual user's name, date of birth, home address, country of residence and National Insurance number or UTR (or overseas tax identification number), plus transaction values, types and volumes. The first reports covering 2026 must reach HMRC by 31 May 2027, and platforms face penalties of up to £300 per user for inaccurate or missing reports.
Should I tell my family about my bitcoin?
Tell them the two facts that matter: that crypto exists, and that a recovery plan exists. They do not need amounts, addresses or technical detail, and they must never hold your seed phrase informally. Pair that disclosure with a documented recovery process for when it is genuinely needed; total secrecy usually means the coins die with you.
Sources
- GOV.UK: implementation of the Cryptoasset Reporting Framework (CARF)
- GOV.UK: collecting cryptoasset user and transaction data
- GOV.UK: reporting cryptoasset user and transaction data (deadlines and penalties)
- HMRC Cryptoassets Manual
- Trezor official disclosure: shipping provider incident (13 Aug 2026)
- Ledger: message from Ledger's CEO on the 2020 data leak
- Coinbase Form 8-K: material cybersecurity incident (14 May 2025)
- Chainalysis research: violent wrench attacks on crypto holders (6 Aug 2026)
- Cifas: unauthorised SIM swaps surged over 1,000 per cent in 2024
- NCSC: passkeys, what you need to know
- ICO: what steps should I take if I have experienced a data breach?
Ready to plan your crypto inheritance?
Speak to our UK-based team about your situation. No obligation, no pressure.
Speak to us