Evolve Bank & Trust, a U.S.-based financial institution widely recognized for its partnerships with cryptocurrency companies, has confirmed a major cybersecurity breach. The notorious ransomware group Lockbit 3.0 reportedly leaked a trove of customers' personal identification data on the dark web, including names, Social Security numbers, and account details. The incident has sent shockwaves through the crypto community, raising urgent questions about the security of digital assets and personal information held by traditional banking partners.
Attack Details: Lockbit 3.0 Escalates
In a statement released Thursday, Evolve Bank acknowledged that unauthorized access to its systems resulted in the theft of customer data. Cybersecurity analysts identify Lockbit 3.0 as one of the most sophisticated ransomware-as-a-service (RaaS) operations active today, employing double extortion tactics—encrypting files and threatening to publish stolen data if ransoms are not paid. According to dark web monitoring services, the leaked dataset includes records of tens of thousands of customers, many of whom are users of crypto exchanges, wallet providers, and other digital asset platforms that rely on Evolve Bank for fiat transaction rails. The bank has since engaged external cybersecurity forensics teams and is cooperating with law enforcement agencies.
Impact on the Crypto Industry
Evolve Bank has long served as a critical banking partner for fintech and crypto companies, offering account and payment processing services that enable customers to convert between fiat and digital currencies. This breach exposes a vulnerable link in the crypto ecosystem: the reliance on traditional financial infrastructure for onboarding and settlements. Leaked personal data can be weaponized for social engineering attacks, including phishing campaigns impersonating bank or exchange representatives. Blockchain security firms warn that affected users may face targeted scams designed to drain their crypto wallets. The incident also highlights regulatory risks, as banks handling crypto-related accounts must meet stringent data protection and anti-money laundering standards.
Bank Response and User Guidance
Evolve Bank announced it will provide complimentary credit monitoring and identity theft protection services for 12 months to all impacted customers. Notifications are being sent via email and postal mail. The bank strongly advises customers to change passwords for any accounts associated with Evolve, enable multi-factor authentication, and monitor bank statements and crypto wallet activity closely for unauthorized transactions. Security experts in the crypto space have issued additional recommendations: avoid clicking unsolicited links or email attachments; be skeptical of urgent messages claiming to be from the bank or a crypto platform; and immediately contact customer support if suspicious activity is detected. Users should also freeze their credit with major bureaus as a precautionary measure.
Regulatory and Market Reaction
As news of the breach spread, U.S. regulators including the Federal Reserve and the Consumer Financial Protection Bureau have expressed concern. However, the crypto market showed relative stability, with Bitcoin and major altcoins experiencing no significant price swings. Analysts suggest that while the immediate market impact is muted, the breach could fuel stricter regulatory scrutiny of banking partnerships with crypto firms, particularly around data security, third-party risk management, and incident disclosure protocols. In the long run, both traditional banks and crypto-native companies may need to invest in advanced data segregation, encryption, and zero-trust architectures to prevent similar incidents.
The Evolve Bank breach serves as a stark reminder that as cryptocurrencies gain mainstream adoption, the interfaces between legacy finance and digital assets become high-value targets for cybercriminals. Users must treat their personal information as carefully as their private keys—and demand that financial partners uphold the highest security standards.

