Have I Been Drained 2025 Data Breach

Have I Been Drained (HIBD) Crypto Wallet Compiliation (2025): 13.5 Million Records Including Account Balances & Phone Numbers from Multiple Platforms

Compilation · Aggregated cryptocurrency-user breach dataset · Multi-source re-indexed exposure dataset targeting crypto account holders · Global

Have I Been Drained (HIBD) Crypto Wallet Compiliation (2025): 13.5 Million Records Including Account Balances & Phone Numbers from Multiple Platforms

Aggregated cryptocurrency-user breach compilation assembled from multiple prior incidents and marketed as a targeting dataset for crypto holders

Compilation · ObscureIQ Intelligence
Breach Risk Index i
54/100
Lower riskHigher risk
Moderate: notable exposure with meaningful misuse potential.
Data Sensitivity i
Elevated
Exposed data raises the risk of fraud, targeting, and impersonation. Proactive steps are warranted.
13.5MRecords
2025Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
FinancialAccount Balance
Classification Tags
Unknown (aggregator)Scraping / CollectionCryptocurrencyUsers2025

Breach Summary

"Have I Been Drained" is a compilation of about 13.5 million cryptocurrency-user records aggregated from multiple prior incidents and circulated as a targeting dataset. It pairs names, email addresses, and phone numbers with account-balance information, making it especially useful for targeting crypto holders.

Full threat analysis, exploitation vectors, and principal guidance below.

10 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

13.5M records analyzed

About Have I Been Drained

"Have I Been Drained" is not a company but an aggregated dataset of cryptocurrency users, compiled from multiple prior breaches and marketed as a targeting list for crypto holders.

Why They Hold Your Data

This dataset is best understood as a cross-platform compilation of user records drawn from multiple cryptocurrency-related services, including exchange, portfolio, token, and crypto-adjacent platforms. The reported fields include email addresses, phone numbers, full names, wallet addresses, IP or location data, account balances, and in some descriptions KYC-related status or transaction-linked details, making it a stitched identity-and-asset mapping dataset rather than the native customer database of a single company

Data Points Exposed

4 verified field types
Account Balance High
Email Address
Full Name
Phone Number

Breach Impact

The pairing of contact details with crypto account balances enables highly targeted phishing, social engineering, SIM-swap, and wallet-drainer attacks against holders, with balance data letting attackers prioritize high-value victims.

Exploitation & Downstream Threats

• SIM swap attacks where phone numbers are present | • Targeted phishing campaigns using exposed email addresses

Principal Risk Advisory

What this means for a principal

A financial-institution breach: account, wealth or payment data supports direct fraud and highly credible financial-impersonation scams. For a high-profile principal the main risk is credible impersonation and enrichment of existing exposure.

What You Should Do

  1. Guard against SIM-swap and vishing: add a carrier port-out PIN and verify any 'support' calls independently.
  2. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping and footprint neutralization: cross-reference against broker-available data and suppress still-removable elements, prioritizing address and phone, since this record re-seeds broker networks.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).
U(
Threat Actor: Unknown (aggregator)
Threat actor

Attribution based on available breach intelligence.

Read the full threat-actor profile →

Protect Yourself

Check If You're Affected

Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation