Glassnode Data Breach: Customer Data Exposed, Users Warned About Phishing
The on-chain analytics provider is notifying customers of a security incident by email. No public statement is live yet. Here is what the disclosure says, and what Glassnode users should do now.
- Glassnode is notifying customers by email of a security incident under investigation; email addresses may have been exposed.
- The company itself warns of phishing attempts impersonating Glassnode, and confirms it has no phone support: any call in its name is fraud.
- No public statement was live when this article was published on July 22, 2026. Scope and root cause are unconfirmed.
- If you use Glassnode: log in only by typing the URL, rotate a reused password, enable 2FA, and expect targeted phishing in the coming weeks.
Glassnode customers woke up to an unusual email on July 22: a Security Notice from the analytics provider itself, disclosing an incident "currently under investigation" and warning that customer data "such as your email address" may have been exposed. At the time of publication there is no public statement on Glassnode's channels. We received the disclosure directly, as customers.
What the Glassnode security notice says
Glassnode disclosed a security incident by customer email on July 22, 2026, and said data such as email addresses may have been exposed. The notice says the incident is under investigation and asks users to stay vigilant against phishing or other suspicious communications claiming to be from Glassnode. Two operational details stand out: the company's only email domain is glassnode.com, and it has no customer phone number, so any call in Glassnode's name is fraudulent by definition.
The email promises further updates "if any additional action is required". It does not say when the incident happened, how many customers are affected, or whether anything beyond email addresses was accessed. The disclosure is published below as received, with personal details removed.

What is Glassnode, and why this list matters
Glassnode is one of the most used on-chain analytics platforms in crypto: Swiss-based, founded in 2018, and the source of the Bitcoin charts that circulate through research desks and crypto social feeds every day. Its Glassnode Studio dashboards track Bitcoin and Ethereum network activity, exchange flows and bitcoin volatility analytics for retail subscribers and hundreds of institutions.
That profile is exactly why an exposed customer list is worth more than a random email dump. Every address on it belongs to someone who follows, holds or trades crypto. For phishing operators, that is a pre-qualified target list.
The playbook that usually follows
Leaked crypto customer lists get worked for years, and the Ledger breach of 2020 is the template. After 270,000+ customer records leaked from the hardware wallet maker, users faced waves of fake security emails, SMS campaigns and, in the worst cases, threats referencing home addresses. The Glassnode exposure looks far narrower on current information, email addresses rather than home addresses, but the mechanics repeat: the attack is not the breach itself, it is the months of impersonation that follow.
The first wave usually imitates the breached company: password resets, security upgrades, refund offers. If an email pushes you to click a Glassnode login link, that is the tell. Real damage control never needs your seed phrase, your exchange password or a phone call.
What Glassnode users should do now
4 steps cover most of the risk: reach the site by typing the URL instead of clicking links, rotate the password if you reuse it anywhere, switch on 2FA, and treat every unexpected crypto email as hostile for the next few months. None of this needs to wait for Glassnode's next update. If your Glassnode email address is the same one you use at your exchange, raise your guard there too: attackers cross-reference lists, and exchange phishing pays better than analytics phishing.
What remains unknown: the scope, the root cause, whether data beyond email addresses was touched, and why the disclosure reached inboxes before any public channel. We will update this article as Glassnode publishes more. Until then, this incident teaches the safest assumption about any crypto service: data that was never collected cannot leak.
Trade with less data at risk
Trade Reclaim works from your public exchange UID alone: no API keys, no account access, no trading data of yours stored. It returns 30 to 50% of every trading fee while doing it.
Frequently asked questions
Was Glassnode hacked?
Glassnode has confirmed a security incident that is under investigation and told customers that data such as email addresses may have been exposed. The company has not called it a hack, named a cause, or published a public statement as of July 22, 2026. This article is based on the customer disclosure email and will be updated as official information appears.
What Glassnode data was exposed?
The disclosure names email addresses as the data that may have been exposed and lists no other categories. Payment information, passwords and account contents are not mentioned in the notice. The exact scope stays unconfirmed until Glassnode publishes details, which is why the safe assumption for now is: your email is on a list, act accordingly.
Is it safe to keep using Glassnode Studio?
Nothing in the disclosure suggests the analytics platform itself is compromised, and Glassnode Studio remains reachable as normal. The risk sits in your inbox, not in the dashboards: use a unique password, enable 2FA, and reach the site by typing glassnode.com yourself rather than following any email link, including ones that look like they come from Glassnode.
Trade Reclaim Research tracks trading fees, VIP schedules and rebate programs across 11 crypto exchanges. Every rate in our articles comes from the exchange's official fee schedule and is re-verified on publication. The team trades on the platforms it writes about.
Trade Reclaim earns from exchange referrals and shares most of it back to you as cashback. Education, not financial advice.