Razed Exposes 183 VIP Email Addresses, Calls It Human Error

A VIP host cc'd 183 recipients on one email, letting high rollers see each other's addresses. Razed says it was human error, and has acknowledged it only in a single reply on X.

Header image (style 3): Razed Exposes 183 VIP Email Addresses, Calls It Human Error

Crypto casino Razed exposed the email addresses of 183 VIP customers to one another in a single mass email, an error the company acknowledged on July 27.

The recipient list paired usernames with the addresses of confirmed high-stakes players. The gambling account @YogiGambles, which published a redacted screenshot of the list, called the incident a possible violation of the General Data Protection Regulation (GDPR), the European Union's privacy law.

That is the account's characterization, not a regulator's finding.

Razed Calls It Human Error, Not a Breach

A VIP host cc'd the recipients instead of sending individual emails, according to @MarkRazed, a verified account replying on the operator's behalf 11 hours later.

This was not a breach, but a human error. Measures have been taken to ensure this is not possible again.

That reply is the only acknowledgement Razed has made. The company's main @Razedcom account has not mentioned the incident, and the reply drew 1,200 views against 31,400 for the post it answered.

The account also rejected the scale of the claim, calling the "largest breach" framing engagement farming while saying the small subset involved "by no means reduces the seriousness of this."

@YogiGambles replied that the addresses are worth money to third parties and marketing agencies because they belong to high-value customers.

Exposed VIP Lists Invite Spearphishing

An address tied to a known high roller is a precise target for fraud aimed at one person. Players can limit that exposure by using a platform-specific or burner email address for each gambling site, so one operator's mistake cannot be matched to their identity elsewhere.

The error itself is common. The UK's Information Commissioner's Office has recorded nearly 1,000 breaches since 2019 from senders using cc or "to" instead of bcc, and warns that showing who received an email can itself disclose confidential information about them.

Razed has not said publicly whether it notified the 183 affected customers or any data protection authority, and no regulator has said it is examining the incident as of writing.

Mission Statement

Crypto gambling has a transparency problem. We're fixing it.

On-chain data and original research, not recycled press releases

Honest operator reviews and news, free from affiliate influence

Player-first reporting built on transparency and responsible gambling