DriveWealth provides a global Brokerage-as-a-Service (BaaS) fintech platform that lets banks, broker dealers, asset managers, digital wallets, and consumer brands add investing and trading to their offerings. It does this through APIs that partners integrate into their own products, providing a modern toolkit to support traditional investment workflows and newer ideas like rounding up purchases into fractional-share ownership. Compared with competitors, DriveWealth differentiates itself by its broad B2B focus and extensible API platform that enables a wide range of partner integrations, from traditional investment processes to micro-investing features, all under a scalable, partner-first model. The company's goal is to help partners embed investing experiences into their services and generate revenue by charging fees for access to its platform and services.
Company Size
201-500
Company Stage
Series D
Total Funding
$552.8M
Headquarters
New York City, New York
Founded
2012
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Insurance – Medical, Dental, Vision, Life, LTD & STD. HSA and FSA options.
Unlimited PTO
401k plan
Flexible working hours and work from home
Continuing education and conferences reimbursement
Fitness/Wellbeing reimbursement
Home Office stipend
Lunch program, snacks and beverages available in the office
Second data breach hits Revolut after service provider cyber attack. Revolut reported a second data security incident this month after service provider DriveWealth suffered a cyber attack that exposed sensitive customer information. Revolut is a London-based digital banking platform offering services such as multi-currency accounts, global payments, savings, budgeting, and investments. DriveWealth is a US-based B2B fintech that provides Brokerage-as-a-Service, powering the trading and brokerage infrastructure behind Revolut's US stock investment services. In a data security incident notice published on its website, Revolut said DriveWealth had recently notified the company that an unauthorised third party had gained access to customer data stored on its systems. While Revolut did not disclose the specific data that was compromised, it explained that customers signing up for US investment services entered into two agreements - one with the relevant Revolut trading entity and another with US-based DriveWealth. As a result, the information required to provide the trading services was shared with both companies. "Revolut's own systems, app infrastructure, and core databases were not accessed or affected in any way. All Revolut customer funds and investments remain completely safe. "All affected Revolut customers have received two emails, one from DriveWealth and one from Revolut, confirming they were impacted and explaining the scope of the breach," the fintech giant said. In a notice detailing the incident, DriveWealth said that an unauthorised party gained access to its internal network between September 4 and September 5 and accessed personal data contained in certain systems. The compromised data included personal identifiers, but DriveWealth confirmed that passwords and financial information, such as credit card and bank account details, were not affected. "No unauthorised brokerage account activity including trading, transfer, withdrawal, ACAT request, or balance or position alteration was identified. Production brokerage and trading systems and the client-facing platform were not impacted by this activity and continue to operate normally," DriveWealth said. The brokerage company advised all affected individuals to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to law enforcement authorities, including the police and the state attorney general. Earlier this month, Revolut reported another data security incident after threat actors impersonated a legitimate government agency using a spoofed email domain to request sensitive information from the company.
Bullish coalition pushes real ownership for tokenized stocks. Bullish, Equiniti, Alpaca, Apex Fintech Solutions and DriveWealth formed a coalition to develop issuer-sponsored tokenized shares. The initiative aims to preserve shareholder rights. It also seeks stronger links between blockchain markets and traditional equities. Published on: 26 Sep 2026, 11:00 am Updated on: 26 Sep 2026, 11:00 am Bullish and Equiniti have launched the Issuer Sponsored Token Coalition alongside Alpaca, Apex Fintech Solutions and DriveWealth. The group wants tokenized public shares tied directly to companies' official shareholder registers. The coalition will work on standards, infrastructure and operating frameworks for issuer-sponsored tokenized securities. Its members also want blockchain-based securities to operate alongside existing capital markets. At the center of the initiative lies a key ownership issue. Some products marketed as tokenized equities may not give investors the same rights as traditional shares. Coalition targets shareholder rights in tokenized stocks. Under the coalition's proposed issuer-sponsored model, tokenized securities would connect directly with an issuer's authoritative shareholder register. That structure could preserve voting rights, dividends and corporate-action entitlements. As a result, investors holding qualifying tokenized securities could maintain the ownership protections associated with ordinary public shares. Blockchain technology would provide new infrastructure without separating shareholders from issuers. DriveWealth CEO Naureen Hassan said much of what markets currently describe as tokenized equity does not represent direct equity ownership. She said the coalition intends to address that gap. Hassan added that an issuer-sponsored model can retain voting rights and corporate-action entitlements while market infrastructure moves onchain. DriveWealth will help develop the model alongside the other coalition members. The coalition therefore centers its work on direct ownership rather than simply creating blockchain-linked exposure to listed shares. SEC framework shapes emerging onchain equity market. The coalition's launch follows the U.S. Securities and Exchange Commission's September 17 Innovation Exemption. The measure permits limited onchain trading involving U.S.-listed equities. Under the SEC framework, venues must verify that tokenized stocks provide holders with the same rights and privileges as their traditional equivalents. That requirement places shareholder treatment at the center of onchain equity development. The relief will remain available for five years. Meanwhile, the SEC is seeking public comments on how the framework should develop as tokenized markets expand. For the coalition, those requirements align with its issuer-sponsored approach. Members want tokenized shares connected to official company records rather than operating separately from established ownership systems. Bullish CEO Tom Farley said public companies should remain central to relationships with their shareholders. He also said market participants need to establish the right architecture as tokenization develops. Farley described tokenization as a way to turn static assets into more active and transparent digital shares. At the same time, he said existing market protections should remain part of the structure. Market infrastructure firms focus on interoperability. Alpaca will contribute infrastructure intended to connect traditional securities markets with onchain systems. The company already operates its Instant Tokenization Network for converting tokenized equities and traditional counterparts. Arush Sehgal, Alpaca's Head of Digital Assets, said tokenization creates new ways to connect issuers and investors. He also said shareholder protections must remain intact as those markets develop. Apex Fintech Solutions will contribute experience spanning issuers, broker-dealers and investors. Global Head of Digital Markets Travis McGhee said connective infrastructure will determine whether tokenized securities can scale. According to McGhee, tokenized markets need standards that preserve existing relationships and investor protections. Apex joined the coalition to help develop that infrastructure. Meanwhile, Equiniti and Bullish will work with the other participants on the wider standards and frameworks needed for issuer-sponsored securities. The coalition plans to address technical standards, operating structures and market connections as tokenized public securities develop. Its model keeps issuers linked to investors while blockchain infrastructure changes how shares can trade and settle. Final thoughts. The Issuer Sponsored Token Coalition aims to connect tokenized stocks directly with company shareholder registers while preserving voting, dividend and corporate-action rights. Its members will develop standards and infrastructure as the SEC's five-year framework opens limited onchain trading for U.S.-listed equities.
Revolut data breach at DriveWealth follows impersonation incident. DriveWealth confirmed unauthorised access to its network on 4 and 5 September, adding to a separate impersonation case disclosed earlier in the month. Get the hottest Fintech Switzerland News once a month in your Inbox A data incident at US broker DriveWealth has affected Revolut customers, BeInCrypto reported. The broker has supported Revolut's US stock trading service. It is the second case involving Revolut customer data in September. Neither company has disclosed how many Revolut customers are involved. In a statement on its website, DriveWealth said unauthorised access to its network took place on 4 and 5 September. BeInCrypto reported that DriveWealth attributed the access to social engineering. Instead of breaking into software, this approach works by misleading people into handing over access or information. A Revolut spokesperson told The Irish Times that in the UK, the European Economic Area (EEA) and Australia, the incident involves older records from before Revolut changed how it runs US stock trading. In the EEA, including Ireland, this change took place in December 2023. The spokesperson said individual customer details in these markets have not been shared with DriveWealth since then, so more recent users there are not affected. According to BeInCrypto, the records may contain names and contact details, such as email addresses, phone numbers and postal addresses. They may also include employment information, citizenship, age, gender and partial DriveWealth account numbers. Earlier in September, a separate incident saw Revolut release sensitive data in response to requests from impersonators using a legitimate government email domain. Featured image: Edited by Fintech News Switzerland, based on image by Revolut via its website.
Stake data breach exposes customer details after hack at partner DriveWealth. Andrew HedgmanNewsWire Thu, 24 September 2026 11:02PM The No. 1 source of news for every west australian. No lock-in contract / week for 8 weeks, billed weekly. Pay in advance Annual Digital Save $104! Billed as $312 per annum. Pay as you go Digital + Weekend Newspapers Billed monthly or quarterly. All access digital Daily Digital Edition Need help with a subscription? Call us at 1800 811 855
DriveWealth security breach exposes personal data of Revolut, Stake, and Hatch users. Verified 26 votes Updated 7 hours ago A security breach at DriveWealth, a US brokerage infrastructure provider, hit customers of Revolut, Stake, and Hatch on September 4 and 5. Unauthorized access to personal data - and in some cases investment-related records - got through. The damage wasn't uniform across the three platforms. Discover more Compare Investment Apps Investment DriveWealth said the breach came from a social-engineering campaign. Someone talked their way into the systems, basically. The company confirmed the issue was contained and stressed that no unauthorized trades, transfers, or withdrawals happened as a result. But affected customers are now being warned about phishing and impersonation risks, since real personal data is floating around out there. What each platform lost. For Revolut users, the exposed data was older. The Currency Analytics is talking historical records - contact details, employment info, basic biographical data, and partial DriveWealth account numbers. Identity documents and payment details weren't touched. Revolut stopped sending new European Economic Area customer data to DriveWealth back in December 2023 when its operating model changed, so current EEA customers are probably clear. DriveWealth still acts as the clearing broker for Revolut Securities and Revolut Wealth in the US, so the relationship isn't fully severed - it's just narrower now. Stake and Hatch users got hit harder. Hatch customer records may include income ranges, cash balances, and total portfolio values. For Stake users, the exposed data covered tax status, country of taxation, DriveWealth account numbers, and overall portfolio summaries. That's a more detailed financial snapshot than what Revolut customers lost, and it's the kind of data that makes phishing attempts more convincing. Discover more Open Trading Account Compare Exchange Rates Investment Both Stake and Hatch confirmed their own internal systems weren't touched. The breach stayed inside DriveWealth's environment. Social engineering, not a hack. DriveWealth didn't get cracked through some sophisticated zero-day exploit. It's a social-engineering story - someone manipulated their way in. The company told its partners the incident was contained fast, and there's no sign of unauthorized financial activity. Still, "contained" doesn't mean the data disappeared. Once names, tax statuses, and portfolio summaries are out, they're out. Revolut was quick to clarify that the compromised records only covered older data, stuff shared before December 2023. That's a meaningful distinction - it means the breach doesn't reflect the current state of Revolut's customer base in Europe. Customers who signed up or updated their profiles after that model change aren't in this pool. Whether that's reassuring depends on how long you've been a Revolut customer, and the platform isn't specifying exactly how many people are affected. Stake and Hatch, for their part, said they're working with DriveWealth to tighten things up and prevent future incidents. No details on what that actually looks like in practice. Unclear whether any regulatory notifications beyond customer alerts are planned. Discover more Take Economics Courses Compare Exchange Rates Separate from the earlier Revolut incident. Worth being clear here: this DriveWealth breach is a different thing from the earlier Revolut incident that made headlines. In that older case, attackers used a compromised Italian government email account to fraudulently request information directly from Revolut. That breach involved the unauthorized acquisition of Know Your Customer documents and transaction records for roughly 680 Revolut customers. Different method, different data, different scope. The DriveWealth breach is broader in terms of platforms affected - three companies, not one. But the financial exposure so far seems limited to data theft rather than actual fund movement. DriveWealth is firm on that point. It's worth noting that brokerage infrastructure providers sit at a tricky intersection. They power the backend for multiple consumer-facing apps simultaneously, which means a single breach can ripple across platforms that have no direct relationship with each other. Revolut, Stake, and Hatch compete for similar users in some markets. They share a backend provider. And now they share a breach. Take Economics Courses Social-engineering attacks on financial infrastructure aren't new, and they're not going away. Regulators in multiple jurisdictions have flagged the risk for years. Whether DriveWealth faces any formal scrutiny over this incident hasn't been confirmed. Customers on all three platforms are being urged to watch for suspicious emails or messages that reference their real account details - because whoever accessed the data now has enough to make a phishing attempt look legitimate. Stake and Hatch users especially, given the financial data involved. DriveWealth confirmed no unauthorized financial activity was detected. Stake and Hatch confirmed their own systems were clean. Revolut confirmed the older-data-only scope of its exposure. And all three consumer platforms have pushed notifications to affected users. The breach dates: September 4 and 5. Frequently asked questions. What personal data was exposed in the DriveWealth breach for Revolut customers? Were Stake and Hatch customers' financial details exposed in the DriveWealth breach? Why it matters. This breach underscores the vulnerabilities that exist within the financial technology sector, particularly as companies increasingly rely on third-party service providers for brokerage and trading infrastructure. The incident not only raises concerns about the security of user data across multiple platforms but also highlights the potential risks associated with social engineering tactics, which can undermine consumer trust in digital financial services. As the crypto and broader financial markets continue to evolve, maintaining robust cybersecurity measures will be crucial for protecting user assets and sustaining market confidence. Trade Crypto Assets Community Trust Index High Confidence Real85% 15%Fake 26 community signals Post Views: 29