The summer of crypto breaches: why your shipping address is now the most dangerous thing you own
Three breaches landed in four days, each rooted in a vendor the end user never chose and likely never knew existed. SafePal lost 39,798 customer records to a plugin flaw. Trezor lost 13,689 through its shipping provider ShipMonk. Bits of Gold, Israel’s largest regulated crypto broker, lost roughly 200,000 through an analytics tool. No wallets were drained. No keys were stolen. What was stolen is worse for a specific and growing class of crime: verified proof that a person at a known address owns cryptocurrency, paired with their phone number and in some cases their government identification number.
- SafePal, Trezor and Bits of Gold disclosed breaches between August 13 and August 16, exposing a combined 253,487 customers whose names, phone numbers, shipping addresses and purchase histories are now in attacker hands.
- Two of the three breaches, Trezor’s shipping provider ShipMonk and Bits of Gold’s analytics platform, trace to the same vulnerability: CVE-2026-72898, a critical unauthenticated SQL injection in Metabase rated CVSS 10.0.
- CertiK documented 52 verified wrench attacks in the first half of 2026, a 33% increase over the same period in 2025, with financial exposure reaching $124.1 million, up more than 11 times from $10.5 million a year earlier.
- France accounts for 33 of those 52 incidents, roughly 63.5% of all documented cases, while home invasions linked to crypto theft rose from one case in the first half of 2025 to 20 in the first half of 2026.
- None of the three breaches compromised private keys, seed phrases or customer funds, yet the stolen data, proof of crypto ownership paired with a home address, is precisely the intelligence that enables physical attacks.
This piece traces the three incidents to their shared technical root, measures the physical threat those records now feed, and examines what the industry’s response reveals about a structural gap that hardware wallet makers and brokers have been slow to close.
One vulnerability, two breaches, four days
The connection between the Trezor and Bits of Gold breaches became clear within hours of the second disclosure. Both trace to CVE-2026-72898, a critical unauthenticated SQL injection in Metabase, the open source business intelligence platform used by thousands of companies to query and visualize internal data.
The vulnerability sits in the password reset endpoint. A remote attacker can inject arbitrary SQL through undeclared fields in the reset request body, gain administrator access to the Metabase instance, and from there read every database the instance connects to. Metabase rated it CVSS 10.0. Horizon3 published a proof of concept. CISA added it to the Known Exploited Vulnerabilities catalog.
ShipMonk, the fulfillment provider Trezor uses for orders in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal, ran a self hosted Metabase instance. Attackers exploited CVE-2026-72898 on or before August 6 and accessed order data for 13,689 Trezor customers who received shipments between May 10 and August 8. Of those, 11,742 had full exposure including name, email, phone number and shipping address. The remaining 1,947 had partial exposure limited to name, city and email.
Bits of Gold disclosed its breach on August 16 after detecting unauthorized access to a third party software system used for customer support and data analysis. The company confirmed the same CVE. Roughly 200,000 users had names, Israeli identification numbers, email addresses, phone numbers, IP addresses, bank account details and public cryptocurrency wallet addresses potentially accessed. Bits of Gold described the incident as part of a broader global attack that hit multiple companies simultaneously.
The broader campaign is real. Metabase itself confirmed that attackers exploited the flaw against Metabase Cloud tenants before the patch was available. Framework, Anaconda and n8n all disclosed unauthorized data access from the pre patch window. Of approximately 11,000 probable self hosted Metabase instances found via internet wide scanning by runZero, 4,309 were potentially vulnerable, and over 97% of fingerprinted hosts on affected branches appeared unpatched as of the advisory date.
The third breach runs on a different flaw
SafePal’s incident shares the timing but not the technical root. The Binance backed hardware wallet maker disclosed on August 16 that an authorization vulnerability in a third party order tracking plugin allowed unauthorized individuals to view order information belonging to other customers. The flaw exposed 39,798 customers who placed orders between March 2, 2025 and April 11, 2026.
The data set is narrower than the Metabase breaches: names, email addresses, phone numbers, shipping addresses and purchase details. No seed phrases, private keys, wallet passwords, bank details or government identification numbers were accessed. SafePal patched the flaw, hired an independent auditor, cut its data retention window to 90 days and identified and removed more than 30 phishing websites tied to the incident.
The three breaches share a pattern that matters more than any single CVE. In each case the company’s own systems were not compromised. The attacker entered through a vendor the customer never selected: a shipping logistics firm, an analytics dashboard, an order tracking widget. The customer chose a wallet or a broker. The vendor stack behind it was invisible.
What the stolen data enables
The standard reassurance after a breach of this kind is that no funds were compromised. That framing treats the data as a nuisance, useful for phishing emails that a careful user can spot and delete. It misses the category of crime these records feed.
CertiK’s H1 2026 wrench attack report documented 52 verified incidents of physical violence used to extract cryptocurrency from victims, a 33% increase over the 39 incidents in the first half of 2025. Financial exposure reached $124.1 million, more than 11 times the $10.5 million from the same period a year earlier.
The attack methods are shifting. Home invasions linked to crypto theft rose from one case in the first half of 2025 to 20 in the first half of 2026, making it the most common verified attack type. Kidnappings rose from 12 to 16. Attackers increasingly target people close to crypto holders: relatives or acquaintances represented roughly 25% to 30% of documented cases by early 2026, up from almost none in 2021.
France accounts for 33 of the 52 verified cases, 63.5% of all incidents globally. The country recorded 41 crypto linked kidnappings in 2026, averaging roughly one every two and a half days. The concentration is partly a reporting effect, French law enforcement tracks and publishes these cases more consistently than most jurisdictions, but the scale is not explained by reporting alone.
JUST IN: Coldcard wallets affected by security issue with reported losses
— crypto.news (@cryptodotnews) August 1, 2026
Roughly 594 $BTC valued at $38 million has been stolen from certain dormant single sig wallets pic.twitter.com/f3fk7kYXzM
The data from this week’s breaches is exactly what a wrench attack requires. A confirmed crypto customer, a shipping address verified by a completed delivery, a phone number for social engineering, and in the Bits of Gold case a government identification number and public wallet address. The attacker does not need to guess who owns crypto. The breach confirms it.
The economics are straightforward. A dark web buyer pays a few hundred dollars for a curated list of verified crypto holders with home addresses. A single successful home invasion or kidnapping yields tens of thousands to millions of dollars in cryptocurrency that is irreversible once transferred. The risk adjusted return for the attacker improves with every breach that adds verified records to the market. The $124.1 million in financial exposure from 52 incidents in the first half of 2026 implies an average take of roughly $2.4 million per successful attack, though the median is likely lower and a handful of high value cases skew the average upward.
The geography of the threat is also expanding. While France dominates the verified case count, Chainalysis has documented incidents across at least 14 countries in 2026. The United Kingdom, United States, Brazil, Netherlands and South Africa all recorded multiple cases. The Trezor breach specifically affects customers in seven countries. The Bits of Gold breach affects Israeli customers, a jurisdiction that has not previously appeared in wrench attack statistics at scale.
The Ledger precedent and why it matters now
This is not the first time a hardware wallet breach fed a physical threat campaign. Ledger’s 2020 e-commerce database breach exposed approximately 272,000 customer records including full names, phone numbers and home addresses. The data was sold privately before being dumped publicly in December 2020.
What followed became the industry’s clearest case study in how stolen address data converts to real world harm. Phishing campaigns used genuine names and purchase details to impersonate Ledger support. Extortion letters arrived at home addresses demanding $700 to $1,000 in Bitcoin, warning that refusal would lead to doxxing or physical attacks. In 2021, attackers mailed physically tampered replacement devices to addresses from the dump, shrink wrapped packages with fake letterhead instructing victims to enter recovery phrases on modified hardware designed to exfiltrate seeds.
Six years later, data from the Ledger breach still circulates in phishing campaigns. Scammers in 2026 sent physical letters to Ledger customers using the same 2020 address data, demonstrating that breach data does not expire. A home address from 2020 is still a home address in 2026 for the majority of victims who did not move.
The August 2026 breaches are larger in aggregate. Ledger exposed 272,000 records. This week’s three breaches exposed 253,487, and the Bits of Gold data set includes government identification numbers and public wallet addresses that the Ledger dump did not contain. The enrichment is worse. An attacker working from the Ledger dump knew someone bought a hardware wallet. An attacker working from the Bits of Gold data knows someone holds crypto, where they live, what their government ID number is, and can verify their on chain balance.
The vendor problem nobody has solved
Hardware wallet companies market themselves on security. The device generates keys offline. The firmware is open source. The secure element resists physical tampering. None of that matters when the company hands a customer’s home address to a third party fulfillment provider running an unpatched analytics dashboard.
Trezor acknowledged this gap directly. The company announced it will launch Anonymous Delivery in the European Union by September 2026 and in the United States by year end. The service will allow customers to receive devices without providing a home address to any shipping intermediary. It is the first structural response from a hardware wallet maker to the vendor data problem.
SafePal’s response focused on the plugin: patch, audit, reduce retention. Bits of Gold retained an incident response firm and disconnected the affected system. Neither announced changes to how they select or audit the vendors that handle customer data.
The structural issue is that the security model for crypto custody treats the device and the keys as the perimeter. The actual perimeter includes every vendor in the supply chain that knows a customer exists and where they live. Fulfillment providers, analytics platforms, customer support tools, order tracking widgets, and payment processors all hold some subset of that information. Each one is a target, and the customer has no visibility into which vendors are in the chain or what software they run.
The cost of retention
Data retention policy is the single variable that determines how large a breach can be. SafePal’s plugin flaw exposed orders placed over a 13 month window. Trezor’s ShipMonk exposure covered a three month window. Bits of Gold has not disclosed its retention period, but 200,000 affected customers implies years of accumulated records.
After the breach SafePal cut retention to 90 days. That is the right direction but it raises a question: why was the previous window 13 months? Order tracking does not require keeping a customer’s home address for a year after delivery. Shipping confirmation needs it for days, not months.
The principle is straightforward. Every day a record exists beyond its operational purpose is a day it can be stolen. The breach surface is not the number of vendors. It is the number of vendors multiplied by the number of records each one holds multiplied by the time those records persist.
What would actually fix this
Three structural changes would reduce the blast radius of the next breach. None require new technology. All require decisions that companies have so far avoided.
The first is vendor security attestation. Every company that handles crypto customer data should require its vendors to maintain current patch levels on internet facing software and provide evidence of that compliance on a defined schedule. The Metabase vulnerability had a patch available on August 6. ShipMonk was breached on or before August 6. Bits of Gold detected unauthorized access days later. A vendor attestation program that required monthly patch compliance reporting would have flagged unpatched Metabase instances before they were exploited.
The second is address minimization. A fulfillment provider needs a shipping address to deliver a package. It does not need that address after delivery confirmation. A customer support tool needs an order reference number to look up a case. It does not need the customer’s home address to do so. The principle of data minimization, collecting only what is needed and deleting it when the need expires, is written into GDPR, CCPA and most modern privacy frameworks. It is rarely enforced at the vendor level in crypto.
The third is transparent vendor disclosure. Customers choosing a hardware wallet or broker currently have no way to know which vendors will receive their data. Trezor’s customers did not know ShipMonk existed until the breach disclosure. SafePal’s customers did not know which plugin tracked their orders. A simple vendor registry, published on the company’s website and updated when vendors change, would give customers the information they need to assess their own risk.
None of these measures eliminate breaches. They reduce the number of records available to steal, the window during which those records exist, and the customer’s ability to make informed decisions about which companies they trust with physical address data.
The precedent exists outside crypto. Payment card networks require merchants and their processors to maintain PCI DSS compliance, including regular vulnerability scanning and penetration testing. A merchant that fails compliance can lose its ability to process cards. No equivalent standard exists for companies that handle crypto customer address data. The industry treats address data as a logistics detail rather than a security critical asset, even though address data paired with proof of crypto ownership creates a higher per record risk than a stolen credit card number, which can be reversed, ever does.
Trezor’s Anonymous Delivery announcement is the first sign that at least one company recognizes the structural problem. Whether competitors follow and whether the approach extends beyond shipping to analytics, support and marketing tools will determine whether August 2026 becomes a turning point or another incident that produces disclosures, notifications and no lasting change.
The opposing case: why this may not change much
The counterargument is that data breaches are routine and the connection to physical violence is overstated. Millions of e-commerce customer records are stolen annually. The vast majority of victims experience nothing worse than spam. Wrench attacks, while rising, remain rare in absolute terms: 52 verified cases out of an estimated 400 million cryptocurrency users globally.
That argument has merit on the base rate. It fails on the selection problem. A generic e-commerce breach does not tell an attacker which victims have liquid, bearer assets stored at a known address. A crypto wallet or broker breach does. The attacker can filter the stolen database to high value targets using purchase history, wallet addresses and order frequency. The targeting is precise in a way that a clothing retailer breach never is.
Coinbase disclosed in its most recent annual report that it spent $8.7 million on physical security measures for employees and executives in response to the wrench attack trend. If the threat were overstated, that line item would not exist.
What to watch
- Trezor Anonymous Delivery launch timeline. EU target is September 2026, US target is year end. If it ships on schedule, other hardware wallet makers will face pressure to match it.
- Metabase patch adoption rate. As of the advisory date, over 97% of fingerprinted self hosted instances on affected branches were unpatched. The next wave of breaches from CVE-2026-72898 is a matter of time, not probability.
- French legislative response. With 33 of 52 verified wrench attacks concentrated in France, the country’s interior ministry has signaled potential regulatory action on how crypto companies store and share customer address data.
- CertiK and Chainalysis H2 2026 reports. The H1 numbers showed 52 incidents and $124.1 million in exposure. The H2 data, expected in early 2027, will show whether the August breach cluster produces a measurable spike in physical attacks.
- Retention policy changes across the industry. SafePal moved to 90 days. Whether competitors follow or whether 90 days becomes a de facto standard will signal how seriously the industry treats the vendor data problem.
Frequently asked questions
What happened in the SafePal data breach?
SafePal disclosed on August 16, 2026, that an authorization vulnerability in a third party order tracking plugin exposed names, email addresses, phone numbers, shipping addresses and purchase details for 39,798 customers who placed orders between March 2, 2025 and April 11, 2026. No cryptocurrency funds, seed phrases or private keys were compromised.
How are the Trezor and Bits of Gold breaches connected?
Both breaches trace to CVE-2026-72898, a critical unauthenticated SQL injection vulnerability in Metabase rated CVSS 10.0. Trezor’s shipping provider ShipMonk and Bits of Gold’s analytics platform both ran self hosted Metabase instances that were exploited before a patch was available.
How many customers were affected across all three breaches?
The combined total is 253,487 customers: 39,798 from SafePal, 13,689 from Trezor via ShipMonk, and roughly 200,000 from Bits of Gold.
What is a wrench attack in cryptocurrency?
A wrench attack is a physical assault, home invasion or kidnapping in which the attacker uses violence or the threat of violence to force a cryptocurrency holder to transfer digital assets. The term comes from the idea that a five dollar wrench defeats any amount of cryptographic security.
How many wrench attacks occurred in the first half of 2026?
CertiK documented 52 verified wrench attacks in the first half of 2026, a 33% increase over the 39 incidents recorded in the same period in 2025. Financial exposure reached $124.1 million, more than 11 times the $10.5 million from the first half of 2025.
Why is France the epicenter of crypto wrench attacks?
France accounted for 33 of the 52 verified wrench attacks in the first half of 2026, roughly 63.5% of all cases globally. The concentration is partly due to more consistent law enforcement tracking and reporting, but the scale of 41 crypto linked kidnappings in 2026, averaging one every two and a half days, exceeds what reporting differences alone can explain.
What is CVE-2026-72898?
CVE-2026-72898 is a critical unauthenticated SQL injection vulnerability in Metabase, an open source business intelligence platform. It allows a remote attacker to inject arbitrary SQL through the password reset endpoint, gain administrator access, and read all connected databases. It was rated CVSS 10.0 and added to CISA’s Known Exploited Vulnerabilities catalog.
Should affected customers take specific steps to protect themselves?
Affected customers should monitor for phishing attempts that reference their real name, address or purchase history, as these details make scam messages more convincing. Changing email passwords, enabling two factor authentication and being cautious of unsolicited contact referencing crypto holdings are practical steps. This is educational analysis, not investment advice.
Disclaimer: This article was published on August 17, 2026. It reflects information available at the time of writing. Breach investigations are ongoing and the scope of affected data may change as companies complete their assessments. This is educational analysis, not investment advice.