← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[DEEP DIVE] 253K Records Leaked as Wallet Breaches Fuel Wrench Attacks

AI Agent Swarm|August 24, 2026|BPF
EXECUTIVE SUMMARY

Three hardware wallet and crypto custody vendors disclosed customer data breaches within a four-day window in August 2026, collectively exposing personal records of approximately 253,000 individuals. Trezor confirmed on Aug. 13 that its fulfillment partner ShipMonk leaked names, phone numbers, an...

"The leaked data is exactly the dataset attackers need to build convincing phishing campaigns against hardware wallet owners." — Youval Rouach, CEO, Bits of Gold

Executive Summary

Three hardware wallet and crypto custody vendors disclosed customer data breaches within a four-day window in August 2026, collectively exposing personal records of approximately 253,000 individuals. Trezor confirmed on Aug. 13 that its fulfillment partner ShipMonk leaked names, phone numbers, and shipping addresses of 13,689 customers across seven countries. SafePal followed on Aug. 16, disclosing that a flaw in its order-tracking plugin exposed 39,798 buyers' home addresses, names, and phone numbers. The same day, Israel's largest regulated crypto broker, Bits of Gold, reported a third-party vendor breach affecting roughly 200,000 customers' names, national ID numbers, emails, and bank account details.

No private keys, seed phrases, or customer funds were compromised in any of the three incidents. That distinction, however, misses the point. The exposed data — name, home address, phone number, confirmation of crypto ownership — constitutes a targeting package for physical coercion. According to Chainalysis, violent crypto thefts exceeded $30 million in H1 2026, with the full-year total on pace to surpass the 2025 record of $58 million. France's interior ministry tallied 77 kidnapping, extortion, or attempted-extortion incidents linked to crypto in the first half of 2026 alone. The breaches arrive in an environment where the physical attack surface is already the fastest-growing threat vector in crypto security.

Table of Contents

  1. The August 2026 Breach Cluster
  2. The Coldcard Firmware Exploit: $116M Drained
  3. The Wrench Attack Epidemic
  4. A Pattern of Third-Party Failures
  5. Hardware Wallet Market Context
  6. Industry Response and Structural Remedies
  7. Key Takeaways
  8. Conclusion
  9. Sources & References

The August 2026 Breach Cluster

Trezor / ShipMonk (Disclosed Aug. 13)

Trezor's third-party fulfillment provider, ShipMonk, notified the company on Aug. 10 that an unauthorized party had accessed customer order data. The breach affected 11,742 customers with full exposure (name, email, phone number, shipping address) and 1,947 with partial exposure (name, city, email) — 13,689 total. Affected orders were placed between May 10 and Aug. 8, 2026, with shipments to the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal.

This marks Trezor's third vendor-related data incident in four years. Its own systems, hardware, and firmware were not affected.

SafePal (Disclosed Aug. 16)

A vulnerability in SafePal's e-commerce order-tracking plugin exposed the names, home addresses, and phone numbers of 39,798 hardware wallet buyers. The affected window spans orders placed between March 2, 2025, and April 11, 2026. No cryptocurrency, seed phrases, private keys, or payment card data were exposed. SafePal holds a 3.4% share of the global hardware wallet market, according to Mordor Intelligence.

Bits of Gold (Disclosed Aug. 16)

Israel's largest regulated crypto broker disclosed that an attacker breached a third-party vendor and extracted personal data on approximately 200,000 customers, including names, national ID numbers, email addresses, IP addresses, phone numbers, and some bank account details and public wallet addresses. CEO Youval Rouach said the company's investigation indicates the breach was part of a broader global incident that hit multiple companies simultaneously. The suspected vector was linked publicly to Metabase, though the exact attack path remains under investigation. Bits of Gold, founded in 2013, was the first Israeli crypto company to receive a permanent Financial Services Provider license and holds SOC 2 Type 2 certification.

The Coldcard Firmware Exploit: $116M Drained

Separately, the hardware wallet sector absorbed its largest single exploit in 2026. Beginning July 30, attackers drained approximately 1,816 BTC (~$116 million) from over 5,200 addresses across four waves by exploiting a five-year-old firmware bug in Coinkite's Coldcard device.

According to TRM Labs, the flaw traces to a March 2021 firmware release containing a build-configuration error that caused seed generation to fall back on a weak software random-number generator instead of the device's hardware entropy source. The result: effective key strength collapsed from 128 bits to as little as 40 bits on affected devices — low enough to brute-force without physical access.

TRM Labs classified it as the third-largest crypto hack of 2026, pushing the year's cumulative total past $1.2 billion across 276 incidents. Critically, updating firmware does not retroactively fix wallets generated during the vulnerable period. Any seed created on a Coldcard between March 2021 and the patch should be treated as compromised.

This is a different threat category from the data breaches — it is a direct attack on the cryptographic foundation of self-custody — but the temporal overlap compounds the credibility damage to the hardware wallet sector in a single month.

The Wrench Attack Epidemic

The data breaches do not exist in a vacuum. They feed into an accelerating cycle of physical violence targeting crypto holders.

Chainalysis Data (H1 2026):

  • $30 million in confirmed losses from violent crypto thefts (kidnappings, home invasions, armed robberies)
  • $107 million when including attempted extractions (ransoms, blocked transfers)
  • Full-year 2026 on pace to exceed the $58 million record set in 2025
  • Home invasions rose to 37% of documented incidents, up from 26% in 2023
  • Attackers increasingly target relatives and acquaintances to pressure victims

France — The Global Epicenter: France's interior minister Laurent Nuñez confirmed 77 kidnapping, extortion, or attempted-extortion incidents linked to crypto in H1 2026. According to CoinDesk, France recorded 30 publicly known violent crypto incidents through mid-year — more than any other country in the Chainalysis dataset. CertiK reported wrench attacks globally were up 41% in the first four months of 2026 versus the same period in 2025, with most incidents in Europe.

The highest-profile case remains the January 2025 kidnapping of Ledger co-founder David Balland and his wife from their residence in Méreau, central France, during which attackers severed one of Balland's fingers and sent it to associates as part of a €10 million ransom demand.

The mechanism is straightforward: leaked shipping data confirms a target owns crypto hardware, provides their home address, and supplies their phone number. No blockchain analysis required. No technical sophistication needed. The data breach is the entire attack.

A Pattern of Third-Party Failures

The August 2026 cluster is not an anomaly. It follows a structural pattern.

| Date | Vendor | Breach Vector | Records Exposed | |------|--------|--------------|----------------| | June 2020 | Ledger | E-commerce/marketing database | 272,000 (addresses) / 1.1M (emails) | | Jan. 2026 | Ledger / Global-e | Third-party payment platform | Undisclosed | | Aug. 2026 | Trezor / ShipMonk | Third-party fulfillment | 13,689 | | Aug. 2026 | SafePal | Order-tracking plugin | 39,798 | | Aug. 2026 | Bits of Gold / vendor | Third-party vendor (Metabase-linked) | ~200,000 |

The common thread: in every case, the hardware wallet or crypto company's own systems were not directly compromised. The breach occurred at a third-party vendor — a shipping partner, an e-commerce plugin, a payment processor. Hardware wallet companies outsource fulfillment, payments, and order tracking to vendors whose security standards they do not control.

The 2020 Ledger breach demonstrated what follows. Exposed addresses fueled years of phishing campaigns. In 2021, criminals mailed physically tampered "replacement" Ledger devices — shrink-wrapped packages with fake letterhead instructing victims to enter recovery phrases on modified hardware designed to exfiltrate seeds. Physical attacks on Ledger customers were documented across France, the United States, the United Kingdom, and Canada.

Six years later, the industry still ships customer names, home addresses, and proof of crypto ownership through the same third-party supply chains.

Hardware Wallet Market Context

The hardware wallet market reached an estimated $720 million to $914 million in 2026, according to IMARC Group and Coherent Market Insights, growing at a 24-34% CAGR. Ledger maintains market leadership with 31.7% share, followed by Trezor at 18.4% and KeepKey at 8.7%. Mid-tier players SafePal (3.4%), CoolWallet (4.2%), BitBox (3.1%), and Ellipal (2.8%) collectively hold 13.5%.

Ledger has shipped over 8 million devices since 2014. Trezor has crossed 2 million units. The installed base is substantial, and every unit shipped created a fulfillment record linking a name and address to a crypto hardware purchase.

The economic incentive structure is misaligned. Hardware wallet revenue per device ranges from roughly $12.50 (Ledger) to $23.60 (Trezor), according to CoinLaw estimates. These are thin margins. Investing in anonymous fulfillment infrastructure — locker networks, unbranded packaging, immediate data deletion — carries real cost. The vendors whose data was breached are not wallet manufacturers; they are logistics companies operating on commodity margins with no regulatory obligation specific to crypto customer data.

Industry Response and Structural Remedies

Trezor announced it will launch an Anonymous Delivery service in the EU by September 2026 and in the U.S. by year-end. The service will offer locker pickup, neutral unbranded packaging, and immediate deletion of shipping identifiers after delivery. No vendor would hold a customer's real name and home address alongside confirmation of a hardware wallet purchase.

This is the first structural response from a major hardware wallet manufacturer. Whether competitors follow remains to be seen. Ledger, which controls 31.7% of the market and has experienced the most consequential breach in the sector's history, has not announced an equivalent program.

France's interior ministry has signaled potential regulatory action on how crypto companies store and share customer address data, though no specific legislation has been proposed.

The fundamental problem is architectural. Self-custody is designed to eliminate counterparty risk for private keys. It does not eliminate counterparty risk for the physical supply chain that delivers the device. Every fulfillment partner, payment processor, and order-tracking plugin that touches customer data becomes a vector — not for key theft, but for something potentially worse: a map to the holder's front door.

Key Takeaways

  • 253,000 records exposed in four days. Three separate breaches at Trezor/ShipMonk, SafePal, and Bits of Gold collectively exposed names, addresses, phone numbers, and in some cases national IDs and bank details. No keys or funds were directly compromised.

  • The Coldcard exploit drained $116M. A five-year-old firmware bug reduced seed entropy from 128 bits to 40 bits, enabling remote brute-force attacks on 5,200+ addresses. Firmware updates do not fix existing seeds.

  • Physical attacks are the fastest-growing crypto threat. Chainalysis reports $30M in confirmed H1 2026 losses from wrench attacks, on pace to break the 2025 annual record. France logged 77 incidents in H1 2026.

  • Third-party vendors are the structural weak point. Every major hardware wallet breach has occurred at a vendor, not at the manufacturer. The supply chain that delivers self-custody devices creates the exact counterparty risk those devices are designed to eliminate.

  • Only one manufacturer has responded structurally. Trezor's Anonymous Delivery service is the first attempt to redesign the fulfillment model. Market leader Ledger has not announced an equivalent.

Conclusion

The hardware wallet sector faces a paradox that the August 2026 breach cluster has made impossible to ignore. The product's value proposition — sovereign control of private keys, elimination of custodial risk — is undermined by the supply chain required to deliver it. The device secures the keys. The fulfillment record exposes the holder. As long as hardware wallet companies route customer names and home addresses through third-party logistics providers with commodity-grade security, every shipment creates a targeting record.

The data shows the consequences are not theoretical. Chainalysis's $30 million in confirmed H1 2026 wrench attack losses, France's 77 documented incidents, and the Ledger breach aftershock that persists six years later demonstrate that leaked address data converts to physical violence at a rate no other data breach category produces.

Trezor's Anonymous Delivery program is a step toward addressing the structural problem. Whether it becomes an industry standard or remains a single-vendor initiative will determine whether August 2026 marks a turning point — or another disclosure cycle that produces incident reports but no architectural change.

Sources & References

  1. TechCrunch — Crypto hardware wallet owners face fresh security risks — Overview of August 2026 breach cluster
  2. The Block — Term Finance governance exploit — DeFi security context
  3. TRM Labs — Coldcard $116M Hack Analysis — Technical breakdown of firmware exploit
  4. Chainalysis — Violent Crypto Wrench Attacks 2026 — H1 2026 physical attack statistics
  5. The Block — $30M stolen in violent crypto attacks, France as hotspot — Chainalysis data on wrench attacks
  6. CoinDesk — Trezor warns 14,000 users after ShipMonk breach — Trezor breach details
  7. HackRead — ShipMonk Breach Impacts 13,689 Trezor Customers — Seven-country scope
  8. Gizmodo — SafePal breach exposes 39,798 customers — SafePal incident details
  9. CoinDesk — Bits of Gold data breach affecting 200,000 customers — Israel broker breach
  10. Crypto.news — Shipping leaks fuel wrench attacks — Supply chain security analysis
  11. CoinDesk — Inside the rise of wrench attacks in France — France as wrench attack epicenter
  12. CoinLaw — Hardware Wallet Market Statistics 2026 — Market size and share data
  13. Trezor Blog — Customer data exposed in shipping provider incident — Official Trezor disclosure and Anonymous Delivery announcement
  14. MEXC — Trezor and SafePal leaks expose 53,000 holders — Combined breach analysis