← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[DEEP DIVE] One Zero-Day Exposes 253K Crypto Users' Home Addresses

Zephyra|August 18, 2026|BPF
EXECUTIVE SUMMARY

A single zero-day vulnerability in Metabase, an open-source analytics platform, exposed the personal records of more than 250,000 cryptocurrency customers across at least three companies in the second week of August 2026. Trezor, SafePal, and Israel's Bits of Gold all disclosed breaches between A...

"The breaches exposing names, phone numbers, emails and delivery addresses could increase phishing, social-engineering and physical-security risks." — Changpeng Zhao, Co-Founder, Binance

Executive Summary

A single zero-day vulnerability in Metabase, an open-source analytics platform, exposed the personal records of more than 250,000 cryptocurrency customers across at least three companies in the second week of August 2026. Trezor, SafePal, and Israel's Bits of Gold all disclosed breaches between August 13 and August 17, each traced to CVE-2026-72898, a CVSS-10.0 unauthenticated SQL injection affecting self-hosted Metabase instances.

The incidents are not isolated. They land in a year that has already produced the IDMerit leak (1 billion KYC records exposed), the Sumsub compromise (18 months undetected), and the Coinbase insider breach ($180M–$400M in estimated costs). Chainalysis data shows violent physical attacks on crypto holders have more than doubled in frequency, from 1.9 per month in 2025 to 4.6 per month in H1 2026, with $30 million stolen through wrench attacks. The common thread: stolen personal data — names, home addresses, phone numbers — that converts digital theft targets into physical ones.

The economic value at stake is not the crypto in wallets. Hardware wallets, private keys, and on-chain assets were untouched in every August breach. The value destroyed is user trust, operational continuity, and the integrity of KYC infrastructure that regulators increasingly mandate.

Table of Contents

  1. The Metabase Zero-Day: One Vulnerability, Three Crypto Companies
  2. Breach-by-Breach: What Was Exposed
  3. 2026: The Year KYC Became the Attack Surface
  4. From Data Leak to Doorstep: The Wrench Attack Pipeline
  5. Economic Cost Assessment
  6. The Supply-Chain Problem
  7. Key Takeaways
  8. Conclusion

The Metabase Zero-Day: One Vulnerability, Three Crypto Companies

On August 6, 2026, Metabase disclosed CVE-2026-72898, a critical unauthenticated SQL injection in the /api/session/reset_password endpoint affecting self-hosted deployments on version 0.58 and above. The vulnerability received a CVSS score of 10.0 — the maximum severity rating. Exploitation was confirmed in the wild before the patch and public disclosure, according to Metabase's security advisory.

Horizon3.ai's analysis confirmed that successful exploitation grants full administrator access to the affected Metabase instance, including the ability to read data from all connected databases, steal stored credentials, and export records. According to RunZero's internet-wide scan, approximately 4,309 of roughly 11,000 self-hosted Metabase instances were potentially vulnerable, and over 97% of fingerprinted hosts on affected branches appeared unpatched at the time of disclosure.

The threat actor group ShinyHunters — known for targeting SaaS and fintech companies — has been linked to the extortion phase of at least one of the resulting breaches, according to cybersecurity outlet Cybernews, though public technical attribution remains limited. ShipMonk, Trezor's shipping partner, reported receiving extortionary emails from the group.

Breach-by-Breach: What Was Exposed

Trezor / ShipMonk (Disclosed August 13)

Trezor's shipping provider ShipMonk informed the company on August 10 that its systems had been compromised via the Metabase vulnerability. The breach exposed:

  • 11,742 customers — full name, email address, phone number, shipping address
  • 1,947 customers — name, city, email address
  • Affected orders: May 10 – August 8, 2026
  • Countries impacted: US, UK, Sweden, Colombia, Brazil, Italy, Portugal

Trezor stated that its own systems, firmware, and private keys were not compromised. The company attributed the limited scope to a 90-day data deletion policy it imposes on partners. Bloomberg reported the breach on August 13.

SafePal (Disclosed August 16)

SafePal, the Binance-backed hardware and software wallet maker, disclosed that an authorization flaw in an order-tracking plug-in exposed 39,798 customer records, including names, email addresses, shipping addresses, phone numbers, and purchase details. The exposed records covered orders placed between March 2, 2025, and April 11, 2026.

SafePal warned customers to watch for "fraudulent phone calls, letters, and text messages" impersonating customer support and requesting wallet recovery phrases under the guise of firmware updates or refund offers.

Bits of Gold (Disclosed August 17)

Israel's largest regulated cryptocurrency broker confirmed a breach affecting approximately 200,000 customers. The breach was attributed to CVE-2026-72898 exploited against the firm's self-hosted Metabase analytics instance, according to CoinDesk. Exposed data included names, national ID numbers, emails, phone numbers, IP addresses, bank account details, and public wallet addresses.

Bits of Gold halted Bitcoin purchases following the disclosure. CryptoSlate reported the total user population at risk could reach 250,000.

Combined exposure from the three August breaches: approximately 253,500 customer records.

2026: The Year KYC Became the Attack Surface

The August incidents extend a pattern that has made 2026 the worst year on record for cryptocurrency-related personal data exposure.

| Breach | Date | Records Exposed | Attack Vector | |---|---|---|---| | IDMerit | Nov 2025 (disclosed Feb 2026) | ~1 billion | Unprotected MongoDB database | | Sumsub | Jul 2024–Jan 2026 | Undisclosed (serves Bitget, Bybit, MoonPay, Bitpanda, Wirex) | Malicious attachment via support ticket | | Coinbase | Dec 2024–May 2025 | 69,461 | Bribed overseas support contractors | | French tax authority | Late Jun 2026 | 678,000 | Undisclosed (government system) | | Trezor / ShipMonk | Aug 2026 | 13,689 | CVE-2026-72898 (Metabase SQL injection) | | SafePal | Aug 2026 | 39,798 | Authorization flaw in order-tracking plug-in | | Bits of Gold | Aug 2026 | ~200,000 | CVE-2026-72898 (Metabase SQL injection) |

The IDMerit breach is the largest by volume. Discovered by Cybernews researchers in November 2025, an unprotected MongoDB database belonging to the global identity verification provider exposed approximately 1 billion records — including 203 million US records — containing full legal names, Social Security numbers, dates of birth, phone numbers, email addresses, and government ID numbers. The database was not password-protected.

The Sumsub compromise, discovered in January 2026, went undetected for 18 months. Sumsub provides KYC verification to multiple major crypto exchanges. While the company stated that biometric data and passport images were not accessed, names, email addresses, and phone numbers were exposed.

Coinbase estimated remediation costs at $180 million to $400 million in its SEC filing, covering customer reimbursement, security upgrades, and the relocation of support operations from overseas to a new US-based hub. The breach was caused by bribed TaskUs call-center staff in India who copied KYC files over a five-month period.

According to the Identity Theft Resource Center, 1,803 data compromises were recorded in H1 2026 across all industries, with more than 471 million victim notices issued — already exceeding the 2025 full-year total.

From Data Leak to Doorstep: The Wrench Attack Pipeline

The economic consequence of these breaches extends beyond remediation costs and regulatory fines. Chainalysis published research in August 2026 documenting a direct link between stolen personal data and violent physical attacks on crypto holders.

Key findings from the Chainalysis report:

  • $30 million stolen through violent physical attacks in H1 2026
  • 46 documented physical assaults through June 2026
  • Attack frequency: 4.6 incidents per month in H1 2026, up from 1.9 per month in 2025
  • Home invasions rose to 37% of 2026 incidents, up from 14% in 2025
  • Kidnappings account for 52% of incidents
  • Family members targeted in 25–30% of cases, up from near zero in 2021

France recorded 30 incidents, the highest of any country, which Chainalysis linked to a breach of French tax agency records that exposed 678,000 people including crypto holders' names, addresses, and income data. In French cases, family members were targeted in over 40% of incidents.

The pipeline is straightforward: a data breach produces a list of confirmed crypto holders with home addresses. That list has direct economic value to criminal networks that specialize in physical extortion. The Ledger 2020 breach, which exposed 270,000+ customer records, has been cited in subsequent investigations of phishing campaigns and wrench attacks for years after the initial incident.

2026's H1 total of $30 million is on track to exceed 2025's full-year record of $58 million if the current frequency holds.

Economic Cost Assessment

The direct and indirect costs of 2026's KYC data breach epidemic span multiple categories:

Direct remediation: Coinbase alone estimated $180M–$400M. Bits of Gold halted Bitcoin purchases, creating revenue loss of undisclosed magnitude. Trezor is developing an "Anonymous Delivery" system, launching in the EU in September and the US by year-end, representing unplanned engineering and logistics expenditure.

Regulatory exposure: Under the GENIUS Act's stablecoin framework and MiCA's data protection requirements, companies that process crypto-related KYC data face potential penalties for inadequate vendor oversight. The IDMerit breach — an unprotected, passwordless database — represents a compliance failure that regulators are likely to scrutinize.

Trust degradation: Hardware wallet manufacturers sell a security proposition. When the purchase itself creates a security vulnerability — exposing the buyer's name and home address — the product's value proposition is undermined. SafePal's warning about "fraudulent letters" to customers' home addresses illustrates the problem: the threat model now includes physical mail.

Insurance gaps: According to data from the existing DeFi insurance analysis, under 2% of crypto assets carry insurance coverage. Personal data breach insurance for individual crypto holders is effectively nonexistent.

The Supply-Chain Problem

The August breaches expose a structural vulnerability: crypto companies that invest heavily in securing on-chain assets routinely outsource logistics, analytics, and customer support to third-party vendors with weaker security postures.

Trezor's devices, firmware, and key management were uncompromised. The breach came through ShipMonk, a fulfillment company, running an unpatched analytics tool. SafePal's wallet infrastructure was intact; the vulnerability was in an order-tracking plug-in. Bits of Gold's trading systems were not breached; the entry point was a self-hosted Metabase instance used for internal analytics.

The pattern repeats across the industry: Coinbase's breach came through outsourced call-center staff. Sumsub's came through a third-party support ticketing platform. Ledger's multiple breaches came through marketing databases and payment processing partners.

Each of these companies secures its primary product — the wallet, the exchange, the verification layer — but the supply chain around that product operates at a lower security standard. The Metabase CVE demonstrates how a single vulnerability in a widely used open-source tool can cascade through the crypto ecosystem via its vendors and partners.

Of the approximately 4,309 vulnerable Metabase instances identified by RunZero, the crypto sector represented a small fraction. But the value of the data those instances connected to — verified identity documents, home addresses, transaction histories — makes crypto-adjacent deployments disproportionately attractive targets.

Key Takeaways

  • One CVE, 253,500 records: CVE-2026-72898, a CVSS-10.0 Metabase SQL injection, was the common entry point for breaches at Trezor/ShipMonk and Bits of Gold. SafePal's breach stemmed from a separate plug-in flaw but occurred in the same week.

  • 2026 is the worst year for crypto KYC exposure. The IDMerit leak alone exposed 1 billion records. Combined with Sumsub, Coinbase, the French tax breach, and the August incidents, the total population of crypto users with compromised personal data is in the hundreds of millions.

  • Data breaches feed physical violence. Chainalysis data shows violent crypto attacks more than doubled in frequency in H1 2026, with $30 million stolen. France's disproportionate share is linked to a tax data breach.

  • The attack surface is the supply chain, not the protocol. In every major 2026 breach, the crypto company's core product — wallet firmware, exchange matching engine, verification API — was uncompromised. The breach came through shipping partners, analytics tools, support ticket systems, and outsourced call centers.

  • Remediation costs are material. Coinbase's $180M–$400M estimate sets the floor for large-scale KYC breaches. Trezor's unplanned "Anonymous Delivery" system represents forced product development driven by vendor failure.

Conclusion

The August 2026 breaches at Trezor, SafePal, and Bits of Gold are not three separate incidents. They are three manifestations of a single structural problem: the crypto industry's security perimeter does not extend to its supply chain.

The economic value framework for evaluating these events is not the dollar amount of crypto stolen — which in these cases is zero. It is the cost of rebuilding user trust, the regulatory liability of mandatory KYC data being held in systems the mandating regulators never audited, and the human cost measured by Chainalysis in kidnappings, home invasions, and extortion.

Hardware wallet makers are now engineering around the problem — anonymous delivery, data deletion policies, reduced vendor access. These are rational responses. But they also represent an admission that the KYC data collection mandated by financial regulators has become the primary attack surface in cryptocurrency, and the infrastructure securing that data has not kept pace with the value it represents to attackers.

The Metabase CVE will be patched. The next zero-day will find the next unpatched analytics tool in the next vendor's infrastructure. The structural problem remains.

Sources & References

  1. Metabase CVE-2026-72898 Analysis — Horizon3.ai — Technical analysis of the critical SQL injection vulnerability
  2. Trezor Data Breach Disclosure — Official Trezor statement on the ShipMonk breach
  3. SafePal Data Breach — CryptoSlate — Coverage of SafePal's 39,798-customer breach
  4. Bits of Gold Data Breach — CoinDesk — Israel's largest crypto broker confirms 200,000 customers affected
  5. Trezor and SafePal: 53,487 Owners Exposed — Forbes — Forbes analysis of combined hardware wallet breaches
  6. Violent Crypto Wrench Attacks — Chainalysis — $30M stolen in physical attacks in H1 2026
  7. ShinyHunters Claims Metabase Hack — Cybernews — Attribution of the extortion campaign
  8. Crypto Firm Trezor Data Breach — Bloomberg — Bloomberg coverage of the Trezor disclosure
  9. IDMerit KYC Data Breach — Cybernews — 1 billion identity records exposed
  10. French Tax Breach Exposes 678,000 — The Block — French crypto holders exposed via government breach
  11. Coinbase Data Breach Costs — CryptoSlate — $180M–$400M estimated remediation
  12. Sumsub Security Breach — Zyphe — 18-month undetected breach at KYC provider
  13. Metabase Vulnerable Instances — RunZero — Internet-wide scan of vulnerable deployments
  14. Bitcoin Purchases Halted — CryptoSlate — Bits of Gold halts purchases after breach