Live on Robinhood Chain — launch tokens with locked liquidity via MintPlus →Arc is coming — Circle’s stablecoin L1, mainnet Sept 16 · Get ready →T-3
Back to Blog

Nobody Stole a Coin. Three Breaches Still Put Holders in Danger.

Onuora Amobi·August 29, 2026
crypto security
data breach
self custody
hardware wallet
wrench attack
Nobody Stole a Coin. Three Breaches Still Put Holders in Danger.

Not a single seed phrase was stolen. No private keys, no passwords, no customer funds. By the standard crypto has spent a decade teaching people to use, the three data breaches disclosed in the past eight days were failures without victims.

That standard is wrong.

Between August 10 and August 17, Trezor notified 13,689 customers that its fulfilment partner ShipMonk had been compromised, exposing full names, phone numbers and shipping addresses across seven countries. SafePal disclosed a flaw in an order-tracking plug-in that leaked the same categories of data for 39,798 buyers. Then Bits of Gold, Israel's largest regulated crypto broker, said roughly 200,000 customer records had walked out through a third-party analytics vendor — names, national ID numbers, bank details, IP addresses, public wallet addresses.

Each company issued the same reassurance. Funds are safe. Keys are safe.

Both statements are true. Both miss what actually happened.

A shipping label is a targeting document

Think about what a hardware wallet order record proves. It proves that a specific named human, at a specific street address, with a working phone number, cared enough about holding crypto to buy a device dedicated to storing it offline. That is not a marketing list. It is a pre-qualified lead sheet for anyone in the business of showing up at doors.

The industry has a euphemism for this. Wrench attacks — from the old joke about the cheapest way to break encryption. In 2026 the joke stopped being funny. Kidnappings and home invasions targeting crypto holders have become a recurring line item in security reporting, and the limiting factor for the people carrying them out has never been technical. It has been finding out who to visit.

Three vendors just answered that question for roughly a quarter of a million people.

The common thread was a dashboard nobody thinks about

Here is the part that should worry every operator reading this. According to reporting from crypto.news, the Trezor and Bits of Gold incidents both trace back to the same root cause: CVE-2026-72898, an unauthenticated SQL injection in Metabase rated a maximum-severity 10.0. Metabase is a business intelligence tool. It is the thing your ops team uses to make charts about order volume.

The vulnerability lets a remote attacker inject SQL through undeclared fields in a password reset request, take administrator control of the instance, and then read every database that instance is wired into. Both companies were running self-hosted deployments. Neither had been breached at the wallet layer, the exchange layer, or anywhere a crypto security audit would normally look.

The attacker did not need to beat a signing scheme. He needed to beat a reporting dashboard maintained by a logistics contractor.

Self-custody moved the risk, it did not delete it

There is an uncomfortable implication here for the maximalist position. Buying a hardware wallet is the single most-recommended step in crypto security, and it works — it takes your keys away from custodians who can be hacked, frozen, or bankrupted. It is also, structurally, an act of self-identification. You place an order. Your name enters a fulfilment database. Your address enters a shipping system. Your purchase history enters an analytics pipeline that you will never see and cannot audit.

Custodial users, ironically, generate less of this specific exhaust. Their exposure is concentrated in one regulated counterparty with a compliance department. The self-custody buyer distributes his exposure across a manufacturer, a payment processor, a fulfilment partner, and whatever SaaS tools those three chose to deploy.

Neither model is safe. They fail differently.

The counterargument deserves a hearing: none of these breaches touched a single satoshi, and a custodial failure at similar scale would have. That is correct, and it is why hardware wallets remain the right default for most people holding meaningful sums. But "your money is fine" is a narrow definition of harm when the leaked file is effectively a list of who in your city keeps wealth at home.

The questions worth asking your vendors now

Every application that knows what you hold is part of your attack surface — the exchange, the broker, the wallet manufacturer, the portfolio tracker on your phone. Tools like The Crypto App sit in that category by design, because tracking a portfolio means knowing a portfolio. The useful discipline is not abstinence from these tools. It is asking, of each one, three concrete things: what personal data does it retain, how long does it keep it, and which third-party subprocessors touch it.

Most companies cannot answer the third question quickly. That is the whole story of this week.

And there is a practical step available to individuals today, which almost nobody takes: stop shipping hardware wallets to the address where you sleep. Post boxes, work addresses, and parcel lockers cost almost nothing and sever the link between the purchase record and the residence. Buy through a reseller if you must, but verify tamper seals independently. The device threat model has always been about supply chain integrity. The buyer threat model is now about supply chain privacy, and those are not the same problem.

Trezor, SafePal and Bits of Gold will all recover from this. Their customers cannot un-leak an address.

The next disclosure will read exactly like these three did — no keys, no funds, deep regret — and the industry will file it under minor. At some point a company is going to have to explain to a court why it kept a home address for eighteen months so a contractor could build a nicer chart.

Share
Back to Blog