
Three breaches in four days exposed 253,487 crypto customers. The data feeds a rising physical attack trend: 52 wrench attacks in H1 2026, $124M in losses.
Three breaches landed in four days. Each one entered through a vendor the customer never chose and likely never knew existed. SafePal lost 39,798 records to a plugin flaw. Trezor lost 13,689 through its shipping provider ShipMonk. Bits of Gold, Israel's largest regulated crypto broker, lost roughly 200,000 through an analytics tool. No wallets were drained. What was stolen is worse for a specific and growing class of crime: verified proof that a person at a known address owns cryptocurrency.
The three incidents share a technical root. Both the Trezor and Bits of Gold breaches trace to CVE-2026-72898, a critical unauthenticated SQL injection vulnerability in Metabase, the open source business intelligence platform. Metabase rated it CVSS 10.0. CISA added it to the Known Exploited Vulnerabilities catalog. Horizon3 published a proof of concept.
ShipMonk, the fulfillment provider Trezor used for orders in seven countries including the US, UK and Brazil, ran a self-hosted Metabase instance. Attackers exploited the flaw on or before August 6 and accessed order data for 13,689 Trezor customers who received shipments between May 10 and August 8. Of those, 11,742 had full exposure including name, email, phone number and shipping address. Bits of Gold disclosed its breach on August 16 after detecting unauthorized access to a third-party software system used for customer support and data analysis. Roughly 200,000 users had names, Israeli identification numbers, email addresses, phone numbers, bank account details and public cryptocurrency wallet addresses potentially accessed.
The broader campaign is real. Metabase confirmed that attackers exploited the flaw against Metabase Cloud tenants before the patch was available. Framework, Anaconda and n8n all disclosed unauthorized data access from the pre-patch window. Of approximately 11,000 probable self-hosted Metabase instances found via internet-wide scanning by runZero, 4,309 were potentially vulnerable and over 97% of fingerprinted hosts on affected branches appeared unpatched as of the advisory date.
SafePal's incident shares the timing but not the technical root. The Binance-backed hardware wallet maker disclosed on August 16 that an authorization vulnerability in a third-party order tracking plugin allowed unauthorized individuals to view order information belonging to other customers. The flaw exposed 39,798 customers who placed orders between March 2, 2025 and April 11, 2026. The data set is narrower than the Metabase breaches: names, email addresses, phone numbers, shipping addresses and purchase details. No seed phrases, private keys, wallet passwords, bank details or government identification numbers were accessed.
The combined total across the three breaches is 253,487 customers.
The standard reassurance after a breach of this kind is that no funds were compromised. That framing treats the data as a nuisance, useful for phishing emails a careful user can spot and delete. It misses the category of crime these records feed.
CertiK's H1 2026 wrench attack report documented 52 verified incidents of physical violence used to extract cryptocurrency from victims, a 33% increase over the 39 incidents in the first half of 2025. Financial exposure reached $124.1 million, more than 11 times the $10.5 million from the same period a year earlier. Home invasions linked to crypto theft rose from one case in the first half of 2025 to 20 in the first half of 2026, making it the most common verified attack type. Kidnappings rose from 12 to 16. France accounts for 33 of the 52 verified cases, 63.5% of all incidents globally. The country recorded 41 crypto-linked kidnappings in 2026, averaging roughly one every two and a half days.
The data from this week's breaches is exactly what a wrench attack requires. A confirmed crypto customer. A shipping address verified by a completed delivery. A phone number for social engineering. In the Bits of Gold case, a government identification number and public wallet address. The attacker does not need to guess who owns crypto. The breach confirms it.
The economics are straightforward. A dark web buyer pays a few hundred dollars for a curated list of verified crypto holders with home addresses. A single successful home invasion or kidnapping yields tens of thousands to millions of dollars in cryptocurrency that is irreversible once transferred. The $124.1 million in financial exposure from 52 incidents in the first half of 2026 implies an average take of roughly $2.4 million per successful attack, though the median is likely lower and a handful of high-value cases skew the average upward.
This is not the first time a hardware wallet breach fed a physical threat campaign. Ledger's 2020 e-commerce database breach exposed approximately 272,000 customer records including full names, phone numbers and home addresses. The data was sold privately before being dumped publicly in December 2020. What followed became the industry's clearest case study in how stolen address data converts to real-world harm. Extortion letters arrived at home addresses demanding $700 to $1,000 in Bitcoin. In 2021, attackers mailed physically tampered replacement devices to addresses from the dump, shrink-wrapped packages with fake letterhead instructing victims to enter recovery phrases on modified hardware.
Six years later, data from the Ledger breach still circulates in phishing campaigns. Scammers in 2026 sent physical letters to Ledger customers using the same 2020 address data. A home address from 2020 is still a home address in 2026 for the majority of victims who did not move.
The August 2026 breaches are larger in aggregate. Ledger exposed 272,000 records. This week's three breaches exposed 253,487, and the Bits of Gold data set includes government identification numbers and public wallet addresses that the Ledger dump did not contain. The enrichment is worse. An attacker working from the Ledger dump knew someone bought a hardware wallet. An attacker working from the Bits of Gold data knows someone holds crypto, where they live, what their government ID number is, and can verify their on-chain balance.
Hardware wallet companies market themselves on security. The device generates keys offline. The firmware is open source. The secure element resists physical tampering. None of that matters when the company hands a customer's home address to a third-party fulfillment provider running an unpatched analytics dashboard.
Trezor acknowledged this gap directly. The company announced it will launch Anonymous Delivery in the European Union by September 2026 and in the United States by year end. The service will allow customers to receive devices without providing a home address to any shipping intermediary. It is the first structural response from a hardware wallet maker to the vendor data problem.
SafePal's response focused on the plugin: patch, audit, reduce retention. Bits of Gold retained an incident response firm and disconnected the affected system. Neither announced changes to how they select or audit the vendors that handle customer data.
The structural issue is that the security model for crypto custody treats the device and the keys as the perimeter. The actual perimeter includes every vendor in the supply chain that knows a customer exists and where they live. Fulfillment providers, analytics platforms, customer support tools, order tracking widgets and payment processors all hold some subset of that information. Each one is a target. The customer has no visibility into which vendors are in the chain or what software they run.
Data retention policy is the single variable that determines how large a breach can be. SafePal's plugin flaw exposed orders placed over a 13-month window. Trezor's ShipMonk exposure covered a three-month window. Bits of Gold has not disclosed its retention period, but 200,000 affected customers implies years of accumulated records.
After the breach SafePal cut retention to 90 days. That is the right direction but it raises a question: why was the previous window 13 months? Order tracking does not require keeping a customer's home address for a year after delivery. Shipping confirmation needs it for days, not months. Every day a record exists beyond its operational purpose is a day it can be stolen.
Three structural changes would reduce the blast radius of the next breach. None require new technology. All require decisions that companies have so far avoided.
The first is vendor security attestation. Every company that handles crypto customer data should require its vendors to maintain current patch levels on internet-facing software and provide evidence of that compliance on a defined schedule. The Metabase vulnerability had a patch available on August 6. ShipMonk was breached on or before August 6. A vendor attestation program that required monthly patch compliance reporting would have flagged unpatched Metabase instances before they were exploited.
The second is address minimization. A fulfillment provider needs a shipping address to deliver a package. It does not need that address after delivery confirmation. A customer support tool needs an order reference number to look up a case. It does not need the customer's home address to do so. The principle of data minimization is written into GDPR, CCPA and most modern privacy frameworks. It is rarely enforced at the vendor level in crypto.
The third is transparent vendor disclosure. Customers choosing a hardware wallet or broker currently have no way to know which vendors will receive their data. Trezor's customers did not know ShipMonk existed until the breach disclosure. SafePal's customers did not know which plugin tracked their orders. A simple vendor registry, published on the company's website and updated when vendors change, would give customers the information they need to assess their own risk.
The precedent exists outside crypto. Payment card networks require merchants and their processors to maintain PCI DSS compliance, including regular vulnerability scanning and penetration testing. A merchant that fails compliance can lose its ability to process cards. No equivalent standard exists for companies that handle crypto customer address data. The industry treats address data as a logistics detail rather than a security-critical asset, even though address data paired with proof of crypto ownership creates a higher per-record risk than a stolen credit card number, which can be reversed, ever does.
Trezor's Anonymous Delivery announcement is the first sign that at least one company recognizes the structural problem. Whether competitors follow and whether the approach extends beyond shipping to analytics, support and marketing tools will determine whether August 2026 becomes a turning point or another incident that produces disclosures, notifications and no lasting change.
The counterargument is that data breaches are routine and the connection to physical violence is overstated. Millions of e-commerce customer records are stolen annually. The vast majority of victims experience nothing worse than spam. Wrench attacks, while rising, remain rare in absolute terms: 52 verified cases out of an estimated 400 million cryptocurrency users globally.
That argument has merit on the base rate. It fails on the selection problem. A generic e-commerce breach does not tell an attacker which victims have liquid, bearer assets stored at a known address. A crypto wallet or broker breach does. The attacker can filter the stolen database to high-value targets using purchase history, wallet addresses and order frequency. Coinbase disclosed in its most recent annual report that it spent $8.7 million on physical security measures for employees and executives in response to the wrench attack trend. If the threat were overstated, that line item would not exist.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.