Category:
RegulationCrypto Breaches: Why Your Shipping Address Is Now Under Attack

The summer of 2024 marked a turning point in cryptocurrency security threats. Within just four days in mid-August, three major breaches exposed over 250,000 customer records—but not in the way most people feared. No private keys were stolen. No wallets were drained. Instead, attackers obtained something far more dangerous: verified proof that specific individuals at known addresses own cryptocurrency. 🎯
This shift represents a fundamental change in how criminals target the crypto community. The data now in attacker hands pairs residential addresses with phone numbers, purchase histories, and in some cases government identification numbers. For a growing criminal ecosystem, this information is worth far more than any stolen password—it's the blueprint for physical attacks.
The Three Breaches That Changed Everything 🚨
Between August 13 and August 16, three separate incidents exposed the vulnerabilities lurking in the vendor networks that support the cryptocurrency industry. Each breach followed a similar pattern: the compromised systems belonged not to the companies customers trusted, but to invisible third parties behind the scenes.
SafePal's August 13 Disclosure
Binance-backed hardware wallet maker SafePal revealed an authorization flaw in a third-party order tracking plugin. The vulnerability allowed unauthorized individuals to access order information from other customers. Approximately 39,798 customers who placed orders between March 2025 and April 2026 were affected, with exposed data including names, email addresses, phone numbers, shipping addresses, and purchase histories.
While SafePal responded quickly—patching the flaw, hiring independent auditors, and reducing data retention to 90 days—the incident illustrated how even security-focused companies depend on external vendors that may not share their security standards.
The Trezor Shipping Disaster
On August 15, hardware wallet manufacturer Trezor announced that ShipMonk, its U.S.-based fulfillment provider, had been compromised. The breach exposed 13,689 customer records from orders shipped between May 10 and August 8. Of those affected, 11,742 customers had complete exposure including names, emails, phone numbers, and shipping addresses. The remaining 1,947 had partial exposure limited to names, cities, and emails.
ShipMonk operates fulfillment for Trezor orders across seven countries: the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. The scope of the compromise extended far beyond what Trezor customers might have anticipated when they purchased a hardware wallet.
Bits of Gold's Israeli Nightmare
On August 16, Bits of Gold, Israel's largest regulated cryptocurrency broker, disclosed unauthorized access to approximately 200,000 customer records. The compromised system was a third-party analytics tool used for customer support and data analysis. Exposed information included names, Israeli identification numbers, email addresses, phone numbers, IP addresses, bank account details, and public cryptocurrency wallet addresses.
Bits of Gold characterized the incident as part of a broader global attack affecting multiple companies simultaneously—a detail that would become crucial to understanding the technical root cause.
One Vulnerability, Two Breaches: The CVE-2026-72898 Connection 🔗
The connection between the Trezor and Bits of Gold breaches became apparent within hours of the second disclosure. Both traced to the same critical vulnerability: CVE-2026-72898, an unauthenticated SQL injection flaw in Metabase, the open-source business intelligence platform used by thousands of organizations worldwide.
Metabase serves as a data visualization and query tool for internal analytics. The vulnerability exists in the password reset endpoint, where attackers can inject arbitrary SQL through undeclared fields in the reset request body. This allows remote attackers to gain administrator access to the Metabase instance and read every database connected to it.
The Technical Details
The CVSS score for this vulnerability reached 10.0—the maximum severity rating. Horizon3 published a proof-of-concept exploit shortly after disclosure, and the Cybersecurity and Infrastructure Security Agency (CISA) added it to the Known Exploited Vulnerabilities catalog. This combination meant attackers had both the technical roadmap and official confirmation of the flaw's severity.
ShipMonk ran a self-hosted Metabase instance to manage its order and logistics data. Attackers exploited CVE-2026-72898 on or before August 6, gaining access to order information for thousands of Trezor customers. The vulnerability allowed them to bypass authentication entirely and access the underlying databases without any credentials.
The Broader Campaign
Metabase itself confirmed that attackers exploited this vulnerability against Metabase Cloud tenants before patches were available. Other major companies disclosed similar unauthorized access during the pre-patch window, including Framework, Anaconda, and n8n. Internet-wide scanning by runZero identified approximately 11,000 probable self-hosted Metabase instances, with 4,309 potentially vulnerable to the exploit. Alarmingly, over 97% of fingerprinted hosts on affected branches remained unpatched as of the advisory date.
Why Shipping Addresses Have Become High-Value Targets 📍
The standard industry response to breaches of this nature focuses on reassurance: no funds were stolen, no private keys were compromised, no wallets were drained. This framing treats the exposed data as a mere inconvenience—useful for phishing emails that vigilant users can recognize and delete.
This analysis fundamentally misunderstands the threat. The stolen data serves a specific and growing category of crime: wrench attacks, also known as physical attacks or home invasions targeting cryptocurrency holders.
The Rise of Wrench Attacks
CertiK, a blockchain security firm, documented a dramatic surge in verified wrench attacks. In the first half of 2024, they recorded 52 documented incidents—a 33% increase compared to the same period in 2023. More significantly, the financial exposure from these attacks reached $124.1 million, representing an 11-fold increase from $10.5 million in the prior year.
France accounted for 63.5% of documented wrench attacks during this period, with 33 of 52 incidents occurring in the country. Home invasions linked to cryptocurrency theft escalated dramatically: from just one case in the first half of 2023 to 20 cases in the first half of 2024.
The Intelligence Gap
Wrench attacks depend on specific intelligence: confirmation that a person at a known address owns cryptocurrency. Attackers need verified proof, not speculation. The breached data from SafePal, Trezor's shipping provider, and Bits of Gold's analytics platform provided exactly this intelligence.
Combining a residential address with a phone number creates a complete targeting package. Criminals can verify the information, research the victim, and plan physical attacks with precision. When government identification numbers are included—as in the Bits of Gold breach—the risk escalates further, enabling identity theft and additional fraud vectors.
The Structural Vulnerability: The Invisible Vendor Problem 🏢
All three breaches followed an identical pattern that reveals a structural weakness in cryptocurrency industry security: the compromised systems belonged not to the companies customers chose, but to third-party vendors operating invisibly behind the scenes.
The Vendor Stack Customers Never See
When you purchase a hardware wallet or open an account with a cryptocurrency broker, you make a conscious security decision about a specific company. You research their reputation, review their security practices, and make an informed choice. However, you have no visibility into—and no choice regarding—the vendor ecosystem supporting that company.
Trezor customers never selected ShipMonk. They didn't evaluate ShipMonk's security practices or data handling procedures. Yet ShipMonk held the keys to their delivery information and, by extension, their physical security. Similarly, Bits of Gold customers never chose the analytics platform that collected and stored their identification numbers.
This creates a security paradox: customers can only control their direct relationship with a company, but the actual security of their data depends on the security practices of vendors they've never heard of.
The Third-Party Risk Cascade
The cryptocurrency industry has grown rapidly, but security practices haven't kept pace with vendor complexity. Hardware wallet manufacturers focus on securing the devices themselves, but they often treat logistics and analytics as commodity services. The assumption is that these vendors handle the same data for thousands of companies, so they must be secure.
This assumption proved catastrophically wrong. ShipMonk wasn't running outdated software because it was uniquely negligent—it was running unpatched Metabase because the broader technology industry has a patch management problem. Thousands of organizations made the same choice, creating a massive attack surface.
What Happens When Attackers Have Your Address 🎯
The practical implications of address-based breaches extend far beyond theoretical risk. With verified proof of cryptocurrency ownership paired with a home address and phone number, attackers can execute sophisticated multi-stage attacks.
Physical Reconnaissance
Criminals can visit the address to assess security measures, identify when residents are home, and plan timing for attacks. They can monitor patterns, identify vulnerable entry points, and determine whether family members or security systems are present.
Social Engineering and Impersonation
With a phone number, attackers can conduct targeted phishing campaigns or social engineering attacks. They might impersonate law enforcement, utility companies, or delivery services to gain entry. They can attempt SIM swaps to compromise phone-based two-factor authentication.
Precision Targeting
Unlike generic phishing campaigns that cast wide nets, attackers with verified address data can conduct highly personalized attacks. They know the target owns cryptocurrency, they know where the target lives, and they can customize their approach accordingly.
Identity Theft and Financial Fraud
When government identification numbers are included in the breach—as with Bits of Gold—the attack surface expands dramatically. Attackers can open new accounts, apply for credit, or commit fraud using verified identity information paired with a known address.
Industry Response and Regulatory Implications ⚖️
The three breaches exposed not just technical vulnerabilities, but gaps in how the cryptocurrency industry approaches vendor security and data protection.
SafePal's Response Model
SafePal's response included several positive steps: immediate patching, independent auditor engagement, reduced data retention windows, and identification of phishing sites. However, the company's response was reactive rather than preventive. The vulnerability existed for months before detection.
The Broader Regulatory Context
These incidents occur against a backdrop of increasing regulatory scrutiny on cryptocurrency platforms. Regulators in multiple jurisdictions are examining how companies handle customer data, particularly information that could facilitate physical attacks. The European Union's Digital Markets Act, various state-level privacy laws, and international anti-money laundering frameworks all impose obligations on how cryptocurrency companies manage customer information.
The breaches raise questions about whether current regulatory frameworks adequately address the unique risks posed by physical attacks targeting cryptocurrency holders. Traditional data breach regulations focus on financial exposure and identity theft. They don't account for the physical safety implications of address disclosure paired with cryptocurrency ownership verification.
Lessons for the Cryptocurrency Community 📚
Vendor Due Diligence
Cryptocurrency companies must implement rigorous security requirements for all third-party vendors, not just those handling financial data. Shipping providers, analytics platforms, and support tools require the same security standards as internal systems.
Data Minimization
Companies should collect only the minimum data necessary for operations. If an analytics platform doesn't need government identification numbers, it shouldn't have access to them. If a shipping provider doesn't need purchase history details, those should be redacted.
Patch Management
The Metabase vulnerability remained unpatched across thousands of organizations. The industry needs standardized patch management protocols, vulnerability scanning, and rapid deployment procedures.
Customer Communication
When breaches occur, companies should clearly communicate the specific risks posed by the compromised data. Generic reassurances that "no funds were stolen" miss the point when physical safety is at stake.
Encryption and Access Controls
Sensitive customer data should be encrypted at rest and in transit. Access should be restricted to personnel who genuinely need it, with comprehensive logging and monitoring.
Looking Forward: The Future of Crypto Security 🔮
The summer of cryptocurrency breaches marked a inflection point in how the industry thinks about security. The threat model has shifted from purely digital attacks to physical attacks enabled by data breaches.
This shift demands a corresponding evolution in security practices. Hardware wallet manufacturers and cryptocurrency brokers must recognize that their responsibility extends beyond securing private keys—it includes protecting customers from physical harm.
The vendor ecosystem supporting the cryptocurrency industry needs immediate attention. Thousands of companies run vulnerable software versions, creating ongoing risk. The industry needs coordinated vulnerability disclosure, rapid patching, and security standards that apply throughout the supply chain.
Most importantly, customers need to understand that their shipping address has become a high-value target. The data stolen in these breaches isn't just personal information—it's a blueprint for physical attacks. As wrench attacks continue to surge globally, the security implications of address disclosure will only intensify.
You May Also Like

Regulation
JPMorgan Accepts Bitcoin as Collateral: Wall Street's Crypto Watershed
August 17, 2026

Regulation
Binance Halts HTX Transactions: What Sanctions Mean for Crypto
August 17, 2026

Regulation
World Liberty Financial Receives OCC Approval for USD1 Bank
August 17, 2026

Regulation
Nigel Farage's $6.7M Crypto Gift Under Parliamentary Scrutiny
August 17, 2026