Recent Data Breaches in the Crypto Industry
In a troubling trend emerging in the crypto industry, three major data breaches within just four days have highlighted vulnerabilities linked to third-party vendors, often unknown to end users. Notably, SafePal, a hardware wallet manufacturer backed by Binance, recently reported that a flaw in its order tracking plugin led to the exposure of 39,798 customer records. Trezor fell victim to a breach through its shipping provider, ShipMonk, resulting in the disclosure of 13,689 records. Meanwhile, Bits of Gold, Israel’s leading regulated cryptocurrency broker, found that around 200,000 customer records were compromised via an analytics tool. No digital assets were stolen in these cases, but what was leaked is far more concerning: verified proof of cryptocurrency ownership tied to personal information, including home addresses and government identification numbers.
Vulnerability Details
The breaches are traced back to a critical vulnerability (CVE-2026-72898) in Metabase, an open-source data analytics platform widely used by organizations for data visualization. The vulnerability affects the password reset endpoint, allowing attackers to perform SQL injection attacks and gain administrative access to databases connected to Metabase instances. This flaw received a perfect CVSS score of 10.0, prompting the CISA to add it to the Known Exploited Vulnerabilities list.
Impact of the Breaches
ShipMonk, tasked with fulfilling Trezor’s order shipments across several countries, including the United States and the United Kingdom, experienced an attack utilizing this vulnerability prior to a patch being deployed on August 6. This breach uncovered sensitive order data from Trezor customers, exposing personal details such as names, emails, phone numbers, and shipping addresses.
In its disclosure on August 16, Bits of Gold confirmed that the same vulnerability was responsible for unauthorized access to their systems. The compromised data potentially included not only personal identification numbers and contact information but also IP addresses and bank account details. Bits of Gold described the incident as part of a broader coordinated attack affecting multiple companies, highlighting the expanded threat landscape.
SafePal‘s situation, although occurring around the same timeframe, was attributed to an authorization vulnerability related to a tracking plugin, which allowed unauthorized users to access over 39,000 orders between March 2025 and April 2026. While this breach did not expose bank details or sensitive identifiers like government ID numbers, the implications of such data leaks cannot be understated. SafePal has since taken steps to close the security gap by implementing a patch, hiring an independent auditor, and shortening its data retention policy to 90 days.
Broader Implications and Industry Response
All three breaches underscore a troubling trend: they did not result from an exploit of the companies’ primary systems but rather through third-party vendors. Customers effectively choose a crypto wallet or broker without knowing about the vendors handling their data — creating unknown risks. This systemic vulnerability raises critical concerns as data leaks can be exploited for malicious activities, including wrench attacks, where physical violence is used to extort funds from cryptocurrency holders.
According to CertiK’s updated reports, there was a 33% increase in verified incidents of such physical assaults linked to cryptocurrency theft in early 2026. The financial impact of these attacks reached a staggering $124.1 million in just the first half of the year. France has emerged as the epicenter of this growing trend, accounting for a significant portion of verified cases globally.
The recent breaches included not just names and shipping addresses but also essential identifiers for potential physical threats, making it easier for attackers to target cryptocurrency owners. The rapid rise in wrench attacks highlights a grim reality: the combined availability of personal and crypto-related data makes individuals more susceptible to exploitation.
In response to these security lapses, Trezor announced plans for an ‘Anonymous Delivery’ service, aimed at mitigating risks to customers by allowing crypto devices to be shipped without necessitating a home address. This move represents a potential turning point in the industry, addressing a growing awareness of data privacy and security.
However, both SafePal and Bits of Gold have yet to outline significant structural changes in their vendor management processes to mitigate future risks. Crypto companies must reassess their data retention policies, adopt improved vendor security assessments, and notably, transparently disclose third-party vendors to clients to empower informed decision-making.
As the industry grapples with the ramifications of these breaches, the common reassurances — that funds remain safe — overlook the broader implications of compromising personal data. The emergence of wrench attacks, largely fueled by such leaks, calls for urgent reforms to adapt existing cybersecurity frameworks to the realities of cryptocurrency ownership. Whether recent incidents catalyze a change in practices by crypto firms or lead to further complacency remains to be seen. Nevertheless, the potential dangers surrounding personal data connected to cryptocurrency ownership cannot be overstated.