Three crypto breaches exposed the names and home addresses of about 250,000 customers. No coins were stolen, but the leaked data fuels phishing and, for large holders, physical 'wrench attacks'
Between 13 and 16 August, SafePal, Trezor's shipping partner ShipMonk, and Israel's Bits of Gold each disclosed data breaches, together exposing about a quarter of a million customers' names, phone numbers and physical shipping addresses. No wallets were drained and no keys were stolen. The harm is downstream: for the Bits of Gold cohort, whose national ID and bank details also leaked, identity theft and fraud; for many, convincing targeted phishing; and, for identifiable large holders, the physical 'wrench attacks' researchers say are rising. Two of the three breaches are linked to the same critical Metabase flaw, CVE-2026-72898.

In mid-August 2026, three crypto companies disclosed data breaches within days of each other: hardware-wallet maker SafePal (39,798 customers), Trezor through its shipping partner ShipMonk (13,689 customers), and Bits of Gold (a reported and company-unconfirmed 200,000 customers), roughly a quarter of a million people in total. What leaked was names, phone numbers and physical shipping addresses, and for Bits of Gold also national ID numbers, bank details and public wallet addresses. Crucially, no cryptocurrency was stolen and no private keys or wallet backups were exposed in the breaches themselves. The lasting harm is downstream, and it is not one thing: for most people the likeliest risk is convincing, targeted phishing; for the Bits of Gold cohort, whose IDs and bank details leaked, identity theft and financial fraud; and for the smaller number of identifiable, large holders, the physical "wrench attacks" researchers have been tracking. These were three separate breaches, not one confirmed operation: two (Trezor's ShipMonk and, per security reporting, Bits of Gold) are linked to the same critical Metabase vulnerability, CVE-2026-72898, while SafePal's was a separate flaw.
A run of crypto data breaches in mid-August did not steal a single coin, and that is exactly why security researchers are paying attention. Between 13 and 16 August 2026, three companies in the crypto supply chain disclosed that customer data had been exposed, and the specific data that leaked, real names tied to home addresses and, in one case, proof of crypto ownership, is the raw material for fraud and, at the extreme, physical crime.
What was actually breached?
Three separate disclosures, close together, adding up to a lot of exposed people:
- SafePal, 39,798 customers. The hardware-wallet maker said an authorization vulnerability in a third-party order-tracking plug-in exposed the data of customers who bought devices between 2 March 2025 and 11 April 2026. Exposed: names, email addresses, phone numbers, shipping addresses and purchase details. This one is not connected to the Metabase flaw below; it was a separate weakness in an order-tracking tool.
- Trezor via ShipMonk, 13,689 customers. Trezor said the breach happened at ShipMonk, one of its shipping providers, which handles orders for the US, UK and other countries. Of those affected, 11,742 had full exposure (name, email, phone number, shipping address) and 1,947 had partial exposure (name, city, email). ShipMonk told customers the attackers exploited the Metabase vulnerability described below.
- Bits of Gold, a reported 200,000 customers. Israel's largest regulated crypto broker suffered the most sensitive leak of the three, through a third-party analytics tool. The 200,000 figure is a reported estimate that the company has not confirmed (some outlets put it nearer 250,000, and Bits of Gold says it has more than 300,000 customers overall). Exposed data reportedly included names, Israeli national ID numbers, email addresses, phone numbers, IP addresses, bank details and public wallet addresses.
The two hardware-wallet breaches are firm at 53,487 people; adding the reported Bits of Gold figure brings the total to roughly a quarter of a million. Treat that total as approximate, since one of its three components is an unconfirmed estimate. The counts and data categories are from the companies' own disclosures; that these breaches are one coordinated operation, or that the three datasets have been combined into a single list, is not established, and the shared root cause below links only two of them.
The common thread: a "perfect 10" Metabase flaw
Two of the three breaches are linked to the same root cause: CVE-2026-72898, a critical vulnerability in Metabase, a widely used open-source business-intelligence and analytics platform that many companies point at their internal databases. ShipMonk, Trezor's shipping partner, told affected customers the attackers exploited this flaw; security reporting has tied the Bits of Gold breach to the same vulnerability, though Bits of Gold has not publicly named the analytics vendor involved. SafePal's breach, again, was a separate weakness and is not part of this.
The flaw is about as bad as they are rated. It is an unauthenticated SQL injection carrying a CVSS score of 10.0, the maximum. An attacker sends a crafted request to Metabase's password-reset endpoint, injects SQL through the request, and gains administrator access to the Metabase instance, with no login, no user interaction and low complexity required. From there they can read and export every database that the Metabase instance is connected to, and steal the stored credentials for those databases. Affected versions run from Metabase 0.58 through 0.63.4 (and the matching Enterprise 1.x builds); patches are available. The US Cybersecurity and Infrastructure Security Agency added CVE-2026-72898 to its Known Exploited Vulnerabilities catalogue on 11 August 2026, confirming it is being exploited in the wild. Reporting indicates the same flaw was used against several companies, not only the two crypto firms here.
The mechanism matters for understanding the blast radius. The victims were not always breached directly. ShipMonk was running Metabase, and the Bits of Gold breach is reported to trace to the same tool; the crypto firms and their customers were exposed because a vendor's analytics platform became a skeleton key to the databases behind it. That is the modern supply-chain shape of these incidents: you can run a tight ship and still leak because a third party you rely on did not patch a "perfect 10" flaw.
Why the leaked data can matter more than a stolen coin
Here is what makes these breaches unusual. In most crypto hacks the loss is money: a bridge is drained, a contract exploited, funds vanish. In these three, no wallets were drained and no keys were stolen, so by the usual measure nothing was lost. The catch is that leaked personal data does not expire the way a stolen password does. You can rotate a credential; you cannot change the home address, phone number or national ID that is now sitting in someone's dataset. So the harm is downstream and unevenly spread, and it is worth ranking it by how likely it is, not just by how dramatic it sounds.
For most of the people in these breaches, the realistic risk is targeted phishing and SIM-swapping. A scammer who can cite your real name, your real purchase and your real address is far more convincing than one sending a generic email, and that is a high-volume, everyday threat. For the roughly 200,000 in the Bits of Gold cohort, whose national ID numbers and bank details also leaked, the more probable harm is ordinary identity theft and financial fraud, the kind that needs no crypto angle at all.
The rarest but gravest risk sits with a smaller group: identifiable holders of significant sums. For them, a record that pairs "owns crypto" with "lives here" is the input for a "wrench attack," the grimly nicknamed crime in which criminals skip the cryptography entirely and use physical coercion, a home invasion or a kidnapping, to force a victim to hand over their assets. The name comes from a well-known webcomic: why break encryption when a $5 wrench gets the key faster. This is not hypothetical as a category. Across the whole market, blockchain security firm CertiK documented 52 physical "wrench attack" incidents in the first half of 2026, with about $124.1 million in exposure, up about a third on the prior period. That figure is a market-wide base rate for the phenomenon, not a measure of harm from these three breaches, but a leak that hands attackers a ready-made list of names and addresses is exactly the kind of fuel that trend runs on.
What was not exposed, and what affected users are being told
It is worth being just as precise about the limits of the damage. Trezor was explicit that its own systems were not compromised: "Trezor systems, hardware wallets, private keys, and wallet backups were not affected," and the parcel contents were not exposed either. The same logic holds across these incidents: a hardware wallet's security model does not depend on a shipping database, so a leaked order record does not put the coins on the device at risk. On that basis Trezor says customers do not need to move their funds because of the breach, since the keys were never exposed, and any message claiming otherwise, especially one asking for a recovery seed, should be treated as a phishing attempt.
The companies are notifying affected customers and, in the Metabase cases, the fix is to patch to a non-vulnerable Metabase version, which is on the vendors, not the customers. For individuals, the standing official guidance for any breach of this kind applies: be sceptical of unsolicited contact that references your real details, never share a wallet recovery phrase with anyone, and treat physical-security awareness as part of crypto ownership if your holdings are significant. None of that is specific investment or security advice for your situation; it is the general posture that regulators and the companies themselves point to after a data leak.
The three breaches, at a glance
| Company | Affected | Root cause | Most sensitive data exposed | Coins stolen in breach? |
|---|---|---|---|---|
| SafePal | 39,798 | Order-tracking plug-in flaw (not Metabase) | Names, emails, phones, shipping addresses | No |
| Trezor (via ShipMonk) | 13,689 | ShipMonk's Metabase (CVE-2026-72898) | Names, emails, phones, shipping addresses | No |
| Bits of Gold | ~200,000 (reported, unconfirmed) | Analytics tool (reported Metabase, CVE-2026-72898) | Names, national IDs, phones, bank details, wallet addresses | No |
| Total | ~253,000 (approx) | Two of three linked to the Metabase flaw | Home addresses + proof of crypto ownership | No |
Frequently asked questions
Was any cryptocurrency stolen in these breaches?
No. All three were data breaches, not thefts of funds. No wallets were drained and no private keys or recovery phrases were exposed. What leaked was customer records: names, contact details and physical addresses, plus, for Bits of Gold, national ID and bank details.
What is a "wrench attack"?
It is a physical attack, robbery, home invasion or kidnapping, in which criminals coerce a crypto holder into handing over their assets rather than trying to break the encryption. Leaked data that ties a real address to proof of crypto ownership makes it easier to pick targets. CertiK recorded 52 such incidents in the first half of 2026.
What is CVE-2026-72898?
A critical, unauthenticated SQL-injection vulnerability in the Metabase analytics platform, rated CVSS 10.0 (the maximum). It lets an attacker reach the password-reset endpoint, gain admin access to a Metabase instance without logging in, and read the databases behind it. It was added to the US CISA Known Exploited Vulnerabilities list on 11 August 2026. Two of these three crypto breaches (via ShipMonk and Bits of Gold) trace to it; SafePal's did not.
Do I need to move my crypto or reset my hardware wallet?
Based on the disclosures, no. The hardware wallets, private keys and wallet backups themselves were not compromised in these incidents. Be wary, though, of phishing that uses your leaked details, and never enter or share your recovery phrase in response to any message, however official it looks.
Which companies were affected?
SafePal (39,798 customers), Trezor via its shipping provider ShipMonk (13,689 customers), and Israel's Bits of Gold (a reported, company-unconfirmed 200,000 customers), disclosed between 13 and 16 August 2026.


