TLDR
Recent data breaches at multiple crypto firms have exposed personal data for roughly a quarter million customers, mainly without directly touching their funds.
- Israels broker Bits of Gold reports a third?party analytics breach that may have exposed data on up to 250,000 customers, though crypto assets remain safe.
- Hardware wallet maker SafePal and shipping partner incidents at Trezor add tens of thousands more exposed records, increasing risks of phishing and even physical wrench attacks.
- The main impact is heightened fraud and privacy risk, so crypto users should focus on account hygiene, data minimization, and watching for regulatory and platform updates.
Deep Dive
1. What Was Exposed
Bits of Gold, Israels largest regulated crypto broker, disclosed that an attacker accessed a connected analytics system, potentially exposing personal information for up to 250,000 customers, including names, national IDs, contact details, bank accounts and public wallet addresses, while passwords and private keys were not hit, according to its incident summary and follow?up reporting about the breach linked to Metabase analytics software.
In the same week, SafePal revealed that a flaw in its order?tracking plug?in exposed names, emails, phone numbers, and shipping addresses for about 39,798 hardware wallet buyers, again without compromising seeds or private keys, in a detailed statement on the SafePal breach.
Trezor previously confirmed a shipping?partner leak that exposed roughly 13,700 customers order information, and Ledgers older breach affected around 272,000 users, showing a persistent pattern of crypto data exposure via third?party services rather than direct wallet compromise.
2. Why It Matters For Crypto Users
These incidents shift risk from direct asset theft toward targeted fraud and coercion. With identity details, bank data, and proof of crypto ownership in hand, attackers can craft highly convincing phishing, impersonation, and refund scams that bypass generic security training.
For hardware wallet buyers, the combination of physical home address and evidence of holdings has already correlated with a rise in violent wrench attacks, where victims are threatened until they hand over keys, with Chainalysis data cited in the SafePal coverage pointing to dozens of such incidents and tens of millions of dollars stolen in 2026.
Bits of Golds breach also undermines trust in licensed brokers data handling, and because it involves regulated infrastructure, it is likely to attract scrutiny from Israels Capital Market Authority and cyber agencies, potentially influencing how exchanges worldwide are expected to treat customer records.
Even if your coins are technically safe on chain or in a hardware wallet, poor data security at brokers and vendors can turn you into a more attractive, and more vulnerable, target.
3. How Users Can Respond
- Treat any unexpected emails, calls or texts referencing your crypto activity, order history or personal data with extreme skepticism, and verify directly through official sites or apps before sharing information or authorizing transfers.
- Reduce the amount of personal data you provide where possible, avoid reusing email and phone numbers across every crypto service, and prefer platforms that clearly limit retention and disclose vendor relationships.
- Follow official incident pages and regulator notices for affected services, as they clarify which fields were exposed and what monitoring or credential changes (for example, new passwords or fresh 2FA setups) are actually warranted.
Conclusion
These breaches show that the weakest point in crypto security is often the data infrastructure around exchanges and wallet vendors, not the blockchains or hardware devices themselves.
For users, the practical implication is to combine strong self?custody with disciplined privacy and fraud awareness, watching both what information you share and how you respond when someone appears to know your crypto history.
