Need help? Support
BITCOIN
Tether Dominance USDT.D

Hardware wallet data breaches expose 253,000 users

Published 546 words 3 min read

TLDR

Recent breaches at SafePal, Trezor and Israeli broker Bits of Gold exposed data for about 253,000 crypto users, increasing phishing and physical robbery risks even though wallets remain intact.

  1. SafePal, Trezor and Bits of Gold all leaked customer data via third party tools, exposing names, contact details and addresses but not private keys.
  2. The leaked data effectively proves where specific people hold crypto, raising risks of targeted scams and wrench attacks at home.
  3. Affected users should harden their security now, and the wider industry will likely face pressure for stricter vendor standards and data minimization.

Deep Dive

1. Scope Of The Breaches

Reporting on three linked incidents describes three major crypto-related data breaches between 13 and 16 August 2026, affecting about 253,487 customers.

SafePal lost 39,798 customer records through a flaw in an order tracking plugin, while Trezor saw 13,689 customers exposed via shipping provider ShipMonk. Bits of Gold, Israels largest regulated crypto broker, had roughly 200,000 customers affected through a vulnerable analytics tool.

The exposed data includes names, phone numbers, shipping or home addresses, purchase histories and in Bits of Golds case Israeli ID numbers and public wallet addresses. All three companies say wallets, private keys and recovery phrases were not accessed, and funds have not been reported stolen directly from these breaches.

2. Risks For Crypto Users

Even without key compromise, this type of data creates a map of who owns crypto and where they live, enabling highly targeted phishing and impersonation. Reports note that attackers already use such information to send convincing scam emails, letters and QR codes, aiming to trick users into revealing their recovery phrases.

More seriously, investigators link these leaks to rising physical attacks on crypto holders, often called wrench attacks, where criminals show up in person and coerce victims into signing transactions. CertiK recorded 52 verified wrench attacks in the first half of 2026, with reported financial exposure of over 124 million dollars and a sharp rise in home invasions in France.

What this means

Self custody still protects your keys from online hacks, but poor data security around shipping and brokerage services can put you, and not just your wallet, in danger.

3. Steps And Signals To Watch

For affected users, first steps are practical: monitor accounts for unusual activity, treat unsolicited messages as suspicious, change passwords, enable strong two factor authentication and consider reducing how often your real address appears in crypto orders.

On the provider side, Trezor has introduced Anonymous Delivery to avoid linking shipments to identifiable customer records, and SafePal reportedly cut data retention to 90 days after the incident. Bits of Gold is under scrutiny for how it handles personal and financial data in light of the breach described in its own community disclosure.

Experts are calling for vendor security attestations, stricter data minimization and standards similar to card-industry PCI rules for crypto customer address data. Watching whether hardware wallet makers and brokers adopt these measures will show how seriously they treat the new physical risk layer.

Conclusion

The headline figure around 253,000 affected users reflects a shift in crypto security from pure key protection to broader personal safety. Hardware wallets still do their job, but the services around them have become attractive targets. Until customer data practices catch up with onchain security, the main risk is not just losing coins to a hack, but becoming identifiable and reachable to attackers in the real world.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top