The summer of crypto breaches: why your shipping address is now the most dangerous thing you own

1 hour ago 1



Three breaches landed in four days, each rooted in a vendor the end user never chose and likely never knew existed. SafePal lost 39,798 customer records to a plugin flaw. Trezor lost 13,689 through its shipping provider ShipMonk. Bits of Gold, Israel’s largest regulated crypto broker, lost roughly 200,000 through an analytics tool. No wallets were drained. No keys were stolen. What was stolen is worse for a specific and growing class of crime: verified proof that a person at a known address owns cryptocurrency, paired with their phone number and in some cases their government identification number. Summary SafePal, Trezor and Bits of Gold disclosed breaches between August 13 and August 16, exposing a combined 253,487 customers whose names, phone numbers, shipping addresses and purchase histories are now in attacker hands. Two of the three breaches, Trezor’s shipping provider ShipMonk and Bits of Gold’s analytics platform, trace to the same vulnerability: CVE-2026-72898, a critical unauthenticated SQL injection in Metabase rated CVSS 10.0. CertiK documented 52 verified wrench attacks in the first half of 2026, a 33% increase over the same period in 2025, with financial exposure reac...

Read Entire Article