PrivacyThree crypto breaches exposed the names and home addresses of about 250,000 customers. No coins were stolen, but the leaked data fuels phishing and, for large holders, physical 'wrench attacks'
Between 13 and 16 August, SafePal, Trezor's shipping partner ShipMonk, and Israel's Bits of Gold each disclosed data breaches, together exposing about a quarter of a million customers' names, phone numbers and physical shipping addresses. No wallets were drained and no keys were stolen. The harm is downstream: for the Bits of Gold cohort, whose national ID and bank details also leaked, identity theft and fraud; for many, convincing targeted phishing; and, for identifiable large holders, the physical 'wrench attacks' researchers say are rising. Two of the three breaches are linked to the same critical Metabase flaw, CVE-2026-72898.