SafePal, Trezor and Israeli crypto broker Bits of Gold disclosed separate customer data breaches between Aug. 13 and Aug. 16, exposing a combined 253,487 records. None of the incidents involved stolen private keys, seed phrases or direct loss of customer funds, but the compromised data included names, phone numbers, shipping addresses and purchase information.
Two of the breaches were linked to the same critical Metabase vulnerability, while the third came from a flaw in a separate order-tracking plugin. The incidents have drawn attention to a different risk in crypto security: the exposure of verified ownership data and home addresses through third-party vendors that customers typically never see.
Two incidents traced to one Metabase flaw
The clearest technical link emerged between Trezor and Bits of Gold. Both said attackers exploited CVE-2026-72898, a critical unauthenticated SQL injection flaw in Metabase, the open-source analytics platform. The bug affected the password reset endpoint and, according to the source article, could allow a remote attacker to gain administrator access and read connected databases. Metabase rated the issue CVSS 10.0, Horizon3 published a proof of concept, and CISA added it to its Known Exploited Vulnerabilities catalog.
Trezor said the breach occurred through ShipMonk, its fulfillment provider for orders in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal. Attackers exploited the flaw on or before Aug. 6 and accessed order data for 13,689 customers who received shipments between May 10 and Aug. 8. Trezor said 11,742 customers had full exposure of name, email, phone number and shipping address, while 1,947 had partial exposure limited to name, city and email.
Bits of Gold disclosed its own incident on Aug. 16 after detecting unauthorized access to a third-party software system used for support and data analysis. The broker said roughly 200,000 users may have had names, Israeli identification numbers, email addresses, phone numbers, IP addresses, bank account details and public cryptocurrency wallet addresses accessed. The company tied the incident to the same Metabase flaw and described it as part of a broader attack affecting multiple companies.
SafePal breach followed a different path
SafePal’s disclosure came on the same day as Bits of Gold’s, but the company said its incident did not involve Metabase. Instead, SafePal said an authorization vulnerability in a third-party order tracking plugin allowed unauthorized people to view other customers’ order information.
The company said 39,798 customers who placed orders between March 2, 2025 and April 11, 2026 were affected. Exposed information included names, email addresses, phone numbers, shipping addresses and purchase details. SafePal said no seed phrases, private keys, wallet passwords, bank details or government identification numbers were accessed.
In response, SafePal said it patched the flaw, hired an independent auditor, reduced data retention to 90 days and identified and removed more than 30 phishing websites connected to the incident.
Why address data matters in crypto breaches
The article argues that these incidents are more serious than a typical customer-data leak because they can confirm that a person linked to a specific address owns cryptocurrency. In the case of Bits of Gold, the exposed data could also include government identification numbers and public wallet addresses, adding further detail for potential attackers.
CertiK documented 52 verified wrench attacks in the first half of 2026, up 33% from 39 in the same period of 2025. Reported financial exposure rose to $124.1 million from $10.5 million a year earlier. Home invasions linked to crypto theft increased from one case in the first half of 2025 to 20 in the first half of 2026, while kidnappings rose from 12 to 16.
France accounted for 33 of the 52 verified cases, about 63.5% of the total, though the article notes that reporting there is more consistent than in many countries. Still, the concentration was presented as too large to be explained by reporting differences alone. The source also said Chainalysis documented incidents across at least 14 countries in 2026.
A broader vendor and retention problem
The three breaches shared one structural pattern: the entry point was not the wallet maker’s or broker’s core product, but an outside vendor handling fulfillment, analytics or order tracking. The article frames that as a gap in crypto’s usual security model, where attention stays on offline key storage and device security even though customer identity and location data may sit with several third parties.
The Metabase campaign appears to have extended beyond these crypto firms. According to the source article, Metabase confirmed that attackers exploited the flaw against its cloud tenants before a patch was available, while Framework, Anaconda and n8n also disclosed unauthorized access during the pre-patch window. Internet-wide scanning by runZero found about 11,000 probable self-hosted Metabase instances, of which 4,309 were potentially vulnerable, and more than 97% of fingerprinted hosts on affected branches appeared unpatched as of the advisory date.
The article also highlights data retention as a factor that determines how much can be stolen once a system is breached. Trezor’s exposed ShipMonk data covered roughly three months of shipments, while SafePal’s affected plugin data stretched across about 13 months of orders. Bits of Gold did not disclose its retention period, but the size of the affected user base suggested a much larger historical data set.
What companies have confirmed next
Among the three companies, Trezor announced the most visible structural change. It said it plans to launch Anonymous Delivery in the European Union by September 2026 and in the United States by year end, aiming to let customers receive devices without providing a home address to a shipping intermediary.
SafePal’s confirmed follow-up steps were narrower and focused on the plugin issue and shorter retention. Bits of Gold said it retained an incident response firm and disconnected the affected system. The article says the next important signals will be whether more companies change vendor practices, how quickly Metabase users patch exposed systems, and whether the second-half 2026 crime data shows any measurable effect from this cluster of breaches.
Source: crypto.news