READ. SCROLL. LISTEN.

Unbiased headlines. Facts, not spin.

Every story is an unbiased news briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Crypto's Data Breach Summer: Bits of Gold, Trezor, and 200,000-Plus Customers Exposed

Crypto's Data Breach Summer: Bits of Gold, Trezor, and 200,000-Plus Customers Exposed
Israel's largest regulated crypto broker, Bits of Gold, reportedly had personal data on roughly 200,000 customers stolen. Days earlier, hardware wallet maker Trezor disclosed a breach through its shipping partner ShipMonk affecting nearly 14,000 buyers. Neither company's wallets or crypto holdings were touched, but the stolen identity data sets up years of phishing risk for customers who did nothing wrong.

Two of crypto's most trusted brands just told customers their personal data got stolen. Neither breach touched actual coins. Both still put real people at risk for years.

Bits of Gold: 200,000 Customers, Few Details

Bits of Gold, Israel's largest regulated crypto broker, reportedly suffered a breach exposing personal data belonging to roughly 200,000 customers, according to Calcalist and reported by Crypto Briefing. That's essentially the platform's entire user base.

This is the same company that became the first crypto firm to receive a virtual asset service provider license from Israel's Capital Market Authority, back in September 2022. In April 2026, regulators approved Bits of Gold to issue BILS, a shekel-backed stablecoin built with Solana and Fireblocks and audited by EY.

The specific data types stolen have not been publicly detailed. Crypto brokers collect extensive know-your-customer documentation under Israeli financial regulations: government IDs, proof of address, financial records. If any of that left the building, the exposure goes well beyond an email address.

Bits of Gold has not published a detailed public breach notification laying out exactly what was taken, at least not one reflected in available reporting. Customers deserve to know precisely what a hacker now holds on them, not a vague acknowledgment that something happened.

Trezor: ShipMonk Got Hit, Not the Wallets

Separately, hardware wallet maker Trezor disclosed on Thursday, August 13, that its shipping and logistics partner ShipMonk suffered unauthorized access to its systems, according to CoinDesk, Bitcoin Magazine, and BleepingComputer.

The numbers are specific. Trezor said 11,742 customers had full exposure: names, emails, phone numbers, shipping addresses. Another 1,947 had partial exposure: names, cities, emails. That's nearly 14,000 people total, spread across the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal, affecting anyone who placed an order between May 10 and August 8, 2026.

Trezor was blunt about it. "We have some difficult news to share," the company posted on X. "Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data."

Trezor said its own infrastructure and devices were not compromised. Customers who bought through Amazon are unaffected, since Amazon orders ship through a different fulfillment partner. As of Trezor's disclosure, the company told CoinDesk it has no confirmed cases of the stolen data being sold, published, or used in any scam attempt.

BleepingComputer dug further into the mechanics. ShipMonk told affected customers the breach traced back to a critical SQL injection zero-day vulnerability in Metabase, a third-party analytics platform. Attackers used that flaw to gain administrator access and pull customer data. Metabase has since patched the vulnerability and invalidated active sessions, according to ShipMonk's notification.

Trezor wasn't the only Metabase casualty. Laptop maker Framework and form-builder Tally also got hit through the same vulnerability, according to BleepingComputer and a data breach roundup from Privacy Guides. Framework's breach reportedly exposed names, emails, phone numbers, and physical addresses for its entire customer base.

The Pattern Repeats

Ledger, Trezor's biggest hardware wallet competitor, suffered a nearly identical breach in 2020 when its e-commerce database was hacked, exposing over a million email addresses and detailed contact information for nearly 10,000 customers. That leak fueled years of phishing campaigns and, in some documented cases, physical threats against people known to hold cryptocurrency.

When a database of crypto holders' names and home addresses gets stolen, criminals don't need to hack a wallet. They just need to show up, call, email, or mail a convincing enough impersonation of "your exchange" or "your bank" to get someone to hand over access voluntarily. Home addresses tied to known crypto ownership have already been used in extortion attempts against Ledger customers.

SentinelOne, a cybersecurity firm, says data breaches overall are up 17% this year compared to 2025, averaging 2,090 attacks worldwide every week, according to Privacy Guides' breach roundup. Ceva Logistics, a major shipping company, got hacked too, exposing customer data for Dutch retailer Bol, luxury retailer De Bijenkorf, football club Ajax, bank ING, and gaming giant Valve. Wesco, a supply chain firm, says attackers claim to have stolen 2.6 million records.

Across nearly every one of these incidents, the core product stayed secure. Whether a hardware wallet, a laptop, or a bank account, the vulnerability sat with a third-party vendor holding customer data for shipping, analytics, or logistics.

No arrests, charges, or named suspects have been announced in either the Bits of Gold or the ShipMonk breach as of this writing. Trezor said it's continuing to investigate. Bits of Gold has not issued a detailed public account of what customer data specifically was compromised or what regulatory reporting obligations under Israel's Capital Market Authority it may trigger. Customers of both platforms should assume their data is now circulating and treat any unexpected call, email, or letter claiming to be from a bank or crypto platform as hostile until proven otherwise.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center
Crypto BriefingBits of Gold reported to have suffered data breach affecting 200,000 customers
unknown
coindeskThird-party breach exposes shipping addresses of 14,000 Trezor buyers
unknown
bitcoinmagazineData Breach At Trezor Leaks Info On Nearly 14,000 Bitcoin Wallet Users
unknown
bleepingcomputerTrezor discloses data breach affecting nearly 14,000 customers
unknown
privacyguidesData Breach Roundup (August 7 - 13, 2026)