ThreatCluster tracks entity (keyword) mentions across 20,000+ sources and compares the current week against a rolling 8 week baseline. When a keyword appears in significantly more clusters than its own history predicts, it surfaces as a spike. Most spikes are single stories. Occasionally several spike together, and this particular spike is worth talking about.

This week produced 10 crypto related spikes:

  • Trezor — 6 clusters against a baseline of 0.1 per week
  • ShipMonk — 4 clusters against 0.0
  • Ledger — 3 clusters against 0.1
  • SafePal — 2 clusters against 0.0
  • Harmony — 1 cluster against 0.0
  • Jewelbug — 1 cluster against 0.0
  • Coldcard — 1 cluster against 0.9
  • Coinkite — 1 cluster against 0.5
  • Binance — 1 cluster against 0.4
  • Metabase — 1 cluster against 0.4

Placeholder: ThreatCluster spike view showing the ten crypto-related entities against their 8-week baselines

Trezor disclosed on the 13th August that 13,689 customers were affected by a breach at ShipMonk, the company handling its order fulfilment. ShipMonk notified Trezor on the 10th August. For 11,742 of those customers, the exposed data covers name, shipping address, phone number and email. A further 1,947 had partial data exposed. The orders run from the 10th May to the 8th of August. Trezor’s own systems were never accessed.

The exploit used was CVE-2026-72898, an unauthenticated SQL injection in Metabase (10.0 CVSS). CISA added it to the KEV on the 11th of August. Metabase disclosed it on the 6th of August after finding its own cloud environment had been attacked using what was at the time an unknown flaw. The vulnerability was used to access the application database through the password reset endpoint, and from there an attacker holds the credentials used to query everything it connects to.

SafePal disclosed 39,798 affected customers, with name, email, shipping address and phone number exposed across orders from 2nd of March 2025 to the 11th of April 2026. The cause was an authorisation flaw in an order tracking plugin, which has since patched. Seed phrases and private keys were never exposed.

Bits of Gold, Israel’s largest regulated broker, is currently investigating a breach affecting roughly 200,000 customers. Names, ID numbers, email addresses, phone numbers and banking details were exposed through a third party support system. Digital assets, passwords and card security codes were not. Although, the investigation is ongoing and these figures may change.

So, 3 companies, 3 separate 3rd parties, and 3 unrelated causes, but the outcome is the same.

The shipping address

Every one of these disclosures states that no funds, seed phrases or private keys were exposed. Which is true, but each one also directs attention to the wrong risk.

A shipping address held by a hardware wallet vendor is a purchase record. It confirms that a named person at a verified address owns a device built specifically to hold cryptocurrency offline. Add a phone number and the record works as a target profile for phishing, for impersonation, and for somebody you don’t want turning up at your door!

You could argue the wallet makers technically did what the industry asked of them. Trezor’s systems held. SafePal’s keys stayed secure. The compromise happened at the fulfilment provider and the analytics vendor, which is where the customer records live and where the security budget usually is not.

The market that consumes this data

Reporting aggregated by ThreatCluster this week describes more than $30m stolen from holders in physical “wrench” attacks in 2026 (coercion of a holder in person to hand over their recovery phrase). The incidents we clustered show the tactic moving from street robbery toward home invasion, and in one case a French couple was attacked 3 times in a month at their home, targeted using leaked personal data. One of the assaults was even filmed on Snapchat. CertiK also counts 52 verified wrench attacks in the first half of 2026, with 33 of them in France.

Roughly 54,000 combined Trezor and SafePal records are already circulating. Changpeng Zhao has warned publicly about the phishing wave that followed.

Fraud tooling aimed at the same people

Rapid7 documented Operation ASTERIX, an active campaign running counterfeit Ledger, Trezor and Exodus applications built to capture recovery phrases, supported by voice and message phishing. The operators checked victim phone numbers against live accounts before making contact. Stolen data left through Telegram. Build artifacts show signs of AI assistance. The infrastructure was still running when Rapid7 published.

Separately, a US based scammer stole at least $5m by impersonating exchange support staff. External estimates put global crypto scam losses at roughly $17bn for 2025, with impersonation the fastest growing category.

Weaknesses in the devices themselves

Coinkite published an advisory on the 30th of July describing a weak random number generator in Coldcard, which produces predictable entropy. Single signature users are exposed, and attackers are scanning derived keys for live balances. Multi signature setups of 2 of 3 or better are shielded by design. This one affects deployed devices now.

Placeholder: Coinkite advisory on the weak Coldcard random number generator

An audit of the XRP Ledger by Sherlock, funded at $550k, found 96 bugs including 2 rated critical. Both allowed account drainage without possession of the private key, one through batch transaction signature validation and one through permission delegation. Both were fixed in XRPL 3.3.0 before release.

On-chain losses

Harmony was exploited on the 12th August. Roughly 4 billion $ONE tokens were minted, around 26% of supply. The price fell 35% to an all time low near $0.00057. Funds moved to exchanges and freeze attempts are in progress.

A single wallet lost $25.6m to phishing on the 12th August, including $6.3m in aWBTC, $5.1m in DAI and $4.7m in WBTC. The same wallet lost $24.2m to phishing in 2023, taking the combined total to approximately $49.8m. Nothing has been returned this time.

The Coreum Bridge was also compromised, pushing XRP below $1 for the first time since November 2024 and driving a 211% spike in XRP perpetual funding rates. The attack vector remains unclear.

Actors and infrastructure

Jewelbug, a China based group, runs espionage and cryptocurrency theft through one command and control system called XG-Web. The espionage side has taken 15 or more government webmail accounts across the Middle East and Asia, along with over 580,000 browser cookies and more than 2,300 email bodies. The theft side runs a browser extension presenting itself as a PDF viewer, which swaps wallet addresses during transactions. Both operations share the same infrastructure, which is unusual enough to be worth tracking on its own.

The Aeternum botnet stores command and control instructions on the Polygon blockchain, making takedown considerably harder. It spreads through a counterfeit DBeaver installer and delivers XWorm and XMRig.

IOCs

Jewelbug APT — espionage and cryptocurrency fraud (21)

TypeIndicator
MD5abfa7742e315485a98a5fafd6dbfb68e
SHA25601b5c6acb20e41799a0e96d9d1d6e1c44791883706b6285e874fcb15cc93b31a
SHA25609ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cff
SHA2560c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bd
SHA256153d077bcb58e00f5746573cba25f6b0788b809bf7b2a52fca0dc22d3bb5c94e
SHA2561573e125197ec77d8e9930c611ba2802ee59e19629396b5e99b426b46c53bd25
SHA256297413a3e49e7353bf484a3eb15ec647de729211059df8fc68678d2378b6f561
SHA25630f5122cc199b9c2e524503b343a9ee13a6f9773dcbc1df82c8b25ad20bca61d
SHA256315bdba98c6fe863d39f6afccc727e17d5aea63bf21259444fa988cae56d61c1
SHA256430f12970f8d58f12edccee9019a1aa90fa232c961449bdcc69c8d348a52cf55
SHA2565ccdf53881f6c758af8d94fe67066af209b4bc0a3cb80b6a4c724fad86eb97ef
SHA2565edb8d1023b8babf302871b68fa2b26d5ca57633f64951922998e8f1d6c8f7ac
SHA2566d5fe6b6a34eeb470798b970b70f41a07ccf59b22f49ad9b3dfff7aa3256f3c2
SHA25697c3a6be1711c5340d8806e4a54f7297f3f763d0aa4240b667f1e4e1f98f2aad
SHA2569b7df409c9a89f7536d3ba7b6d43fb6dbac618c8bb52615ba34cc971ad71bbf3
SHA256ac3d453d3c9b0310ebb8a67cef35e2ac954d4acdf70cf497fe43a02c7a510813
SHA256b90a4e770869c28fd2140acb3ebdc50c113bb6f096b4bbdb9ac87c349c70e85e
SHA256c11714f9fe2df1ca906585c81498cd77f5ec05b132aab73fa3a71d71d71e42cc
SHA256e782a6d4919f194d41e524ebd6df5894197043cf772fcf60455127b246f302c0
SHA256e809da86bd81463347fa7f922d3e088755a94a331889d32acb55aa8f57778a34
SHA256ed96e7f1085a50251eb8967ac53777272a617831084f0edad8a769c583a18869

Coruna / DarkSword iOS exploit kits (2)

TypeIndicator
SHA173b26374b1c8df29c163775c2cd1f735ff6acd56
SHA2562e5a56beb63f21d9347310412ae6efb29fd3db2d3a3fc0798865a29a3c578d35

All IOCs can be found here — threatcluster.io/iocs