ThreatCluster tracks entity (keyword) mentions across 20,000+ sources and compares the current week against a rolling 8 week baseline. When a keyword appears in significantly more clusters than its own history predicts, it surfaces as a spike. Most spikes are single stories. Occasionally several spike together, and this particular spike is worth talking about.
This week produced 10 crypto related spikes:
- Trezor — 6 clusters against a baseline of 0.1 per week
- ShipMonk — 4 clusters against 0.0
- Ledger — 3 clusters against 0.1
- SafePal — 2 clusters against 0.0
- Harmony — 1 cluster against 0.0
- Jewelbug — 1 cluster against 0.0
- Coldcard — 1 cluster against 0.9
- Coinkite — 1 cluster against 0.5
- Binance — 1 cluster against 0.4
- Metabase — 1 cluster against 0.4

Trezor disclosed on the 13th August that 13,689 customers were affected by a breach at ShipMonk, the company handling its order fulfilment. ShipMonk notified Trezor on the 10th August. For 11,742 of those customers, the exposed data covers name, shipping address, phone number and email. A further 1,947 had partial data exposed. The orders run from the 10th May to the 8th of August. Trezor’s own systems were never accessed.
The exploit used was CVE-2026-72898, an unauthenticated SQL injection in Metabase (10.0 CVSS). CISA added it to the KEV on the 11th of August. Metabase disclosed it on the 6th of August after finding its own cloud environment had been attacked using what was at the time an unknown flaw. The vulnerability was used to access the application database through the password reset endpoint, and from there an attacker holds the credentials used to query everything it connects to.
SafePal disclosed 39,798 affected customers, with name, email, shipping address and phone number exposed across orders from 2nd of March 2025 to the 11th of April 2026. The cause was an authorisation flaw in an order tracking plugin, which has since patched. Seed phrases and private keys were never exposed.
Bits of Gold, Israel’s largest regulated broker, is currently investigating a breach affecting roughly 200,000 customers. Names, ID numbers, email addresses, phone numbers and banking details were exposed through a third party support system. Digital assets, passwords and card security codes were not. Although, the investigation is ongoing and these figures may change.
So, 3 companies, 3 separate 3rd parties, and 3 unrelated causes, but the outcome is the same.
The shipping address
Every one of these disclosures states that no funds, seed phrases or private keys were exposed. Which is true, but each one also directs attention to the wrong risk.
A shipping address held by a hardware wallet vendor is a purchase record. It confirms that a named person at a verified address owns a device built specifically to hold cryptocurrency offline. Add a phone number and the record works as a target profile for phishing, for impersonation, and for somebody you don’t want turning up at your door!
You could argue the wallet makers technically did what the industry asked of them. Trezor’s systems held. SafePal’s keys stayed secure. The compromise happened at the fulfilment provider and the analytics vendor, which is where the customer records live and where the security budget usually is not.
The market that consumes this data
Reporting aggregated by ThreatCluster this week describes more than $30m stolen from holders in physical “wrench” attacks in 2026 (coercion of a holder in person to hand over their recovery phrase). The incidents we clustered show the tactic moving from street robbery toward home invasion, and in one case a French couple was attacked 3 times in a month at their home, targeted using leaked personal data. One of the assaults was even filmed on Snapchat. CertiK also counts 52 verified wrench attacks in the first half of 2026, with 33 of them in France.
Roughly 54,000 combined Trezor and SafePal records are already circulating. Changpeng Zhao has warned publicly about the phishing wave that followed.
Fraud tooling aimed at the same people
Rapid7 documented Operation ASTERIX, an active campaign running counterfeit Ledger, Trezor and Exodus applications built to capture recovery phrases, supported by voice and message phishing. The operators checked victim phone numbers against live accounts before making contact. Stolen data left through Telegram. Build artifacts show signs of AI assistance. The infrastructure was still running when Rapid7 published.
Separately, a US based scammer stole at least $5m by impersonating exchange support staff. External estimates put global crypto scam losses at roughly $17bn for 2025, with impersonation the fastest growing category.
Weaknesses in the devices themselves
Coinkite published an advisory on the 30th of July describing a weak random number generator in Coldcard, which produces predictable entropy. Single signature users are exposed, and attackers are scanning derived keys for live balances. Multi signature setups of 2 of 3 or better are shielded by design. This one affects deployed devices now.

An audit of the XRP Ledger by Sherlock, funded at $550k, found 96 bugs including 2 rated critical. Both allowed account drainage without possession of the private key, one through batch transaction signature validation and one through permission delegation. Both were fixed in XRPL 3.3.0 before release.
On-chain losses
Harmony was exploited on the 12th August. Roughly 4 billion $ONE tokens were minted, around 26% of supply. The price fell 35% to an all time low near $0.00057. Funds moved to exchanges and freeze attempts are in progress.
A single wallet lost $25.6m to phishing on the 12th August, including $6.3m in aWBTC, $5.1m in DAI and $4.7m in WBTC. The same wallet lost $24.2m to phishing in 2023, taking the combined total to approximately $49.8m. Nothing has been returned this time.
The Coreum Bridge was also compromised, pushing XRP below $1 for the first time since November 2024 and driving a 211% spike in XRP perpetual funding rates. The attack vector remains unclear.
Actors and infrastructure
Jewelbug, a China based group, runs espionage and cryptocurrency theft through one command and control system called XG-Web. The espionage side has taken 15 or more government webmail accounts across the Middle East and Asia, along with over 580,000 browser cookies and more than 2,300 email bodies. The theft side runs a browser extension presenting itself as a PDF viewer, which swaps wallet addresses during transactions. Both operations share the same infrastructure, which is unusual enough to be worth tracking on its own.
The Aeternum botnet stores command and control instructions on the Polygon blockchain, making takedown considerably harder. It spreads through a counterfeit DBeaver installer and delivers XWorm and XMRig.
IOCs
Jewelbug APT — espionage and cryptocurrency fraud (21)
| Type | Indicator |
|---|---|
| MD5 | abfa7742e315485a98a5fafd6dbfb68e |
| SHA256 | 01b5c6acb20e41799a0e96d9d1d6e1c44791883706b6285e874fcb15cc93b31a |
| SHA256 | 09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cff |
| SHA256 | 0c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bd |
| SHA256 | 153d077bcb58e00f5746573cba25f6b0788b809bf7b2a52fca0dc22d3bb5c94e |
| SHA256 | 1573e125197ec77d8e9930c611ba2802ee59e19629396b5e99b426b46c53bd25 |
| SHA256 | 297413a3e49e7353bf484a3eb15ec647de729211059df8fc68678d2378b6f561 |
| SHA256 | 30f5122cc199b9c2e524503b343a9ee13a6f9773dcbc1df82c8b25ad20bca61d |
| SHA256 | 315bdba98c6fe863d39f6afccc727e17d5aea63bf21259444fa988cae56d61c1 |
| SHA256 | 430f12970f8d58f12edccee9019a1aa90fa232c961449bdcc69c8d348a52cf55 |
| SHA256 | 5ccdf53881f6c758af8d94fe67066af209b4bc0a3cb80b6a4c724fad86eb97ef |
| SHA256 | 5edb8d1023b8babf302871b68fa2b26d5ca57633f64951922998e8f1d6c8f7ac |
| SHA256 | 6d5fe6b6a34eeb470798b970b70f41a07ccf59b22f49ad9b3dfff7aa3256f3c2 |
| SHA256 | 97c3a6be1711c5340d8806e4a54f7297f3f763d0aa4240b667f1e4e1f98f2aad |
| SHA256 | 9b7df409c9a89f7536d3ba7b6d43fb6dbac618c8bb52615ba34cc971ad71bbf3 |
| SHA256 | ac3d453d3c9b0310ebb8a67cef35e2ac954d4acdf70cf497fe43a02c7a510813 |
| SHA256 | b90a4e770869c28fd2140acb3ebdc50c113bb6f096b4bbdb9ac87c349c70e85e |
| SHA256 | c11714f9fe2df1ca906585c81498cd77f5ec05b132aab73fa3a71d71d71e42cc |
| SHA256 | e782a6d4919f194d41e524ebd6df5894197043cf772fcf60455127b246f302c0 |
| SHA256 | e809da86bd81463347fa7f922d3e088755a94a331889d32acb55aa8f57778a34 |
| SHA256 | ed96e7f1085a50251eb8967ac53777272a617831084f0edad8a769c583a18869 |
Coruna / DarkSword iOS exploit kits (2)
| Type | Indicator |
|---|---|
| SHA1 | 73b26374b1c8df29c163775c2cd1f735ff6acd56 |
| SHA256 | 2e5a56beb63f21d9347310412ae6efb29fd3db2d3a3fc0798865a29a3c578d35 |
All IOCs can be found here — threatcluster.io/iocs