Wallet Security News

Security incidents, vulnerabilities, and data breaches affecting Ethereum wallets


Shared Newsletter Provider Breach Used for Phishing Against Trezor and BitBox


A shared newsletter/e-mail provider used by multiple Bitcoin hardware wallet companies was compromised, letting attackers send phishing e-mails from the companies' legitimate domains. Trezor warned that an e-mail titled 'Critical Security Alert: STM32 Entropy Vulnerability' did not originate from them and took down the compromised domain. BitBox confirmed a phishing e-mail was sent to its newsletter subscribers about an hour earlier and, after preliminary review, found it very likely that the shared newsletter provider was compromised, noting multiple other Bitcoin companies were targeted as well. Both companies warned their subscribers, contacted the provider, and reported the phishing domains; most phishing links have since been taken down. Both are still investigating.

Impact

  • Funds: Not Affected
  • Category: Phishing Related


Silent Signature Extraction Vulnerability in Rabby Browser Extension


Security researcher disclosed a silent signature extraction flaw in the Rabby browser extension. A malicious app can queue a fund-draining signature request hidden by a Chrome pop-under bug, and because unlocking the wallet resolves the pending approval queue without re-confirming consent, the signature could be signed without the user seeing it. This vulnerability only works if the user has manually configured their wallet auto-lock timer to exactly 10 minutes, and there are no reports of any funds being compromised. Rabby released a fix on August 11 2026. The mobile app is unaffected. No exploits were detected in the wild.

Impact

  • Funds: Affected
  • Category: Signing Bug


BitBox firmware update fixes three internally-discovered vulnerabilities


BitBox disclosed three security issues in its hardware wallet firmware, all fixed in the 08.2026 "Dixence" update (firmware version 9.26.5). A bootloader issue, already fixed in the prior Oeschinen release (v9.26.2), could have let an attacker trick users into installing malicious firmware and thereby steal funds, but required a phishing attack (the BitBox02 Nova is not affected). A different memory corruption issue on multi-edition devices without a wallet set up, used with a malicious host, could enable arbitrary code execution and malicious firmware installation (the Bitcoin-only edition is not affected). A silent payments issue could have allowed an attacker to lock funds to an unintended payment address for a potential ransom. There are no reports of exploitation or stolen funds from any of these vulnerabilities.

Impact

  • Funds: Affected
  • Category: Hardware Vulnerability


Unauthorized Access to SafePal Customer Order Information


SafePal disclosed that an authorization flaw in its order-tracking plug-in allowed unauthorized access to the order information of 39,798 customers who placed orders between March 2, 2025 and April 11, 2026. Exposed data included names, email addresses, shipping addresses, phone numbers, and purchase details, but no seed phrases, private keys, wallet passwords, or wallet funds. Affected customers are at risk of targeted phishing/impersonation attempts and wrench attacks.

Impact

  • Funds: Not Affected
  • Category: Privacy Leak


Customer Data Exposed in Trezor Shipping Provider Incident


ShipMonk, an independent shipping provider for Trezor, experienced a data breach that exposed customer personal information including full names, shipping addresses, phone numbers, and email addresses. Trezor initially disclosed 13,689 affected customers, but a 2026-09-02 update revealed the breach was far larger: an additional 67,000 US customers who ordered between November 2019 and August 2021 had their full names, emails, phone numbers, shipping addresses, and order numbers exposed. Trezor said it had repeatedly obtained written assurance from ShipMonk that the data had been deleted per their contract, but it had not been. Trezor's own systems were not compromised and its devices remain secure, but affected customers may face an increase in phishing attempts and wrench attacks.

Impact

  • Funds: Not Affected
  • Category: Privacy Leak


Privy Data Breach via Metabase Service Provider


Privy disclosed a security incident affecting Metabase, an external analytics and customer support provider it uses. The attacker gained access to customer and end-user email addresses and a small subset of developer-set custom metadata fields. Privy wallet infrastructure and authentication systems were not affected, with wallet infrastructure run on separate hardware. Privy suspended connections from Metabase, rotated connection credentials, and notified affected customers. Because email addresses were involved, the incident may increase the risk of phishing and targeted social engineering.

Impact

  • Funds: Not Affected
  • Category: Privacy Leak


COLDCARD seed generation vulnerability reduces entropy


Coinkite disclosed a security advisory affecting seed generation on COLDCARD hardware wallets (Mk2, Mk3, Mk4, Mk5 and Q). Affected firmware generates seeds with reduced entropy: Mk2/Mk3 firmware versions 4.0.1 through 4.1.9 inclusive, and Mk4, Mk5 and Q before their fixed releases, produce roughly 72 bits of entropy instead of the expected 128 bits. Funds controlled by such seeds are at risk. Fixed firmware has been released for all affected models. Coinkite advises migrating to a newly-generated seed.

Impact

  • Funds: Affected
  • Category: Hardware Vulnerability


Consensys (MetaMask) Accidentally Hired North Korean-Linked Developer


Consensys, creator of MetaMask, accidentally hired a North Korean-linked developer using the alias "Tyler Knapp" who worked as a consultant on core MetaMask platform code, including crypto-to-fiat conversion functionality. The actor contributed to MetaMask's mobile wallet for roughly a month (from March to April 2026) before access was terminated. Consensys's investigation confirmed that there was no misappropriation of assets or data, no malicious code deployed, and no impact to user safety and security.

Impact

  • Funds: Not Affected
  • Category: Vendor Infiltration



Bankr Users Report Wallets Being Drained in Active Security Incident


BankrBot reported that several users had their wallets compromised and drained. The root cause and full scope of the breach have not yet been disclosed. Transactions have been disabled as a precautionary measure while the team investigates.

Impact

  • Funds: Affected
  • Category: Other


Global-e Independent Provider Data Breach Affecting Ledger Customers


Global-e, an independent e-commerce platform used by Ledger.com, experienced unauthorized access to their cloud systems. Personal data including names and contact information of Ledger customers who made purchases through Global-e were improperly accessed. No payment information, account credentials, or passwords were compromised.

Impact

  • Funds: Not Affected
  • Category: Privacy Leak


Trust Wallet Browser Extension v2.68 Supply Chain Attack


A malicious version of Trust Wallet Browser Extension (v2.68) was published to the Chrome Web Store on December 24, 2025, through a compromised API key. The attack, linked to the industry-wide Sha1-Hulud supply chain incident, affected users who logged in during December 24-26, 2025. Approximately 2,520 wallet addresses were impacted with $8.5M in losses. Trust Wallet has committed to reimbursing all affected users.

Impact

  • Funds: Affected
  • Category: Supply Chain


Slope Wallet users' seed phrases leaked to user tracking platform Sentry


Slope Wallet versions 2022-06-24 and later contained user tracking code that leaked users' full seed phrase to the Slope's on-premise Sentry analytics platform.

Impact

  • Funds: Affected
  • Category: Seed Phrase Leak


Know about a security incident affecting a wallet? Please help by contributing to our repository!