A fulfillment partner exposed names, addresses and phone numbers belonging to hardware wallet buyers, according to The Register. The vendor's boundary was the company's boundary.
Perspective Coverage
3 publishers
- Builder
- Builder 28%
- Operator
- Operator 55%
- Investor
- Investor 17%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+5
- Incentives60
- Confidence68
Roughly 40,000 SafePal customers had names, addresses and payment methods exposed, according to Crypto Briefing; the air-gapped device held, the shipping list did not.
Perspective Coverage
4 publishers
- Builder
- Builder 24%
- Operator
- Operator 55%
- Investor
- Investor 21%
Reality
- Evidence75
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence70
The records that expanded Trezor's breach were US orders from 2019 to 2021, held years past the 90-day deletion window its fulfillment partner had promised, which puts the failure in the contract rather than the device.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+15
- Incentives60
- Confidence58
The records cover orders placed between November 2019 and August 2021, years past the 90-day deletion window Trezor advertises. Trezor says it held repeated written confirmation from ShipMonk that the data was gone.
Perspective Coverage
3 publishers
- Builder
- Builder 30%
- Operator
- Operator 55%
- Investor
- Investor 15%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+8
- Incentives64
- Confidence66
Brevo says an intruder reached 120 customer accounts and used them to mail phishing from those customers' own domains. Three crypto companies confirmed their newsletter lists were hit. Only one named the provider.
Perspective Coverage
4 publishers
- Builder
- Builder 15%
- Operator
- Operator 69%
- Investor
- Investor 16%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap−20
- Incentives40
- Confidence70
The email telling Trezor owners their recovery phrases might lack entropy came from a real trezor.io address and passed DKIM, SPF and DMARC, and it described a defect close to the one that took 1,778.84 BTC from Coldcard users.
Reality
- Evidence42
- Adoption55
- Hype gap+22
- Incentives58
- Confidence45
Trezor's hardware held, but its logistics vendor gave away the one input an AI phishing operation otherwise has to guess at: a payment-verified list of buyers, 11,742 of them with full contact details.
Reality
- Evidence34
- Adoption41
- Hype gap+27
- Incentives66
- Confidence37
Rapid7's Operation ASTERIX report shows the cost of building convincing wallet malware collapsing while targeting stayed manual. The durable asset is the validated list, not the code.
Reality
- Evidence58
- Adoption32
- Hype gap+26
- Incentives62
- Confidence45