Within four days, SafePal, Trezor and the Israeli encryption broker Bits of Gold disclosed data leaks, affecting 253,487 users. None of the three incidents involved the theft of private keys, assistive notes or funds, but the disclosure of names, telephone calls, addresses and purchase records exposed the encrypted holder to higher down-line security risks.
Two incidents point to the same loophole.
Térezor and Bits of Gold were all linked to the serious gap in Metabase CVE-2026-72898. The loophole is an unauthorized SQL injection with a rating of CVSS 10.0, through which the assailant can access administrator privileges and read the contents of the associated database.
Térezor stated that the example of the self-custody Metabase used by its logistics partner, ShipMonk, was used. The impact was on 13,689 clients who had received the goods between 10 May and 8 August, of whom 11,742 had their names, mailboxes, telephone calls and receiving addresses fully exposed.
Bits of Gold disclosed on 16 August that third-party client support and data analysis systems had been unauthorized access, and the company confirmed that the same loopholes were involved. Information about 200,000 users may be accessed, including names, Israeli identity card numbers, mailboxes, telephone calls, IP addresses, bank account information and public wallet addresses.
SafePal came from another flaw.
The incident in SafePal did not involve Metabase. According to the company, the attack originated from a plug-in loophole that led to the release of 39,798 customer records, involving names, mailboxes, telephone calls, receiving addresses and purchase details.
According to SafePal, no assistive words, private keys, wallet passwords, bank information or government identity documents were found to have been accessed. The company has closed loopholes, reduced the data retention period to 90 days and cleared more than 30 incident-related fishing websites.
Below-line risk from leaking address information
Citing CertiK data, the article states that 52 underground violent attacks against encryption holders were confirmed in the first half of 2026, an increase of 33 per cent over the same period in 2025. The associated financial risk exposure reached $124.1 million, which is more than 11 times greater than the same period of the previous year.
Of these, the most significant increase was in burglary, from 1 in the first half of 2025 to 20 in the first half of 2026, and in kidnapping cases from 12 to 16. France accounted for 33 of the confirmed cases and is currently the most concentrated country.
The article mentions that the attacker does not need the private key most, but rather the two types of information, “confirming that a person holds an encrypted asset” and “verifiable address”. The three successive leaks once again demonstrate that, even if the funds are not stolen directly, the outflow of identity and address data itself could turn into a real-world security threat.
