Hardware wallet maker Trezor said a breach at its shipping provider ShipMonk exposed personal data of nearly 14,000 customers who ordered devices between May and early August. About 11,700 had full details exposed, including name, email, phone number, and shipping address, while roughly 1,900 had partial data taken. Trezor stressed that its own systems were not compromised and its devices remain secure, but warned customers to expect phishing. Exposed home addresses tied to cryptocurrency ownership carry an added risk, as physical attacks on crypto holders have risen this year. The company said it is introducing an anonymous delivery option in response.
A firmware flaw in Coldcard Bitcoin hardware wallets let attackers reconstruct wallet seeds offline and sweep roughly 70 million dollars from 1,196 addresses in 41 minutes on July 30. A March 2021 build error routed seed generation to a weak software random number generator instead of the device's hardware one, because the check confirmed a configuration macro existed rather than that it was enabled. That collapsed the randomness behind seeds to as little as 40 bits on older models, letting an attacker who can constrain the device identifier and timer state reproduce candidate seeds and match them to funded addresses. Coinkite shipped emergency firmware, but updating does not repair an already-generated seed.