Evidence-backed timeline

Wallet incidents

Search and filter reviewed vulnerabilities, exploits, supply-chain incidents, data breaches, and other security events. Severity describes the recorded event, not a permanent safety score for the wallet.

13 of 13 reviewed incident records
2026-08-13
third_party_data_breachhigh

Shipping provider customer data breach disclosed

Wallet: Trezor

Trezor disclosed that ShipMonk, a third-party fulfillment partner, experienced unauthorized access exposing customer order information.

Scope: third_party_vendorFunds affected: noAction: monitorEvidence: 2
2026-08-02
software_issuehigh

Relationship-enrollment randomness bug disclosed

Wallet: Bitkey · Product: Bitkey Mobile App

Bitkey disclosed that the mobile app used a non-cryptographic random-number generator for a one-time relationship-enrollment secret. The demonstrated practical path was limited to narrow second-generation recovery-contact or inheritance flows and did not weaken wallet spending keys.

Scope: mobile_appFunds affected: noAction: update, reconfigureEvidence: 1
2026-07-30
vulnerability_disclosedcritical

Seed-generation entropy defect disclosed

Wallet: COLDCARD

COLDCARD disclosed a seed-generation defect in affected firmware lines. Fixed releases restore the intended hardware-randomness path for future seed generation, but existing affected seeds require migration unless an advisory exception applies.

Scope: seed_generationFunds affected: unknownAction: update, migrateEvidence: 1
2026-01-26
vulnerability_disclosedmedium

Two BitBox02 Nova firmware security issues disclosed and fixed

Wallet: BitBox · Product: BitBox02 Nova

BitBox disclosed two physical-access firmware issues in BitBox02 Nova. The more relevant scenario could reveal a reused device password after an advanced attack, while the attacked device's seed remained protected.

Scope: firmwareFunds affected: noAction: updateEvidence: 1
2025-12-24
supply_chain_compromisecritical

Malicious Trust Wallet Browser Extension v2.68 published

Wallet: Trust Wallet · Product: Trust Wallet Browser Extension

An unauthorized malicious Browser Extension v2.68 was published to the Chrome Web Store using a leaked publishing API key, enabling theft from users who logged in during the affected period.

Scope: supply_chainFunds affected: yesAction: move_funds, updateEvidence: 1
2025-12-16
vulnerability_disclosedhigh

Jade RPC stack-overwrite vulnerability disclosed

Wallet: Blockstream Jade

Blockstream disclosed a descriptor-RPC memory-safety issue affecting Jade firmware 1.0.24 through 1.0.36 across Original Jade, Jade 1.1 and Jade Plus device types.

Scope: firmwareFunds affected: noAction: updateEvidence: 1
2024-01-17
third_party_data_breachhigh

Third-party support portal accessed without authorization

Wallet: Trezor

Trezor reported unauthorized access to a third-party support portal, potentially exposing names or nicknames and email addresses of users who had interacted with support.

Scope: third_party_vendorFunds affected: noAction: monitorEvidence: 2
2023-12-14
supply_chain_compromisecritical

Malicious Ledger Connect Kit versions published through compromised NPM account

Wallet: Ledger

A former employee phishing compromise enabled malicious Ledger Connect Kit packages to be published to NPM and dynamically loaded by some dApps, causing a small number of users to sign draining transactions.

Scope: supply_chainFunds affected: yesAction: monitorEvidence: 1
2023-08-08
vulnerability_disclosedhigh

Browser-extension cached secret-key vulnerability reported

Wallet: Leather · Product: Leather Browser Extension

Leather's security history records a browser-extension issue where browser textarea caching could leave a private key or mnemonic in local storage under certain conditions, creating exposure if another party gained access to the computer.

Scope: key_storageFunds affected: unknownAction: updateEvidence: 1
2023-06-07
vulnerability_disclosedhigh

Xverse Extension local seed-phrase logging issue disclosed

Wallet: Xverse · Product: Xverse Browser Extension

Xverse disclosed that browser behavior could cause a seed phrase to be written unencrypted to a local Chrome log during extension onboarding under certain conditions.

Scope: browser_extensionFunds affected: noAction: update, migrateEvidence: 1
2022-06-15
vulnerability_disclosedcritical

Phantom disclosed remediation of the Demonic browser-extension vulnerability

Wallet: Phantom · Product: Phantom Browser Extension

Phantom disclosed a critical browser-extension vulnerability reported by Halborn in September 2021 and stated that fixes began rolling out in January 2022, with Phantom users protected by April 2022.

Scope: browser_extensionFunds affected: unknownAction: updateEvidence: 1
2020-07-14
customer_data_breachhigh

E-commerce and marketing database breach discovered

Wallet: Ledger

Ledger discovered unauthorized access to its e-commerce and marketing database through a third-party API key; later publication of the stolen database exposed a much larger set of customer records.

Scope: customer_dataFunds affected: noAction: monitorEvidence: 2
2020-01-31
vulnerability_disclosedhigh

Physical read-protection downgrade attack disclosed

Wallet: Trezor

Kraken Security Labs disclosed a voltage-glitching attack that could extract seeds from Trezor Model One and Model T after physical access to the device.

Scope: deviceFunds affected: unknownAction: enable_passphraseEvidence: 2