Search and filter reviewed vulnerabilities, exploits, supply-chain incidents, data breaches, and other security events. Severity describes the recorded event, not a permanent safety score for the wallet.
33 of 33 reviewed incident records
2026-09-15
unauthorized_accesscritical
Mass unauthorized transfers affected DCENT App Wallet users
DCENT disclosed abnormal unauthorized asset transfers involving its software App Wallet while separately stating that no impact originating from the hardware wallets themselves had been confirmed. Independent XRPL on-chain analysis later tracked the same incident through September 25, reporting 12,402,589 XRP taken from 7,393 XRP Ledger wallets across repeated sweep and account-deletion activity.
Forensic analysis of XRPH Wallet Android build 8.0.15 found that seed material was stored unencrypted in the app's local database and that staking/unstaking code transmitted the user's seed to an XRP Healthcare server. The same investigation found 1,225 wallets that had staked through the app and 1,198 of them among the drained wallets.
Beginning at 22:07 UTC on 2026-09-03, XRPH Wallet accounts were swept into a newly created collector address. XRP Healthcare reported 4,011 affected wallets and later warned users not to use XRPH Wallet until further notice. Independent ledger reconstruction identified 4,010 victim senders after excluding the attacker's collector-funding transaction and traced the stolen value through XRPL and NEAR Intents into approximately 445,198 DAI on Ethereum.
Ledger disclosed that applications built with affected Ledger Secure SDK releases could accept a new APDU command while an earlier command was awaiting on-screen user review, allowing signing parameters held in application state to be changed after display but before signature generation when an application did not independently validate its state machine.
Ledger disclosed an Ethereum app Generic Transaction Parser flaw in which an attacker-controlled 16-bit array element count was stored in an 8-bit countdown field. For a 257-element array, the device could review only one operation while its signature still authorized the complete transaction.
Ledger disclosed an Ethereum app flaw in the token-payment path used by the Exchange application during swaps: the path checked the expected address and quantity but not the requested operation type, so a token approval carrying the expected values could pass validation and be signed without being displayed as an approval.
SafePal disclosed exposure of customer order information affecting approximately 40,000 customers. SafePal stated that private keys and seed phrases were not compromised.
Trezor disclosed that ShipMonk, a third-party fulfillment partner, experienced unauthorized access exposing customer order information; on 2026-09-04 Trezor reported that the breach also affected approximately 67,000 additional U.S. customers whose orders dated from November 2019 to August 2021.
Bitkey disclosed that the mobile app used a non-cryptographic random-number generator for a one-time relationship-enrollment secret. The demonstrated practical path was limited to narrow second-generation recovery-contact or inheritance flows and did not weaken wallet spending keys.
SecondFi reported that between June 21 and June 23 external attackers exploited a cryptographic flaw in per-transaction signature generation, resulting in approximately 16.1 million ADA being stolen from 374 wallets.
Electrum disclosed an external-plugin authorization bypass that could allow a rogue local process with filesystem write access to the Electrum data directory to execute arbitrary plugin code inside Electrum. The official advisory states the external-plugin system was affected from Electrum 4.6.0 until the fix in 4.7.2.
Electrum disclosed two flaws in its Nostr Wallet Connect plugin that could let a malicious or compromised NWC client spend above the configured daily limit through concurrent budget checks and millisatoshi truncation. The official advisory states the NWC plugin was affected from Electrum 4.6.0 until the fix in 4.7.2.
A Sparrow Wallet issue documented a narrow crash window during removal of a wallet password where the H2 wallet file could become unencrypted while seed or keystore state remained encrypted, causing Sparrow to reject the resulting inconsistent wallet database. Maintainer Craig Raw later said the race window appeared real but very small.
Scope: softwareFunds affected: unknownEvidence: 2
2026-01-26
vulnerability_disclosedmedium
Two BitBox02 Nova firmware security issues disclosed and fixed
BitBox disclosed two physical-access firmware issues in BitBox02 Nova. The more relevant scenario could reveal a reused device password after an advanced attack, while the attacked device's seed remained protected.
An unauthorized malicious Browser Extension v2.68 was published to the Chrome Web Store using a leaked publishing API key, enabling theft from users who logged in during the affected period.
Blockstream disclosed a descriptor-RPC memory-safety issue affecting Jade firmware 1.0.24 through 1.0.36 across Original Jade, Jade 1.1 and Jade Plus device types.
A targeted compromise of a Safe{Wallet} developer workstation and Safe{Wallet} web-delivery infrastructure enabled malicious JavaScript to manipulate a Bybit Safe transaction on 2025-02-21. The manipulated transaction resulted in approximately $1.46 billion in assets leaving Bybit's affected Ethereum cold wallet.
Tangem disclosed that when a wallet was activated with a generated or imported seed phrase, a bug in the mobile app's NFC logging mechanism could write the private key into app logs. Potential exposure required the user to also contact Tangem support through the app within seven days, allowing those logs to be included with the support interaction.
Trezor reported unauthorized access to a third-party support portal, potentially exposing names or nicknames and email addresses of users who had interacted with support.
A former employee phishing compromise enabled malicious Ledger Connect Kit packages to be published to NPM and dynamically loaded by some dApps, causing a small number of users to sign draining transactions.
Fireblocks publicly disclosed a Lindell17 implementation vulnerability initially discovered in Zengo that could leak key material across repeated failed signing attempts when an attacker had privileged access. Fireblocks and Zengo state that Zengo mitigated the issue through responsible disclosure and that no Zengo wallets were exploited.
Leather's security history records a browser-extension issue where browser textarea caching could leave a private key or mnemonic in local storage under certain conditions, creating exposure if another party gained access to the computer.
Xverse disclosed that browser behavior could cause a seed phrase to be written unencrypted to a local Chrome log during extension onboarding under certain conditions.
Atomic Wallet reported receiving user complaints on June 3, 2023 about unauthorized transactions from affected wallets and said funds associated with the incident were being mixed and laundered while the company investigated.
Rabby reported that the Rabby Swap smart contract suffered a hack attack and that stolen funds were being tracked. Users who had used Swap were instructed to revoke existing approvals across chains, while Rabby stated that users who had not used Swap were unaffected.
Phantom disclosed a critical browser-extension vulnerability reported by Halborn in September 2021 and stated that fixes began rolling out in January 2022, with Phantom users protected by April 2022.
Halborn disclosed CVE-2022-32969, known as Demonic, in which browser session-restore behavior could cache an imported Secret Recovery Phrase to disk in plaintext under specified conditions. MetaMask Extension versions before 10.11.3 were affected; MetaMask implemented mitigations in 10.11.3 and later, and MetaMask Mobile was not affected.
MetaMask reported a critical Extension-only clickjacking vulnerability that could render the wallet UI as a hidden layer over a malicious site and trick users into revealing private data or sending crypto-assets. MetaMask awarded the reporting team a $120,000 bounty and stated that Extension 10.14.6 and later were protected.
Ledger discovered unauthorized access to its e-commerce and marketing database through a third-party API key; later publication of the stolen database exposed a much larger set of customer records.
Kraken Security Labs disclosed a voltage-glitching attack that could extract seeds from Trezor Model One and Model T after physical access to the device.
imToken reported that an attacker reset an email-linked password and obtained access to the Amazon AWS account hosting its 2.0 Beta servers. The company cut off access after detecting the intrusion and said the attacker may have obtained beta-tester device data, wallet addresses and subscribed email addresses.
A BGP route hijack affecting Amazon Route 53 DNS infrastructure redirected some DNS resolution for myetherwallet.com to a malicious server. Users who proceeded through the invalid TLS certificate warning could submit wallet credentials to the phishing site, and the attacker used stolen information to transfer Ethereum.