Shipping provider customer data breach disclosed
Wallet: Trezor
Trezor disclosed that ShipMonk, a third-party fulfillment partner, experienced unauthorized access exposing customer order information.
Evidence-backed timeline
Search and filter reviewed vulnerabilities, exploits, supply-chain incidents, data breaches, and other security events. Severity describes the recorded event, not a permanent safety score for the wallet.
Wallet: Trezor
Trezor disclosed that ShipMonk, a third-party fulfillment partner, experienced unauthorized access exposing customer order information.
Wallet: Bitkey · Product: Bitkey Mobile App
Bitkey disclosed that the mobile app used a non-cryptographic random-number generator for a one-time relationship-enrollment secret. The demonstrated practical path was limited to narrow second-generation recovery-contact or inheritance flows and did not weaken wallet spending keys.
Wallet: COLDCARD
COLDCARD disclosed a seed-generation defect in affected firmware lines. Fixed releases restore the intended hardware-randomness path for future seed generation, but existing affected seeds require migration unless an advisory exception applies.
Wallet: BitBox · Product: BitBox02 Nova
BitBox disclosed two physical-access firmware issues in BitBox02 Nova. The more relevant scenario could reveal a reused device password after an advanced attack, while the attacked device's seed remained protected.
Wallet: Trust Wallet · Product: Trust Wallet Browser Extension
An unauthorized malicious Browser Extension v2.68 was published to the Chrome Web Store using a leaked publishing API key, enabling theft from users who logged in during the affected period.
Wallet: Blockstream Jade
Blockstream disclosed a descriptor-RPC memory-safety issue affecting Jade firmware 1.0.24 through 1.0.36 across Original Jade, Jade 1.1 and Jade Plus device types.
Wallet: Trezor
Trezor reported unauthorized access to a third-party support portal, potentially exposing names or nicknames and email addresses of users who had interacted with support.
Wallet: Ledger
A former employee phishing compromise enabled malicious Ledger Connect Kit packages to be published to NPM and dynamically loaded by some dApps, causing a small number of users to sign draining transactions.
Wallet: Leather · Product: Leather Browser Extension
Leather's security history records a browser-extension issue where browser textarea caching could leave a private key or mnemonic in local storage under certain conditions, creating exposure if another party gained access to the computer.
Wallet: Xverse · Product: Xverse Browser Extension
Xverse disclosed that browser behavior could cause a seed phrase to be written unencrypted to a local Chrome log during extension onboarding under certain conditions.
Wallet: Phantom · Product: Phantom Browser Extension
Phantom disclosed a critical browser-extension vulnerability reported by Halborn in September 2021 and stated that fixes began rolling out in January 2022, with Phantom users protected by April 2022.
Wallet: Ledger
Ledger discovered unauthorized access to its e-commerce and marketing database through a third-party API key; later publication of the stolen database exposed a much larger set of customer records.
Wallet: Trezor
Kraken Security Labs disclosed a voltage-glitching attack that could extract seeds from Trezor Model One and Model T after physical access to the device.