Evidence-backed timeline

Wallet incidents

Search and filter reviewed vulnerabilities, exploits, supply-chain incidents, data breaches, and other security events. Severity describes the recorded event, not a permanent safety score for the wallet.

33 of 33 reviewed incident records
2026-09-15
unauthorized_accesscritical

Mass unauthorized transfers affected DCENT App Wallet users

Wallet: DCENT · Product: DCENT App Wallet

DCENT disclosed abnormal unauthorized asset transfers involving its software App Wallet while separately stating that no impact originating from the hardware wallets themselves had been confirmed. Independent XRPL on-chain analysis later tracked the same incident through September 25, reporting 12,402,589 XRP taken from 7,393 XRP Ledger wallets across repeated sweep and account-deletion activity.

Scope: mobile_appFunds affected: yesAction: update, move_funds, rotate_seed, monitorEvidence: 7
2026-09-05
seed_key_exposurecritical

Forensic analysis found seed transmission in XRPH Wallet staking flows

Wallet: XRPH Wallet · Product: XRPH Wallet Mobile

Forensic analysis of XRPH Wallet Android build 8.0.15 found that seed material was stored unencrypted in the app's local database and that staking/unstaking code transmitted the user's seed to an XRP Healthcare server. The same investigation found 1,225 wallets that had staked through the app and 1,198 of them among the drained wallets.

Scope: key_storageFunds affected: unknownAction: move_funds, rotate_seed, monitorEvidence: 2
2026-09-03
unauthorized_accesscritical

Mass unauthorized drain affected XRPH Wallet users

Wallet: XRPH Wallet · Product: XRPH Wallet Mobile

Beginning at 22:07 UTC on 2026-09-03, XRPH Wallet accounts were swept into a newly created collector address. XRP Healthcare reported 4,011 affected wallets and later warned users not to use XRPH Wallet until further notice. Independent ledger reconstruction identified 4,010 victim senders after excluding the attacker's collector-funding transaction and traced the stolen value through XRPL and NEAR Intents into approximately 445,198 DAI on Ethereum.

Funds affected: yesAction: move_funds, rotate_seed, monitorEvidence: 3
2026-08-27
vulnerability_disclosed

Ledger disclosed command-interleaving signing vulnerability class

Wallet: Ledger

Ledger disclosed that applications built with affected Ledger Secure SDK releases could accept a new APDU command while an earlier command was awaiting on-screen user review, allowing signing parameters held in application state to be changed after display but before signature generation when an application did not independently validate its state machine.

Scope: transaction_signingFunds affected: unknownAction: updateEvidence: 1
2026-08-27
vulnerability_disclosedhigh

Ledger disclosed Ethereum clear-signing array-count truncation vulnerability

Wallet: Ledger

Ledger disclosed an Ethereum app Generic Transaction Parser flaw in which an attacker-controlled 16-bit array element count was stored in an 8-bit countdown field. For a 257-element array, the device could review only one operation while its signature still authorized the complete transaction.

Scope: transaction_signingFunds affected: unknownAction: updateEvidence: 1
2026-08-27
vulnerability_disclosed

Ledger disclosed Ethereum swap token-approval substitution vulnerability

Wallet: Ledger

Ledger disclosed an Ethereum app flaw in the token-payment path used by the Exchange application during swaps: the path checked the expected address and quantity but not the requested operation type, so a token approval carrying the expected values could pass validation and be signed without being displayed as an approval.

Scope: transaction_signingFunds affected: unknownAction: updateEvidence: 1
2026-08-16
customer_data_breachhigh

Customer order data exposure disclosed

Wallet: SafePal

SafePal disclosed exposure of customer order information affecting approximately 40,000 customers. SafePal stated that private keys and seed phrases were not compromised.

Scope: customer_dataFunds affected: noAction: monitorEvidence: 1
2026-08-13
third_party_data_breachhigh

ShipMonk customer data breach disclosed and later expanded

Wallet: Trezor

Trezor disclosed that ShipMonk, a third-party fulfillment partner, experienced unauthorized access exposing customer order information; on 2026-09-04 Trezor reported that the breach also affected approximately 67,000 additional U.S. customers whose orders dated from November 2019 to August 2021.

Scope: third_party_vendorFunds affected: noAction: monitorEvidence: 4
2026-08-02
software_issuehigh

Relationship-enrollment randomness bug disclosed

Wallet: Bitkey · Product: Bitkey Mobile App

Bitkey disclosed that the mobile app used a non-cryptographic random-number generator for a one-time relationship-enrollment secret. The demonstrated practical path was limited to narrow second-generation recovery-contact or inheritance flows and did not weaken wallet spending keys.

Scope: mobile_appFunds affected: noAction: update, reconfigureEvidence: 1
2026-07-30
vulnerability_disclosedcritical

Seed-generation entropy defect disclosed

Wallet: COLDCARD

COLDCARD disclosed a seed-generation defect in affected firmware lines. Fixed releases restore the intended hardware-randomness path for future seed generation, but existing affected seeds require migration unless an advisory exception applies.

Scope: seed_generationFunds affected: unknownAction: update, migrateEvidence: 1
2026-06-21
exploitcritical

SecondFi security incident exploited per-transaction signature flaw

Wallet: Yoroi · Product: Yoroi Browser Extension

SecondFi reported that between June 21 and June 23 external attackers exploited a cryptographic flaw in per-transaction signature generation, resulting in approximately 16.1 million ADA being stolen from 374 wallets.

Scope: transaction_signingFunds affected: yesAction: migrate, monitorEvidence: 1
2026-04-28
vulnerability_disclosedmedium

External plugin authorization bypass disclosed

Wallet: Electrum · Product: Electrum

Electrum disclosed an external-plugin authorization bypass that could allow a rogue local process with filesystem write access to the Electrum data directory to execute arbitrary plugin code inside Electrum. The official advisory states the external-plugin system was affected from Electrum 4.6.0 until the fix in 4.7.2.

Scope: softwareFunds affected: unknownAction: updateEvidence: 1
2026-04-28
vulnerability_disclosedlow

Nostr Wallet Connect spending-limit bypass disclosed

Wallet: Electrum · Product: Electrum

Electrum disclosed two flaws in its Nostr Wallet Connect plugin that could let a malicious or compromised NWC client spend above the configured daily limit through concurrent budget checks and millisatoshi truncation. The official advisory states the NWC plugin was affected from Electrum 4.6.0 until the fix in 4.7.2.

Scope: softwareFunds affected: unknownAction: updateEvidence: 1
2026-03-05
software_issuemedium

Password-removal crash window could leave Sparrow wallet database unreadable

Wallet: Sparrow Wallet · Product: Sparrow Wallet Desktop

A Sparrow Wallet issue documented a narrow crash window during removal of a wallet password where the H2 wallet file could become unencrypted while seed or keystore state remained encrypted, causing Sparrow to reject the resulting inconsistent wallet database. Maintainer Craig Raw later said the race window appeared real but very small.

Scope: softwareFunds affected: unknownEvidence: 2
2026-01-26
vulnerability_disclosedmedium

Two BitBox02 Nova firmware security issues disclosed and fixed

Wallet: BitBox · Product: BitBox02 Nova

BitBox disclosed two physical-access firmware issues in BitBox02 Nova. The more relevant scenario could reveal a reused device password after an advanced attack, while the attacked device's seed remained protected.

Scope: firmwareFunds affected: noAction: updateEvidence: 1
2025-12-24
supply_chain_compromisecritical

Malicious Trust Wallet Browser Extension v2.68 published

Wallet: Trust Wallet · Product: Trust Wallet Browser Extension

An unauthorized malicious Browser Extension v2.68 was published to the Chrome Web Store using a leaked publishing API key, enabling theft from users who logged in during the affected period.

Scope: supply_chainFunds affected: yesAction: move_funds, updateEvidence: 1
2025-12-16
vulnerability_disclosedhigh

Jade RPC stack-overwrite vulnerability disclosed

Wallet: Blockstream Jade

Blockstream disclosed a descriptor-RPC memory-safety issue affecting Jade firmware 1.0.24 through 1.0.36 across Original Jade, Jade 1.1 and Jade Plus device types.

Scope: firmwareFunds affected: noAction: updateEvidence: 1
2025-02-21
supply_chain_compromisecritical

Safe{Wallet} Web supply-chain compromise enabled targeted Bybit transaction manipulation

Wallet: Safe · Product: Safe{Wallet} Web

A targeted compromise of a Safe{Wallet} developer workstation and Safe{Wallet} web-delivery infrastructure enabled malicious JavaScript to manipulate a Bybit Safe transaction on 2025-02-21. The manipulated transaction resulted in approximately $1.46 billion in assets leaving Bybit's affected Ethereum cold wallet.

Scope: supply_chainFunds affected: yesAction: monitorEvidence: 3
2024-12-31
software_issuehigh

Tangem App logging bug could include private-key material in diagnostic logs

Wallet: Tangem · Product: Tangem App

Tangem disclosed that when a wallet was activated with a generated or imported seed phrase, a bug in the mobile app's NFC logging mechanism could write the private key into app logs. Potential exposure required the user to also contact Tangem support through the app within seven days, allowing those logs to be included with the support interaction.

Scope: mobile_appFunds affected: noAction: update, move_funds, rotate_seedEvidence: 1
2024-01-17
third_party_data_breachhigh

Third-party support portal accessed without authorization

Wallet: Trezor

Trezor reported unauthorized access to a third-party support portal, potentially exposing names or nicknames and email addresses of users who had interacted with support.

Scope: third_party_vendorFunds affected: noAction: monitorEvidence: 2
2023-12-14
supply_chain_compromisecritical

Malicious Ledger Connect Kit versions published through compromised NPM account

Wallet: Ledger

A former employee phishing compromise enabled malicious Ledger Connect Kit packages to be published to NPM and dynamically loaded by some dApps, causing a small number of users to sign draining transactions.

Scope: supply_chainFunds affected: yesAction: monitorEvidence: 1
2023-08-09
vulnerability_disclosedhigh

BitForge Lindell17 key-exfiltration vulnerability disclosed

Wallet: Zengo · Product: Zengo Crypto Wallet

Fireblocks publicly disclosed a Lindell17 implementation vulnerability initially discovered in Zengo that could leak key material across repeated failed signing attempts when an attacker had privileged access. Fireblocks and Zengo state that Zengo mitigated the issue through responsible disclosure and that no Zengo wallets were exploited.

Scope: transaction_signingFunds affected: noAction: noneEvidence: 2
2023-08-08
vulnerability_disclosedhigh

Browser-extension cached secret-key vulnerability reported

Wallet: Leather · Product: Leather Browser Extension

Leather's security history records a browser-extension issue where browser textarea caching could leave a private key or mnemonic in local storage under certain conditions, creating exposure if another party gained access to the computer.

Scope: key_storageFunds affected: unknownAction: updateEvidence: 1
2023-06-07
vulnerability_disclosedhigh

Xverse Extension local seed-phrase logging issue disclosed

Wallet: Xverse · Product: Xverse Browser Extension

Xverse disclosed that browser behavior could cause a seed phrase to be written unencrypted to a local Chrome log during extension onboarding under certain conditions.

Scope: browser_extensionFunds affected: noAction: update, migrateEvidence: 1
2023-06-03
unauthorized_accesshigh

Atomic Wallet users reported unauthorized transactions

Wallet: Atomic Wallet

Atomic Wallet reported receiving user complaints on June 3, 2023 about unauthorized transactions from affected wallets and said funds associated with the incident were being mixed and laundered while the company investigated.

Scope: otherFunds affected: yesEvidence: 1
2022-10-11
exploithigh

Rabby Swap smart contract exploited

Wallet: Rabby · Product: Rabby Browser Extension

Rabby reported that the Rabby Swap smart contract suffered a hack attack and that stolen funds were being tracked. Users who had used Swap were instructed to revoke existing approvals across chains, while Rabby stated that users who had not used Swap were unaffected.

Scope: smart_contractFunds affected: yesAction: revoke_permissionsEvidence: 3
2022-06-15
vulnerability_disclosedcritical

Phantom disclosed remediation of the Demonic browser-extension vulnerability

Wallet: Phantom · Product: Phantom Browser Extension

Phantom disclosed a critical browser-extension vulnerability reported by Halborn in September 2021 and stated that fixes began rolling out in January 2022, with Phantom users protected by April 2022.

Scope: browser_extensionFunds affected: unknownAction: updateEvidence: 1
2022-06-15
vulnerability_disclosedmedium

Demonic vulnerability exposed MetaMask Extension recovery phrases on disk

Wallet: MetaMask · Product: MetaMask Browser Extension

Halborn disclosed CVE-2022-32969, known as Demonic, in which browser session-restore behavior could cache an imported Secret Recovery Phrase to disk in plaintext under specified conditions. MetaMask Extension versions before 10.11.3 were affected; MetaMask implemented mitigations in 10.11.3 and later, and MetaMask Mobile was not affected.

Scope: browser_extensionFunds affected: unknownAction: updateEvidence: 3
2022-06
vulnerability_disclosedcritical

MetaMask Extension critical clickjacking vulnerability disclosed

Wallet: MetaMask · Product: MetaMask Browser Extension

MetaMask reported a critical Extension-only clickjacking vulnerability that could render the wallet UI as a hidden layer over a malicious site and trick users into revealing private data or sending crypto-assets. MetaMask awarded the reporting team a $120,000 bounty and stated that Extension 10.14.6 and later were protected.

Scope: browser_extensionFunds affected: unknownAction: updateEvidence: 1
2020-07-14
customer_data_breachhigh

E-commerce and marketing database breach discovered

Wallet: Ledger

Ledger discovered unauthorized access to its e-commerce and marketing database through a third-party API key; later publication of the stolen database exposed a much larger set of customer records.

Scope: customer_dataFunds affected: noAction: monitorEvidence: 2
2020-01-31
vulnerability_disclosedhigh

Physical read-protection downgrade attack disclosed

Wallet: Trezor

Kraken Security Labs disclosed a voltage-glitching attack that could extract seeds from Trezor Model One and Model T after physical access to the device.

Scope: deviceFunds affected: unknownAction: enable_passphraseEvidence: 2
2018-06-09
unauthorized_accessmedium

imToken 2.0 Beta AWS account breached

Wallet: imToken · Product: imToken App

imToken reported that an attacker reset an email-linked password and obtained access to the Amazon AWS account hosting its 2.0 Beta servers. The company cut off access after detecting the intrusion and said the attacker may have obtained beta-tester device data, wallet addresses and subscribed email addresses.

Scope: customer_dataFunds affected: noAction: monitorEvidence: 1
2018-04-24
phishing_campaignhigh

BGP and DNS hijack redirected MyEtherWallet web users to a phishing site

Wallet: MyEtherWallet

A BGP route hijack affecting Amazon Route 53 DNS infrastructure redirected some DNS resolution for myetherwallet.com to a malicious server. Users who proceeded through the invalid TLS certificate warning could submit wallet credentials to the phishing site, and the attacker used stolen information to transfer Ethereum.

Scope: otherFunds affected: yesEvidence: 2