Trezor disclosed on Wednesday that a breach at its third-party fulfillment provider ShipMonk exposed personal information for 13,689 of its customers. That number breaks down as 11,742 customers with full exposure, meaning attackers now have their name, email address, phone number, and shipping address. Another 1,947 customers had partial data exposed. The affected orders shipped to customers in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal between May 10 and August 8 this year. Trezor’s own systems and hardware wallets were not compromised, and the company has been clear about that distinction. It is also the first breach in the company’s 13-year history to expose customer phone numbers and shipping addresses together.
Here is why that specific combination of data matters more than a typical retail data leak. Attackers now possess a curated list of 11,742 people who are all three of the following. Confirmed cryptocurrency holders, because they bought a hardware wallet in the last 90 days. Located at specific physical addresses. Reachable by phone. That is not a phishing target list. That is a physical attack target list. And we know exactly what happens when this specific combination of data reaches criminal networks, because France has been running the experiment in public for two years now.
In 2024, French authorities recorded roughly 30 crypto-related violent incidents. In 2025, the number climbed to about 45. In the first half of 2026 alone, French Interior Minister Laurent Nuñez reported 77 cases involving unlawful detention, kidnapping, extortion, or attempts. Chainalysis, using a narrower publicly documented count, tracked the French attack rate accelerating from 1.9 incidents per month in 2025 to 4.6 per month in the first half of 2026. Home invasions rose from 14 percent to 37 percent of all cases. Attacks targeting family members and close relatives of the primary holder climbed to more than 40 percent of French incidents. And 93 percent of French victims were local residents, which points to reconnaissance and planning rather than opportunism. French organized-crime prosecutors have responded with roughly 200 arrests and 88 indictments through mid-year.
What drove the surge is the part relevant to Trezor customers reading this newsletter. In 2024, a French tax official in the Paris area is alleged to have stolen and sold dossiers on high-net-worth crypto holders, including names, addresses, holdings, phone numbers, and tax records. Criminal intermediaries bought them, reportedly for around 800 euros per person. In January 2026, the French crypto tax reporting tool Waltio disclosed a separate breach exposing data on approximately 50,000 users. The stolen Waltio database appeared on a dark web marketplace on December 24, 2025. That specific breach has been directly linked to at least three subsequent kidnappings that netted attackers a combined $17.1 million. Ledger co-founder David Balland was kidnapped in France in January 2025 along with his partner. During the attack, one of his fingers was severed and sent to associates as part of a 10 million euro ransom demand. He was rescued after a police operation. Some French crypto executives now pay more than $50,000 per month for private security. NFT Paris and RWA Paris were both cancelled for 2026 over safety concerns. This is the actual, documented, real-world outcome of the exact data combination that Trezor customers just had leaked.
Trezor is not the first to do this and it will not be the last. Ledger suffered a breach in 2020 exposing data for nearly 300,000 customers, and that dataset produced documented waves of sophisticated phishing attacks and physical safety incidents against affected users. Ledger had another breach in January 2026 through its e-commerce partner Global-e. Trezor itself had breaches in April 2022 affecting roughly 107,000 users and January 2024 affecting roughly 66,000. And we cannot talk about the hardware wallet ecosystem in August 2026 without mentioning the Coldcard exploit that has drained roughly 2,055 bitcoin worth approximately $130 million from more than 7,300 wallets since July 30, or the BTCPay Server exploit last week that drained Lightning nodes belonging to Foundation and other prominent Bitcoin voices. Different attack surfaces. Same result. The wallet itself is not the failure point. The “everything around the wallet” is.
Which brings me to the harder question this pattern forces, and it is one I have been reluctant to ask out loud.
Is self-custody actually ready for retail? I have spent years telling readers that holding your own keys is the right answer to counterparty risk. I still believe the philosophical argument. The Mt Gox and Celsius and FTX failures happened because users trusted counterparties who did not deserve trust. Self-custody solves that specific problem. But solving one problem is not the same as being safe. What the last two years of hardware wallet incidents actually demonstrate is that the current retail self-custody offering has known failure modes at every layer that is not the actual hardware. Firmware bugs sitting dormant for years. Payment infrastructure with credential leaks. Fulfillment vendors with sloppy data hygiene. E-commerce partners getting breached. Tax reporting tools getting breached. And in the case of France, insider leaks from government databases producing targeting lists that produce kidnappings.
The response for sophisticated holders is real. Buy from anonymous delivery when it exists. Use PO boxes. Run multi-signature setups. Separate your online identity from any signal of crypto ownership. Never post about holdings publicly. Consider private security if you are a whale. Diversify hardware across vendors. And treat any single piece of the self-custody stack as fallible until proven otherwise. All of that is correct advice. Roughly 5 percent of the retail holders I am writing this newsletter for will actually do it.
For the other 95 percent, the honest conversation the industry has been avoiding is this. The current retail self-custody product is not fit for purpose for a retail user who does not have the operational security discipline of a professional. The wallet works. The delivery chain leaks. The tax reporting tool leaks. The government database leaks. The e-commerce partner leaks. And each leak has a growing body of documented physical outcomes attached to it. If the industry wants retail to hold its own keys, the industry has to build products that are actually safe for a retail user to hold. Anonymous delivery has to become the default. Vendor data retention has to be measured in days, not months. Third-party audits of fulfillment partners have to be as rigorous as audits of the firmware itself. And until that happens, retail holders who are not equipped to operate the current stack safely need to be told, honestly, that a regulated custodian with insured storage may be a more appropriate answer for them than the hardware wallet they were told to buy.
That is not a reversal of my position on self-custody. It is a calibration of it. Self-custody is right in principle and right for people who can operate it safely. The current product offering is not right for the retail user it is being sold to. The industry needs to earn the retail recommendation it already receives. Trezor announcing a forthcoming Anonymous Delivery option, targeted for the EU in September and the US by year-end, is a start. It is also two years overdue given what France has been demonstrating in public.
The slogan says not your keys, not your coins. What the last two years should have taught us is that it also matters whether your address, your phone number, and your family are safe from the criminal networks that increasingly know all three.
I’ll see you Monday.
SEC cancels long-awaited proposal of Reg Crypto, postponing meeting without new date
The Securities and Exchange Commission cancelled Friday’s open meeting to propose Regulation Crypto at approximately 5:13pm Eastern on Thursday, citing an unforeseen scheduling issue and providing no new date. The meeting was to have been the first formal SEC crypto rulemaking of Chair Paul Atkins’s tenure and would have opened for public comment a tailored offering regime for certain investment contracts involving crypto assets. The cancellation lands 12 days after the Senate went to recess without advancing the CLARITY Act, leaving the industry without a clear near-term path to either agency-level or congressional regulatory clarity.
Goldman Sachs leaps into bitcoin income ETFs with $2.25 billion NEOS buyout
Goldman Sachs announced Wednesday that it has agreed to acquire NEOS Investments in a cash-and-equity deal valued at up to $2.25 billion, gaining three crypto-linked income ETFs collectively holding more than $1.1 billion in assets and a broader options-based ETF platform managing roughly $30 billion across 19 funds. The flagship NEOS Bitcoin High Income ETF has grown to over $1 billion in assets since its October 2024 launch and generates approximately 27 percent annual yield through a covered-call strategy on Bitcoin ETPs. The deal follows Goldman’s December 2025 acquisition of Innovator Capital Management and will lift the bank’s total ETF assets under management above $130 billion, making it the world’s eighth-largest active ETF manager. Closing expected first quarter 2027 pending regulatory approval.
CFTC orders Kalshi to keep operating in $36B New York fight
The Commodity Futures Trading Commission invoked its emergency authority under Section 8a(9) of the Commodity Exchange Act on Tuesday to order prediction market operator Kalshi to continue operating despite a New York Attorney General lawsuit filed July 31 seeking to bar the exchange nationwide and recover more than $36 billion in damages. CFTC Chair Michael Selig framed the state action as an attempt to disrupt a federally regulated derivatives market through gambling law enforcement and stated that states cannot regulate interstate financial venues. The intervention is the second time in a month the CFTC has invoked emergency authority to protect Kalshi from state enforcement, following a July 14 order directing the exchange to serve Michigan residents.
Arch Public - It’s a hedge fund in your pocket. Built for retail traders, designed to outperform Wall Street. Try emotionless algorithmic trading at Arch Public today.
Promote your brand with The Wolf of All Streets. For sponsorship and partnership opportunities, contact info@thewolfofallstreets.io.
The Wolf Pack - My Telegram group where I share daily market updates, real-time observations, and ongoing discussions with the community. There’s a dedicated channel and group chat, and it’s completely free to join.
X - I spend most of my time on X, contributing to CryptoTownHall every weekday morning, sharing random charts, and responding to as many of you as I can.
YouTube - Home of the Wolf Of All Streets Podcast and daily livestreams. Market updates, charts, and analysis!
The views and opinions expressed here are solely my own and should in no way be interpreted as financial advice. Every investment and trading move involves risk. You should conduct your own research when making a decision. I am not a financial advisor. Nothing contained in this e-mail constitutes or shall be construed as an offering of financial instruments or as investment advice or recommendations of an investment strategy or whether or not to "Buy," "Sell," or "Hold" an investment.
Thanks for reading The Wolf Den! Subscribe for free to receive new posts and support my work.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.