An e-commerce database was breached and published. The records identified people who had bought bitcoin hardware wallets, along with where they lived.
~1M email addresses and roughly 272,000 detailed records including names, physical addresses and phone numbers.
Buying a hardware wallet is a disclosure that you hold bitcoin. Those records still drive targeted phishing and physical-coercion attempts six years later, and no firmware update can fix a leak of who you are and where you live.
These are the custody configurations structurally exposed to this kind of event. It describes the failure class, not any individual holder.
Whether your own arrangement sits in one of those groups is the question our Custody Independence Standard is designed to answer, and the four questions in Is your custody setup actually safe? walk through it.
Vendor incident disclosures, published breach data
Figures are as reported by the named sources. Proof of Custody has not independently reproduced the underlying analysis.
Proof of Custody, "Ledger customer database breach" incident record, proofofcustody.io/incidents/ledger-data-breach-2020An e-commerce database was breached and published. The records identified people who had bought bitcoin hardware wallets, along with where they lived. Reported loss: No direct bitcoin loss.
Buying a hardware wallet is a disclosure that you hold bitcoin. Those records still drive targeted phishing and physical-coercion attempts six years later, and no firmware update can fix a leak of who you are and where you live.
This class of failure could reach: self-custody, single signature; multisig, devices from one vendor; multisig, devices from several vendors; collaborative custody. It describes the failure class rather than any individual holder.