Issue #007 · Week of August 16, 2026

This Week’s Verdict

The threat model quietly moved from your seed phrase to your front door. Between Trezor, SafePal, a French tax breach, and Israel’s largest exchange, the week’s real exploit was logistics metadata, not smart contracts. Meanwhile a president got a bank charter and Bitcoin slid under $63K, which is to say the board rearranged itself exactly as leverage said it would.

The Breaches

The headline number came from self-custody, not an exchange. Cointelegraph’s Crypto Biz logged a $116 million Bitcoin wallet exploit, and Galaxy Research separately estimated that Coldcard-related thefts could top $150 million, with the recent lull suggesting vulnerable holders either migrated or were already emptied. Neither of these is a protocol failure in the DeFi sense. They are the slow, grinding harvest of poorly secured keys, and the money does not come back.

The rest of the week’s damage was data, which converts into money later. Trezor confirmed roughly 14,000 customers exposed through its shipping provider ShipMonk: names, emails, phone numbers, and for many, physical shipping addresses. Days later SafePal disclosed a breach hitting nearly 40,000 customers’ order information, same attack vector, same lesson ignored. Both firms will tell you their devices and backups were never touched. True, and beside the point. The leak links a confirmed hardware wallet purchase to a real-world identity and location, which is the exact input a wrench attack requires.

Add the largest crypto exchange in Israel, Bits of Gold, where customer identification details and deposit addresses were reportedly compromised, and the French tax breach exposing nearly 678,000 taxpayers and businesses, now on pace to make 2026 France’s worst year ever for violent crimes targeting crypto holders. The exploit surface this week was a spreadsheet of who owns what and where they sleep.

Vulnerabilities Worth Your Attention

  • macOS Screen Sharing (CVE-rated 9.8): The Netherlands’ NCSC warned that attackers are actively exploiting a macOS authentication bypass after public exploit code dropped, deploying Monero miners. Critical severity, patch available, exploitation already underway. The gap between disclosure and mass abuse is now measured in days.
  • DefiLlama phishing apps on the App Store: The founder said Apple removed a fake app only after DefiLlama documented it draining a small wallet, and delayed its own mobile launch as a result. The App Store review process is not your security perimeter.
  • x402 facilitators failing security tests: Coinbase and 14 other x402 facilitators reportedly failed security tests designed for the coming AI-agent payment economy. File this under systemic risk being built in real time, before the agents even show up to spend.
  • SAP Commerce Cloud (max severity): A maximum-severity RCE was targeted in attacks three days after patching. Not crypto-native, but it runs commerce backends that touch plenty of it.

Threat Actors & Campaigns

The DPRK-flavored social engineering playbook keeps working because it targets people, not code. Singapore attributed $11.8 million in losses to fake LinkedIn crypto job scams, where malware planted during a bogus coding assessment harvested a session token and bypassed multi-factor authentication to reach a code repository. Stolen tokens, not stolen passwords, remain the path of least resistance.

New malware to note: AmnesiaStealer, a macOS info-stealer spreading via ClickFix lures, ships a streaming module letting attackers interactively drive the victim’s browser in real time. Session hijacking is graduating from token theft to live remote control. Elsewhere, the ShinyHunters crew exposed 1.6 million RingCentral accounts, and Clop claimed 89GB from Shell, reminders that the extortion supply chain feeding future crypto-targeting lists never sleeps.

The through-line: every leaked customer database this week is raw material for the next wave of phishing, coercion, and wrench attacks. The threat actors do not need to break your wallet if a courier’s database tells them where to knock.

The Bigger Picture

The biggest regulatory move was also the most predictable. The OCC granted conditional approval for World Liberty Trust Company, the Trump-linked venture, to operate as a national trust bank and take over issuance of the USD1 stablecoin from BitGo. Senator Elizabeth Warren called it the most brazen self-dealing in financial history. Priced in or not, the precedent is set: the family issuing the currency now also runs the bank.

The legislative track went the other way. Galaxy cut CLARITY Act odds to 10%, citing unresolved ethics, stablecoin yield, and developer protection issues plus a narrow September Senate window. The SEC promptly shelved a crypto rule meeting after the Senate recessed without a vote. Structure over sentiment, again.

Markets did what leverage told them to. Bitcoin slipped below $63,000, then toward $62.5K, ignoring cooperative US inflation while Binance longs faced a cleanout in open interest. The institutional bid, however, kept building underneath: UBS grew Bitcoin ETF call options 24-fold, Morgan Stanley raised IBIT holdings 23%, JPMorgan boosted its BTC ETF position 25% and quadrupled its ETH position, and Paul Tudor Jones’ firm bought back in after a year of selling. CoinDesk declared the “long bitcoin, short the bankers” era officially over. The bankers won by buying the ETF.

On the plumbing: Israel’s Bank Leumi tapped Galaxy to offer BTC, ETH, and SOL trading from early 2027, Ethereum devs are narrowing 66 proposals for the privacy-focused Hegotá upgrade, and Solana proposed a fee overhaul to make resource hogs pay while burning more SOL. Tether finally cleared a first KPMG audit, ending its longest-running criticism, though it still declines to publish the statements. Meanwhile the ECB found crypto payment acceptance below 1% in the euro area, a quiet reminder that after all this, almost nobody is paying for coffee with it.

The board shifted toward banks, ETFs, and charters. The risk shifted toward your doorstep. Neither was a surprise if you were reading the explorer instead of the timeline.

Resources

  • https://www.reddit.com/r/CryptoCurrency/comments/1vp71ny/trezor_data_breach_exposes_almost_14000_customers/
  • https://www.coindesk.com/tech/2026/08/16/crypto-wallet-safepal-reveals-a-data-breach-exposing-nearly-40-000-customers-order-info
  • Incident trackers (reference standard): Rekt leaderboard · SlowMist Hacked

More: Issues · Field Notes · RTFM


New Issue every week. Follow @ItsAlreadyPrice or subscribe via RSS so the next exploit does not surprise you.