Ethereum Researcher Calls for Crypto Industry to Prepare for AI Threats
Bitcoin Buyers Strengthen Positions Between $81,000 and $82,000
Gate Launches All-in-One Finance App, Gate Money, for Global Users
Paxos Expands Offerings with XRP Trading and Custody for Institutions
HIVE Digital Technologies Expands Hydro-Powered Campus in Paraguay to 400 MW
BitGo Bank & Trust Launches ETH Staking for US Clients via Lido
Centrifuge’s deSPXA Token Accepted as Collateral on Hyperdrive
Orca DAO Proposes Acquisition and Treasury Overhaul Amid 84% Surge in ORCA Token
Chainlink Announces 40 New Integrations in September 2026
Moody's Assigns B3 Rating to Sky, Highlights Capital Concerns
Eric Trump Highlights AI as Key Driver for Digital Asset Growth at Token2049
Noah Secures $16 Million in Additional Funding, Totaling $38 Million in Seed Round
Crypto Liquidations Reach $608 Million Amid Ether Price Reversal
Circle and Tereina Integrate Stablecoins into SAP Pay for Enhanced Enterprise Payments
Solana Reports Record Monthly Active Programs in September 2026
Tether Partners with Kazakhstan's Central Bank to Explore Tenge Stablecoin
StablecoinX Shares Now Available as Tokenized Securities on Binance's bStocks Platform
Standard Chartered Projects Ethena's ENA Token to Reach $1.10 by 2027
Crypto Trader Frogman Loses Over $4 Million in Hack During TOKEN2049
Jupiter Lend Surpasses Kamino as Solana's Leading Lending Protocol
Europol Warns Crypto Wallets Vulnerable to Future Quantum Attacks
Solana Liquidity Declines Over 28% in 2026 Amid Market Changes
Spark Savings USDT Vault Sees Rapid Growth to $600 Million
SwissBorg Integrates Worldcoin's WLD Token for Multi-Asset Swaps
Hyperliquid Policy Center CEO Jake Chervinsky said that "every single exchange,"
Dragonfly Managing Partner Challenges Cryptocurrency Adoption Narrative at TOKEN2049 Summit
Russia Registers First Cryptocurrency Exchanges and Custodians
XRP Price Drops to $1.47: Why Is XRP Down Today?
Jito's JTX plans to launch a mobile app this fall, with a new equities feature in
Why Is Stacks Suddenly on Everyone’s Radar?
Meritz Securities Partners With Ripple to Explore Digital Asset Services in South Korea
Russia approves first crypto exchanges and custodians, Sberbank plans to launch crypto products in December
Upbit parent Dunamu and NAVER Financial postpone share swap to March next year
Binance to open Alpha airdrop claim and trading at 17:00 today
CryptoQuant: Analysts Are Most Bullish on Solana and Ethereum
Bitcoin Between Profit-Taking and Trend Confirmation“Profit-taking can slow the advance as the...
Robinhood adds $25 million in Bitcoin to its own balance sheet, marking...
Data: Global stablecoin holders surpass 300 million, BNB Chain posts largest Q3 growth
Binance Finalizes Token Merger of Stargate Finance into LayerZero
Russia clears first crypto exchanges, custodians under new law
979 $BTC (82,401,569 USD) transferred from #Robinhood to #Cumberland...
BlackRock Says AI Agents May Use Stablecoins for Payments…
Binance Has Completed the Stargate Finance (STG) Token Merge to LayerZero (ZRO)Binance has completed...
24,000 BTC Just Left Exchanges: Is Bitcoin’s (BTC) Supply Crunch Heating Up?
BTCC Exchange Launches Refreshed Trust Center: Alex Hung on 15 Years of Earning Traders’ Trust
XRP ETFs Logged 12 Straight Weeks of Inflows Then XRP Hit $1.45
999 $BTC (84,270,890 USD) transferred from unknown wallet to #Robinhood...
Down but not out. Bitcoin's stair-step bullish trajectory is still intact
A whale withdrew 110 million lobster tokens, accounting for 11% of the total supply
Eric Trump Highlights AI's Positive Impact on Cryptocurrency at Token2049 Conference
Eric Trump Highlights Stablecoins as Future Payroll Method at Token2049 Conference
Ether.fi Launches Dollar Stablecoin, With Ethena Running the Reserves
South Africa’s FNB Launches Crypto Trading Through VALR…
Crypto and Stock Trading App Robinhood Adds $25M in Bitcoin to Balance Sheet
Bitcoin Price Today: BTC Falls to $84K as $546M Liquidations, ETF Outflows Hit Before Fed
JUST IN: Zcash completes bitcoin's evolutionary arc by fulfilling both privacy and "sound money"
$HYPE DAT COMPANY HypeStrat CEO dschamis SAYS “solana DOES A LOT OF THINGS REALLY WELL THE...
CryptoQuant: After Excluding BTC Dormant for Over 10 Years, the Share of Supply in Profit Has Held Around 60%
Spot bitcoin ETFs saw $118.9 million in net inflows on Tuesday, while spot ether ETFs
U.S. Prosecutors Cite Bitcoin Fog Ruling in Case Against Tornado Cash Developer Roman Storm
Bitcoin ETFs Pull In $118.8M as Ether Funds Lose $201.9M on…
Cathie Wood's Ark Invest sold $7.1 million worth of Robinhood shares across two ETFs,
DOJ invokes Bitcoin Fog ruling in potential blow to Roman Storm acquittal bid
0xPolygon FOUNDATION CEO sandeepnailwal SAYS THERE WAS "ABSOLUTELY NO INTENTION TO SUBTWEET...
Bitcoin Falls Below $84K While Oil Surges Past $100 on Hormuz Crisis
XRP News Today: Why October 12 Is Drawing Attention From Institutional Digital Asset Watchers
Anthropic IPO News: Nasdaq-100 Fast Entry Could Put Anthropic In Index Funds Within Weeks
End of Abstract: Igloo Is Winding Down Its Blockchain and Shifting Its Focus Back to Pudgy Penguins
Circle, Ripple and Standard Chartered Back OKX as Its $25 Billion Valuation Holds Flat
The biggest vulnerability in your Bitcoin wallet might be the shipping label
Hardware wallets might be able to protect your keys, but the paperwork from buying them could expose your identity.
To buy a hardware wallet, you give a company your name and address so it can send you a device designed to put you in control of your money. Once you've unpacked the box and set it up, there is little reason to think about the order again.
However, somewhere in the delivery business a record of that purchase may survive for years.
In a Sept. 4 update to its shipping-provider breach disclosure, Trezor said approximately 67,000 additional US customers were affected, including orders from 2019 to 2021. It said ShipMonk, the shipping company tasked with delivering the devices, gave it written assurances that it deleted the records. The company now lists 80,689 affected customers overall.
Trezor says its systems and devices were unaffected and that the contents of parcels weren't exposed. The leaked information included only contact and delivery details, so no funds were stolen or misappropriated.
And while the financial damage so far is zero, those contact details create a bigger problem for the customer that has outlasted the purchase and could continue well into the future.
The device they bought will continue protecting their money, but the information used to deliver it could help a stranger impersonate someone they trust.
The device and the person
The Bitcoin network records coins and who can spend them. Wallets hold the private keys that authorize spending: the secrets that let their owner instruct the network to transfer money.
Hardware wallets keep those secrets in a dedicated device. When you make a payment, it can approve the transaction without handing the private key to the computer running the accompanying software.
That separation means a problem with the computer doesn't automatically become a loss of money.
You also need a way to recover access if the device breaks or disappears, which is where wallet backups step in. The way they work depends mostly on the setup, but it's usually a sequence of words that can recreate the wallet on another device.
However, that recovery mechanism can also help a thief who obtains it, which is why Trezor's backup instructions advise against sharing the backup or keeping digital copies.
Any attacker who persuades the wallet owner to hand over that information bypasses all the device's protections. But convincing a person that a request for their backup is legitimate has always been the hardest part of this type of scam.
Even the tiniest bit of personal information can make that message much more convincing. An email addressed to you by name that refers to an order you recognize feels different from a generic warning sent to a million inboxes. Letters delivered to your home can easily look like official correspondence, even when their instructions are fraudulent.
Ledger's record of phishing campaigns includes physical letters directing recipients to scan a code or visit a website where they are asked for their recovery words. Those campaigns show how physical mail can carry the scam.
The phrase ‘wallet leak' can obscure what someone has actually obtained. Contact information can help a scammer approach an owner; the wallet's secrets can give them access to the money.
| Information | What it enables | Limits |
|---|---|---|
| Name and delivery address | Where an order was sent and a way to contact the recipient | Whether the recipient currently owns Bitcoin or how much |
| A public wallet address | Transactions and balances associated with that address | The real-world identity of its owner |
| A private key | Authority to spend the coins controlled by that key | A complete picture of the owner's other assets |
| A wallet backup | Restoration of wallet access | Extra passphrases or a setup requiring several backup shares can also govern access |
An order might have been a gift. The buyer might have stopped using the device or sold their coins. A shipping record is a clue to a past purchase, but it leaves plenty of uncertainty about what the buyer owns today.
An imperfect clue can still be enough to select a target for deception. The owner then has to assess messages from strangers who may know details that were guaranteed to remain private. The secret inside the hardware wallet and the information outside it are part of the same discussion of personal security, even though they require different protections.
Wallet orders outlive their delivery
Shipping information has a legitimate purpose, as someone has to put the right parcel on the right route, resolve a failed delivery, and handle a return. Given the size and scope of that logistical operation, companies selling devices internationally often rely on other businesses to do that for them.
Problems start when what should be temporary operational information becomes a permanent corporate asset. Keeping an old record costs very little, and deciding where every piece of information went can require work across departments and vendors.
The original reason for collecting it will most likely expire long before the system that stores it does.
Across businesses, information can persist in database replicas, support-system exports, and backups long after its removal from the application staff use every day. Establishing that a record is gone requires a process that accounts for the ways it was stored and shared.
The Federal Trade Commission's business guidance starts from a pretty straightforward principle: collect and retain sensitive information only for a legitimate business need, know where it goes, and dispose of it securely. Its guidance also addresses service providers, because outsourcing a task doesn't absolve the company of the need to understand how the information is handled.
A deletion clause that most contracts have is part of that process, and so is a vendor's assurance that the clause has been followed. But neither one is the same as direct evidence that every relevant system has applied the retention policy.
You can check the address on the parcel and confirm receipt of the device, but you can't inspect the fulfillment partner's databases several years later. The company choosing the partner needs to demand evidence, define retention periods, and test whether those terms are being honored.
That makes privacy a product responsibility as well as a user habit. Advising customers to be careful with their backup addresses doesn't resolve the fate of a record already entrusted to a retailer and its contractors.
Payment cards can be replaced with a new number and compromised passwords can be retired. But home addresses can remain valid long after the original purchase is forgotten, and a copied record can't be recalled from everyone who received it.
Even moving doesn't erase the association. Old addresses can still help someone match other records or impersonate a business the customer once dealt with. The ongoing cost is partly financial security and partly the effort of deciding which communications deserve attention.
Privacy has to survive the wallet purchase
There are ways to keep deliveries more private. Parcel lockers, neutral packaging, and separate contact details for online orders can make these scams much harder to pull off.
However, there's a limit to how much you can push each of these measures. Locker operators can require identification, payment providers can retain billing information, and having a hardware wallet sent in a blank box doesn't delete the retailer's records.
Buying through an unfamiliar or secondhand seller can introduce a different problem if the device's origin becomes harder to trust.
These protections work at different points in the purchase. Buyers need to know which protection they are paying for and which organizations will receive their details.
For manufacturers, the biggest improvement needs to happen before a breach notice. It means collecting less where possible, separating information that doesn't need to travel together, and establishing evidence that contractors dispose of records when their job is over.
Legitimate obligations don't automatically require keeping every old phone number and delivery address available throughout the commercial relationship.
Hardware wallets protect private keys by keeping them away from an ordinary computer. Protecting the person who buys one requires work throughout the business delivering it. Manufacturers choose the warehouse and negotiate the contract, so they can demand evidence that old records have been removed.
Those decisions help determine how much trust a customer must keep extending long after they open the box.
Source: CryptoSlate