
A significant cyberattack at France's tax authority has exposed personal information of 678,437 taxpayers, creating new security concerns for cryptocurrency investors in the country. According to latest French reporting, the breach affected 678,437 people, including nearly 27,000 who reported income above €100,000 and 386 earning more than €1 million. The leaked records reportedly include names, birthdates, addresses, phone numbers and email addresses, along with tax-related details. The breach has been confirmed by France's Finance Ministry after hackers accessed systems at the General Directorate of Public Finances. As per AMBCrypto, security analyst Jameson Lopp from Casa Wallet revealed that over 28,000 victims earn more than €100,000 annually, with approximately 400 individuals having incomes exceeding €1 million. The breach has raised concerns about potential physical attacks on high-net-worth crypto investors, as France is already identified as a leading country for such violent crimes.
The French tax breach coincided with a series of three major hardware wallet and broker breaches that exposed 253,487 customers over just four days between August 13-16, 2026. SafePal lost 39,798 customer records to a plugin flaw, Trezor lost 13,689 customers through its shipping provider ShipMonk, and Bits of Gold lost approximately 200,000 users through an analytics tool. As reported by CoinDesk, all three breaches traced to the same vulnerability: CVE-2026-72898, a critical unauthenticated SQL injection in Metabase rated CVSS 10.0. The vulnerability allowed attackers to inject arbitrary SQL through undeclared fields in password reset requests, gaining administrator access and reading all connected databases. ShipMonk ran a self-hosted Metabase instance that was exploited before the patch was available, while Bits of Gold confirmed the same vulnerability in a third-party analytics platform used for customer support and data analysis.
The breach data has fueled a dramatic escalation in violent physical attacks targeting cryptocurrency holders. According to CertiK's H1 2026 wrench attack report, there were 52 verified incidents of physical violence used to extract cryptocurrency, representing a 33% increase over the 39 incidents in the first half of 2025. The financial exposure reached $124.1 million, more than 11 times the $10.5 million from the same period a year earlier. Home invasions linked to crypto theft rose from one case in the first half of 2025 to 20 cases in the first half of 2026, making it the most common verified attack type. France accounts for 33 of the 52 incidents, representing 63.5% of all documented cases globally, with the country recording 41 crypto-linked kidnappings in 2026, averaging roughly one every two and a half days. The stolen data - verified proof of crypto ownership paired with home addresses, phone numbers, and in some cases government identification numbers - provides exactly what attackers need for successful wrench attacks.
Industry leaders have expressed concern about the combined impact of recent security incidents, with Curve Founder Michael Egorov commenting that 'Paying taxes is now a threat?' following the breach. Trezor has announced the launch of Anonymous Delivery in the European Union by September 2026 and in the United States by year-end, allowing customers to receive devices without providing home addresses to shipping intermediaries. The company also plans to disconnect affected systems and implement stricter vendor security attestation requirements. SafePal has cut its data retention window to 90 days and identified and removed more than 30 phishing websites tied to the incident. However, the breaches highlight a structural vulnerability where hardware wallet companies market security based on device security while customers' home addresses and shipping data are exposed through third-party vendors. The industry treats address data as a logistics detail rather than security-critical information, despite the higher per-record risk compared to stolen credit card numbers.