The Device Layer

Security & Signing Edition 5 3 min read by illithics

The Wallet Was Secure. The Customer Wasn't.

Privacy is not the same thing as security — and crypto companies need to stop treating customer data like ordinary retail exhaust.

The argument in one sentence A privacy-first company does not ask "can we protect this data?" — it asks "why do we have this data at all?"
A street of storefronts at dusk labeled Data Brokers, Ad Trackers, Lead Scrapers, Phishing Kits, SIM Swap, Identity Lookup, and Doxx Services — a Hardware Wallets / Self-Custody sign hangs further down.

For a security company, the amount of customer data floating around the internet should be terrifying. In crypto, even ordinary retail metadata can become attack infrastructure. A tracking pixel, checkout record, support ticket, or shipping address may not contain a private key, but it can help connect a real person to assets that cannot be reversed, recovered, or insured away.

The first layer of defense in this story is to not capture unnecessary data in the first place. Data breaches are common, becoming more so, and inevitably going to be even more of a problem as more powerful AI tools reach more hands. So what happens when a company has to purge its customer list, minimize email scraping, turn off user tracking on apps? Do sales automatically plunge?

I think a more important question we face now is how can we justify not doing those things and proclaim to be a security business. We've seen time and again the largest hardware wallet manufacturer Ledger have its customer rolls leaked over the past several years. Is Ledger special? No. Other companies have had the same issue across crypto and many other industries and public entities alike.

"Ledger's device security was not the issue; the privacy failure was in the commerce layer, where order data tied real people to confirmed hardware-wallet ownership."

At least with the Ledger leaks, users are aware there are security threats that they are taking steps with self-custody to avoid. When custodial platforms' data is breached, an entire new box is open. One can debate the response to the Coinbase customer data breach, May 2025, but the reality was customers had one less tool available to them: a hardware device. I don't typically delve into custodial or software based problems and solutions for crypto — this is The Device Layer — but needless to say, regardless of how well high-value customers were handled behind the scenes, regular users still had to live with the exposure or the uncertainty around it.

"Coinbase expected a $180 million to $400 million hit after hackers bribed support staff outside the U.S. and stole account data from a small subset of customers."

A company focused on security needs to consider its privacy policies. Don't just encrypt your database, minimize it. Collect only what information is necessary, retain only what is crucial. This philosophy can be taken to the development level too. Find alternatives to tracking user behavior in-app. They may be harder to research, but frankly it can be pretty clear when developers don't use their own app. It doesn't take wizardry, it takes work.

In crypto, customer data isn't just residual and harmless. It is a map. It can show who bought a device, where they are and how they can be contacted. A company cannot be expected to operate with zero data — devices have to ship. Support teams need to answer real questions. But privacy first means every piece of data has to justify its own existence and an exit plan for that data needs to be in order. Breaches aren't just embarrassing, they are counter to the whole movement.

The wallet can be secure while the customer is exposed. A privacy-first company understands that difference before the breach, not after it.

Trust Ledger claims · sources · uncertainty

Claims checked

  • Ledger's customer databases have leaked repeatedly, beginning with the 2020 e-commerce database breach that exposed customer names, addresses, and phone numbers.
  • Coinbase's May 2025 breach: overseas support agents were bribed to exfiltrate customer account data; Coinbase estimated a $180–400 million remediation cost in its SEC disclosure.

Primary sources

Commercial interests

  • The essay criticizes the data practices of two competitors (Ledger, Coinbase) of the author's employer. The events described are independently documented.

What is confirmed / what remains uncertain

  • Confirmed: both breaches and the quoted cost range are on the public record.
  • Uncertain: the full scope of downstream harm to affected customers, which by nature resists measurement.
Published: 2026-06-28 (provisional) Last reviewed: 2026-08-05 Corrections: none