> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Argentine Hardware Wallet Retailer Allegedly Exposed, Linking Named Buyers to Home Addresses and ID Numbers
- URL: https://darkwebinformer.com/argentine-hardware-wallet-retailer-allegedly-exposed-linking-named-buyers-to-home-addresses-and-id-numbers/
- Published: 2026-08-19T16:01:25.000Z
- Updated: 2026-08-19T16:01:25.000Z
- Author: Dark Web Informer
- Tags: Data Breaches

Breach Report ![Argentina flag](https://flagcdn.com/w40/ar.png)Argentina E-commerce / Crypto Hardware Selling 

## Argentine Hardware Wallet Retailer Allegedly Exposed, Linking Named Buyers to Home Addresses and ID Numbers

A forum user posting as **kingloki** is offering what they describe as a complete order export from **coincustody.io**, an Argentine reseller of Trezor and Ledger hardware wallets, covering **212 orders placed between May 2025 and August 2026**. The record count is small, but the composition is unusually dangerous: the seller claims **107 customer emails, 70 DNI and CUIT identity numbers, 47 full street addresses with apartment numbers, and 34 phone numbers**, each tied to a named buyer and the specific device they purchased. Also claimed are **payment identifiers, browser IP addresses and live parcel tracking links**. Buyers are said to include corporate and foreign customers. The claim is **unverified**.

Severity HIGH 

Customers107

ID numbers70

Orders212

Actorkingloki

### ▣Post details

Targetcoincustody.io

Country![Argentina flag](https://flagcdn.com/w40/ar.png)Argentina

SectorCrypto hardware retail

ListingSelling, direct contact

Volume278 records, 3 API pulls

Root causeClaimed open read access

ObservedAug 18, 2026

Actorkingloki

### !Allegedly included

- Customer full names
- DNI and CUIT numbers
- Home street addresses
- Apartment and postal codes
- Phone numbers
- Email addresses
- Payment transaction IDs
- Browser IP addresses
- Live parcel tracking links
- Exact device models bought
- Order values and dates
- Payment method used
- Courier and delivery data
- Corporate and foreign buyers

### ◱Screenshots

[ ![coincustody.io Argentina hardware wallet buyer database sale forum post screenshot, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/928735697236597862539782635987235987231.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/928735697236597862539782635987235987231.png) [ ![Claimed affected entities and record structure in the coincustody listing](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/928735697236597862539782635987235987232.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/928735697236597862539782635987235987232.png) 

### ⚠Potential impact

The record count badly understates this one. What the set reportedly establishes is that **a named person at a specific home address, with a verified national ID and a working phone number, took delivery of a device whose only purpose is storing cryptocurrency**. That is a targeting list before it is a privacy incident, and the risk is physical as much as digital: coercive home robbery against known holders is a recurring pattern in the region. The digital exposure is severe on its own, since knowing the **exact wallet model and purchase date makes a fraudulent firmware or security notice highly credible**, and the goal of such messages is the recovery phrase, which surrenders the funds outright. The DNI and phone pairing additionally supports **identity fraud and SIM swapping**. Live courier tracking links raise the further prospect of interception while orders are still in transit.

### iStatus

Unverified 

The post describes **read access to an order interface rather than an intrusion**, and the export is consistent with a standard storefront order pull, which points to an exposed token or misconfigured endpoint. The claim is unusually checkable given its size, and the individuals named in the samples could confirm their own records, though **that is a burden falling on them rather than on the retailer**. The seller notes buyers in the European Union and Uruguay, which would engage obligations beyond Argentina's data protection law. Dark Web Informer is **not reproducing the sample records, which contain complete identities, nor the contact route**. The same account is separately advertising paid intrusion services. The claim is **unverified** and the retailer has not publicly addressed it.

Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) 

[DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE