
A hardware wallet data breach hit Trezor and SafePal, exposing 53,487 users' personal data. Seed phrases and funds stayed safe. Here's how to protect yourself.
Author: Kritika Gupta
In the span of three days, two of the world’s most popular hardware wallet companies disclosed data breaches affecting a combined 53,487 customers. The hardware wallet data breach incidents involved both Trezor and SafePal. Trezor revealed on August 13 that its shipping partner ShipMonk was hacked, exposing 13,689 customers’ names, home addresses, and phone numbers. Three days later, SafePal disclosed that a vulnerability in its order-tracking system exposed similar data for 39,798 customers.
However, the most important detail is what attackers did not access. In both cases, no funds were stolen. No seed phrases leaked. No private keys were compromised. The wallets themselves remain secure. The problem sits around the wallet, specifically in the shipping, order-processing, and customer-data systems that connect real identities to hardware wallet purchases.
That distinction matters for crypto users. Hardware wallets exist to reduce reliance on third parties, yet customers still depend on fulfillment providers, e-commerce systems, and support infrastructure when they buy and receive those devices. When those systems fail, attackers may not gain direct access to crypto, but they can obtain enough personal information to launch targeted phishing, impersonation, SIM-swap attempts, or even physical threats.
Trezor vs SafePal data breach comparison
Trezor’s latest data breach did not start inside its wallets or core infrastructure. Instead, it came through ShipMonk, one of the company’s third-party fulfillment partners. ShipMonk notified Trezor on August 10 that attackers had gained unauthorized access to systems containing customer order data. Trezor then publicly disclosed the breach on August 13. The incident affected customers in seven countries who received orders between May 10 and August 8, 2026.

The exposure affected 13,689 customers in total. Of those, 11,742 had their names, email addresses, phone numbers, and shipping addresses exposed. Another 1,947 customers faced partial exposure involving their names, cities, and email addresses. Crucially, attackers did not access Trezor devices, seed phrases, private keys, or wallet backups.
However, one existing policy significantly limited the scale of the breach. Trezor requires its fulfillment partners to delete customer information after 90 days. As a result, ShipMonk had already removed older order records before the attack occurred. That meant the breach exposed roughly 14,000 recent customers instead of potentially reaching Trezor’s entire historical buyer base. The incident also shows the limits of compliance certifications. ShipMonk holds SOC 2 Type II certification, an audited security standard, yet attackers still breached its systems.
In response, Trezor accelerated plans for an Anonymous Delivery option designed to reduce how much identity data becomes attached to a hardware wallet purchase. The planned system includes locker pickup, neutral packaging, generic sender information, and faster deletion of shipping identifiers. Trezor expects to launch the feature in the EU by September 2026 and in the United States by year-end.
More importantly, the ShipMonk incident adds to a broader pattern around Trezor’s customer data. It follows the January support portal exposure and a June eBay/Amazon data scrape, making this the company’s third data exposure in 2026 alone. The recurring weakness is not Trezor’s wallet cryptography. It is the growing number of external systems, marketplaces, support tools, and fulfillment providers that collect information linking a person’s real identity to their crypto hardware.
SafePal disclosed the breach on August 16, 2026, affecting 39,798 customers who placed orders between March 2, 2025, and April 11, 2026. This hardware wallet data breach covered a 13-month window, making the exposure significantly broader than Trezor’s recent ShipMonk breach. The compromised data included names, email addresses, shipping addresses, phone numbers, and purchase details. However, SafePal said attackers did not access seed phrases, private keys, wallet passwords, bank information, payment card numbers, or government-issued IDs.

The cause matters because this was not another third-party vendor breach. SafePal traced the incident to an authorization flaw known as an Insecure Direct Object Reference, or IDOR, inside its own order-tracking plug-in. Under certain conditions, a user could change an order number in the URL and view another customer’s order information. In other words, the application failed to properly verify whether the person requesting the data actually had permission to see it.
The warning signs also appeared before SafePal fully identified the vulnerability. Customers had reported phishing attempts consistent with leaked order data as early as July. SafePal later patched the affected plug-in, notified users, removed more than 30 fraudulent websites and phishing links, and brought in a third party to review its security. The company also launched a verification tool that lets customers check their exposure using their order number and shipping country.
For context, SafePal is backed by Binance and was originally incubated and invested in by Binance Labs, now YZi Labs. That makes the nature of the failure harder to dismiss as an obscure vendor problem. Unlike Trezor, where attackers compromised a fulfillment partner, SafePal exposed customer data through software running inside its own order-tracking stack.
That distinction is the key takeaway. An IDOR is a basic web authorization flaw, not an exotic exploit. Applications that handle sensitive customer information should prevent one user from accessing another user’s records simply by modifying a URL parameter. SafePal’s wallets and private keys remained secure, but the breach shows how weak application-layer security can still expose the identities behind self-custody.
Hardware wallet data breach timeline
For users worried that these breaches exposed their crypto, the most important point is simple: neither hardware wallet data breach compromised the wallets themselves. In fact, seed phrases, recovery phrases, private keys, wallet balances, passwords, PINs, bank account information, payment card numbers, and government-issued IDs all remained safe.
However, attackers did access the personal information surrounding the purchase. In both breaches, they obtained full names, email addresses, phone numbers, and home shipping addresses. In addition, SafePal’s incident exposed purchase details.
So, while your crypto is not at risk from these breaches, your identity is. More importantly, identity leaks in crypto can create a different kind of attack surface. Once scammers know who owns a hardware wallet and where that person lives, they can use that information for targeted phishing, impersonation, SIM-swap attempts, and other social-engineering attacks aimed at getting the victim to surrender access voluntarily.
The biggest risk from a hardware wallet data breach is not that someone can remotely drain a Trezor or SafePal wallet. Instead, the real threat is social engineering. Once an attacker knows your name, email address, home address, phone number, and the fact that you own a specific hardware wallet, they can build scams that look far more legitimate than generic phishing. For example, a fake message could say: “Dear [Name], your Trezor order [#XXX] shipped to [Your Address] requires a firmware update. Enter your recovery phrase to verify.” As a result, real personal details make the lie harder to spot.
In addition, the same data can support SIM-swap attempts and impersonation scams. With a victim’s name and phone number, attackers can try to hijack their mobile number and bypass SMS-based two-factor authentication on exchanges or other accounts. Meanwhile, a fake caller claiming to be from “Trezor support” or the “SafePal security team” sounds much more convincing when they already know the victim’s order details.
Beyond digital attacks, there is also the physical risk. A leaked home address becomes more serious when it is tied to a hardware wallet purchase because attackers may assume the buyer holds a meaningful amount of crypto. After the Ledger 2020 breach, victims reported receiving threatening letters at their homes. Moreover, attackers used supply-chain phishing. In some cases, they mailed fake Ledger devices with modified firmware designed to trick users into revealing their seed phrases.
Ultimately, that is the core danger of these leaks. The attacker does not need your private keys. They need you to give them your private keys. Personal data is the ammunition for that attack.
Zoom out from Trezor and SafePal, and the same weakness keeps appearing. In fact, each hardware wallet data breach reinforces the same problem: hardware wallet companies build devices specifically to isolate private keys from online threats, yet the businesses surrounding those devices still collect names, addresses, phone numbers, payment information, support records, and shipping data. As a result, attackers repeatedly target these conventional systems instead of trying to break the wallet’s cryptography.
More importantly, the pattern matters more than any single breach. Ledger’s 2020 incident showed how leaked customer data could fuel years of targeted attacks. Since then, Trezor has suffered exposure through a support portal, reseller platforms, and a fulfillment provider. Meanwhile, Ledger’s payment processor became another entry point in 2026, while SafePal exposed data through its own order-tracking software. Coldcard sits in a different category because attackers exploited a firmware flaw and stole funds directly. Nevertheless, its timing adds to broader security concerns surrounding hardware wallet vendors.
Ultimately, the analytical takeaway is uncomfortable but clear. The device is usually not the weak point. The logistics, support, payment, reseller, and e-commerce infrastructure around it is. Hardware wallet security can remain strong while vendor operations repeatedly expose the people using that hardware. In other words, crypto users buy these devices to remove third-party custody risk, yet they still depend on a chain of conventional companies and web applications to purchase, receive, and support them. That operational layer, therefore, has become the recurring failure point.
Major hardware wallet security and data incidents
August 2026 has been brutal for hardware wallet trust. In just three weeks, Coldcard suffered a firmware exploit that led to more than $89 million in stolen funds, Trezor disclosed a data breach affecting 13,689 customers, and SafePal revealed another breach involving 39,798 users. Combined with Ledger’s longer history of customer-data incidents, the latest hardware wallet data breach cases have created a broader credibility problem for the sector. As a result, users are no longer evaluating only whether the hardware can protect private keys. They also have to ask whether the company selling that hardware can protect their identity.
Consequently, that erosion of trust could change how some investors think about custody itself. For users who bought hardware wallets specifically to eliminate counterparty risk, that would represent a major reversal. After all, if securing crypto requires accepting repeated exposure through shipping providers, payment processors, support systems, and online stores, institutional custody can start to look simpler.
However, the counter-argument matters. The Trezor and SafePal incidents did not compromise the wallets themselves. No private keys or seed phrases leaked, and attackers did not drain funds from either device. In both cases, their core security model still worked. Self-custody works. Buying self-custody hardware through traditional e-commerce channels is what keeps failing. Therefore, the distinction matters because the current crisis says more about vendor operations and conventional web infrastructure than it does about the security of hardware wallet cryptography.
Meanwhile, Trezor’s planned Anonymous Delivery option could represent the first structural attempt to address that gap. Locker pickup, neutral packaging, reduced identity linkage, and faster deletion of shipping information attack the problem at its source by limiting how much sensitive customer data exists in the first place. Ultimately, the trust erosion is real, but so is the fact that the devices still work. Both things can be true at once: hardware wallets remain effective at protecting private keys, while the companies and systems surrounding them repeatedly struggle to protect the people who own those keys.
The first rule is absolute: never enter your seed phrase on any website or share it with anyone. No legitimate hardware wallet company will ever ask for it. Likewise, treat urgency as a red flag. Messages that demand immediate action, warn that your wallet is at risk, or pressure you to “verify” your recovery phrase should be treated as suspicious by default.
Always verify information through official channels. Type trezor.io or safepal.com directly into your browser instead of clicking links in emails or messages. For future purchases, use a separate email address that is not tied to your real name or primary accounts. Pay in crypto where possible to reduce the amount of payment processor data attached to the transaction, and use a PO box, parcel locker, or another non-home delivery address so your residential address never enters vendor systems.
You should also enable two-factor authentication across exchanges, email accounts, and other crypto-related services. Prefer app-based 2FA over SMS because attackers can target phone numbers through SIM swaps. If you received a breach notification from Trezor or SafePal, do not click links in any follow-up emails. Instead, visit the official website directly and remain especially alert for targeted phishing attempts over the next 6 to 12 months.
The irony of hardware wallets is simple: the device is often the most secure part of the system. The box it shipped in, and the databases that recorded that shipment, can be the weakest. Protecting your private keys still matters, but protecting the identity connected to those keys has become part of self-custody too.
Hardware Wallet Data Breach Hits Trezor and SafePal
GHO Beyond Borrowing: How Aave Is Scaling Revenue, Cross-Chain Yield, and Retail Distribution
Top Gold-Backed Crypto Projects Ranked: XAUT vs PAXG & More
THE LIST: 72 Crypto Research, Analytics, Trading, and Onchain Investigation Tools Worth Using
Hardware Wallet Data Breach Hits Trezor and SafePal
GHO Beyond Borrowing: How Aave Is Scaling Revenue, Cross-Chain Yield, and Retail Distribution
Top Gold-Backed Crypto Projects Ranked: XAUT vs PAXG & More
THE LIST: 72 Crypto Research, Analytics, Trading, and Onchain Investigation Tools Worth Using