Trezor and SafePal Hardware Wallet Breaches 53,487 Customers’ Personal Data

Home » Trezor and SafePal Hardware Wallet Breaches 53,487 Customers’ Personal Data

TL;DR

The short version

30 sec read
  • 1Trezor and SafePal, which make two of the biggest hardware wallet makers, revealed of separate data breaches literally, days apart in August 2026 that exposed 53,487 customer records.
  • 2Trezor’s breach emanated from ShipMonk, which happens to be its shipping fulfillment partner , and was intruded by attackers who exploited an SQL injection flaw in Metabase; with about 13,689 customer names, emails, phone numbers, and shipping addresses being exposed.
  • 3SafePal’s breach originated from an authorization flaw that was accessed in its order-tracking plug-in, leading to exposure of personal data for 39,798 customers, some dating back over a year.
  • 4Both companies went on to affirm that wallets, seed phrases, private keys, and funds were not exposed; the intrusion was limited to identity and shipping data exclusively.
  • 5Chainalysis has classified leaked crypto-purchaser data to be on the rise under physical crimes, reporting 46 violent incidents attached to crypto holders in the first half of the year, that also covers home invasions and kidnappings.

Two Breaches, Four Days Apart

The key role of hardware wallets is to ensure crypto holdings remain safe from digital theft. These devices store private keys offline, unlinked from the internet, safe from malware and exchange vulnerabilities that come with hot wallets. That big promise was breached in both incidents.

Trezor revealed on August 13; that the breach didn’t interfere with Trezor’s own infrastructure, and that it came from ShipMonk, the 3rd -party Fulfillment Company that ships Trezor devices. Attackers attached to ShinyHunters extortion group initiated a critical SQL injection zero-day in Metabase, in order to access order records made between May 10 and August 8, 2026, in seven countries. Of those impacted, 11,742 customers had names, phone numbers, and full shipping addresses being exposed, while another 1,947 had names, cities, and emails compromised, with 13,689 records in total.

Then, on August 16, SafePal revealed of a breach they had encountered, mentioning the timing relative to Trezor’s announcement “an unfortunate coincidence.” However, this one was far more serious. The main reason was an authorization flaw in SafePal’s order-tracking plug-in, which was serious enough that one customer checking their own order at times could access another customer’s record. The intrusion window was from March 2, 2025 to April 11, 2026, affecting about 39,798 customers, with names, emails, phone numbers, shipping addresses, and purchase data exposed.

SafePal also revealed it received an initial report of the issue in early May 2026 but perceived it “as an isolated case,” only opening a full investigation back in July.

With these two disclosures, 53,487 customer records were exposed in under a week.

What Wasn’t Exposed

Both the companies affirmed that seed phrases, private keys, wallet passwords, and actual funds were never intruded. Trezor mentioned its systems and devices are 100% secure; SafePal went on and confirmed that bank details, card numbers, and government IDs weren’t touched in the breach.

Hardware wallets are designed in a way that shipping data lives completely separate from the keys controlling the assets. However, it minimizes the rea threat. A home address attached to a confirmed hardware wallet purchase may be of importance to a different kind of attacker: typically not one trying to get a password right, but one looking to find who owns certain crypto assets and where they reside.

The Physical Security Problem

This is what differentiates hardware wallet attacks from just another retail data leak. A user purchasing a hardware wallet usually indicates significant crypto holdings, as most typical holders barely bother. A leaked customer list is more of a targeting list for an attacker looking to rob or extort crypto holders particularly.

Chainalysis has followed this trend, and the numbers are staggering: 46 violent incidents attached to crypto holders within 6 months in 2026, with more than $30 million made away with via physical coercion as opposed to digital hacking. Home burglaries have become more widespread than kidnappings within this category, which is quite a big shift toward opportunistic property crime along with the extortion cases that attract headlines.

Ledger, a rival wallet maker, fell victim to a much bigger 2020 breach exposing about 272,000 records, including postal addresses. The occurrence included phishing waves, fraudulent letters mailed to customers’ homes, and the kidnapping of a company co-founder. And six years later now, Ledger customers are still receive phishing letters by post. Once a user’s home address is exposed, scam domains may be eliminated, inboxes will filtered, however addresses won’t expire.

What Both Companies Are Doing Now

Trezor has gone on to reveal an anonymous delivery option that splits a customer’s home address from their verified wallet purchase at the shipping level, reaching the EU in September 2026 and the US by year-end. It’s an important technique, moving forward but may be too late for records exposed previously.

SafePal has repaired the existing flaw and cut order-data retention to 90 days, restricting how much historical purchase data could be intruded in future. It’s also integrated a lookup tool allowing customers check, through order ID and shipping country, if their record was impacted.

Both companies are recommending the same precautions: approach any unexpected contact attached to a recent wallet order, with heavy suspicion, confirm only via official channels, and never share a seed phrase with anyone, including anyone alleging to be support staff. Legitimate companies would never ask for that phrase.

Why This Keeps Happening

Neither breach came with a flaw in the actual wallet hardware or its cryptographic security; both of these stem from third-party and supply-chain weaknesses. Trezor’s exposure emanated from a vendor’s outdated analytics software; SafePal’s from an authorization bug in an internal tool. This isn’t something new in the industry: Ledger’s 2020 incident and another in 2026 came from Global-e, a third-party commerce provider, as opposed to Ledger’s core systems.

At the end of the day, even with hardware wallet companies, providing on cryptographic security; they still run typical e-commerce operations, with shipping partners, order-tracking plug-ins, customer databases that come with vulnerabilities as any other provider. While the wallets themselves may be safe, the systems required to sell and ship are not 100% secure.

XRP Breach>>

Conclusion

The good news is that no funds were stolen in either breach. And both companies’ core security remained intact as designed. However, for the 53,487 users whose names and addresses were exposed, the concept that  “your crypto is safe” only makes part of this narrative, but a home address attached to a hardware wallet purchase is quite a big liability that can’t be repaired the way a password does.

In case you’ve purchased from either company within the revealed; windows, ensuring that your record was affected and keeping tabs to unsolicited contact will be crucial, despite of how secure your actual wallet remains.

This is a developing story. We’ll update this piece if either company releases further details on the scope of exposure or confirmed instances of misuse.

Maria Chen, Staff Writer at Crypto Mojo

Atlas Editorial

Writers, Researchers, and Editors

Atlas Editorial is a dedicated team of writers, researchers, and editors committed to delivering clear, insightful, and well-researched content. Our team brings together diverse perspectives to keep readers informed on the latest developments, trends, and ideas shaping the digital world.

Connect:

Leave a Reply

Your email address will not be published. Required fields are marked *