Two Breaches, Two Different Fault Lines
Hardware wallets promise to be the safest way to hold crypto. Your private keys (the secret codes that prove you own your coins) stay on a small device instead of on an exchange, which makes remote theft much harder.
The customer database, it turns out, is a much softer target.
SafePal disclosed its breach on Sunday, affecting 39,798 customers.
A bug in SafePal's order-tracking plugin allowed some customers to view other people's records, including contact details, mailing addresses, and purchase data.
The data covered orders placed from March 2, 2025 through April 11, 2026, a window of over 13 months.
SafePal has fixed the flaw and reduced its order data retention period to 90 days.
Trezor's breach came through a different door. The company learned on August 10 that a breach at its shipping partner, ShipMonk, caused the problem.
Trezor's total leaked records numbered 13,689, with full details for 11,742 buyers, according to the company's notice; the leaked data included each customer's phone number, email address, name, and postal address, so one leak came from inside SafePal's own system, while the other left through an outside supplier. Both ended with the same result: 53,487 records in the hands of strangers.
If a hardware wallet breach has you thinking about safer ways to build wealth, grab the free Always Be Buying eBook.
Why Addresses Are Valuable to Criminals
The good news is that the most dangerous crypto data did not get out. SafePal said the breach did not expose seed phrases, private keys, bank details, or card numbers.
Seed phrases are the backup codes that can unlock a wallet, and private keys are what prove you own the coins. Without them, nobody can move your crypto.
The bad news is that the data that did leak matters more for crypto owners than for the average online shopper.
People who buy hardware wallets are self-custody holders, meaning they manage their own coins instead of leaving them on an exchange. Their home addresses tell criminals exactly where those coins might be.
That is not a hypothetical worry. In May, US prosecutors charged three Tennessee men over a string of robberies across California.
The alleged thefts totaled $6.5 million.
The men allegedly posed as delivery people to get into victims' homes. SafePal has already taken more than 30 fraudulent websites and phishing links connected to the stolen data.
It says legitimate notifications come only from [email protected], and anyone who gets an email from another address should treat it as an attack.
What This Means for Your Crypto
This is not the first time a hardware wallet maker has lost customer data, and the last one shows how long the damage can last.
Ledger's 2020 breach exposed the contact info of about 272,000 people, including their physical addresses, names, and telephone numbers. Even six years later, the company still warns about mailed phishing attempts, but hasn't confirmed a link to that incident. That is the kind of long, quiet problem a data breach can create.
Trezor is trying to get ahead of that problem.
It plans to offer an anonymous delivery option, launching in the European Union in September and in the US by the end of the year. That will help future buyers, but the 53,487 records already leaked are beyond reach of such a change.
For investors, the immediate financial damage was small. SafePal Token, the digital token tied to the company, traded near $0.23 on Sunday and barely moved.
But the breach is a reminder that crypto security is not just about the code on your device. It is also about the companies that know your name, your phone number, and your front door.
When even the safest crypto tools can leak your data, the free Always Be Buying eBook shows a steadier path.
