In one week, two hardware wallet makers disclosed data breaches: Trezor's shipping partner leaked ~13,700 customer records, and SafePal exposed nearly 40,000 — with the stolen data reportedly up for sale. No coins were touched. But names, phone numbers and home addresses of confirmed crypto holders are now in criminal hands. Here's what happened, and exactly what to do about it.
On August 13, Trezor disclosed that ShipMonk — the fulfillment company that stores and ships its devices — had suffered unauthorized access to systems holding customer order data. According to breach notifications reviewed by BleepingComputer, the attackers got in by exploiting a vulnerability in Metabase, a third-party analytics platform ShipMonk uses. The damage: 11,742 customers with full exposure (name, email, phone number, shipping address) and 1,947 with partial exposure (name, city, email) — with Trezor now verifying whether that second group includes older orders than first thought. Affected orders shipped to the US, UK, Sweden, Colombia, Brazil, Italy and Portugal between May 10 and August 8, 2026. It is the first breach in Trezor's 13-year history to expose customer phone numbers and shipping addresses — and the exposure window stayed narrow only because Trezor requires partners to delete order data after 90 days.
Three days later, SafePal disclosed a bigger one: 39,798 customers exposed through an authorization flaw in an order-tracking plug-in on its own e-commerce site, which under certain conditions let one buyer view another buyer's order details. The affected window is long — orders from March 2, 2025 to April 11, 2026 — and the aftermath uglier: a threat actor claims to be selling the stolen data on a cybercrime forum, and SafePal has already taken down more than 30 phishing websites linked to the breach. A warning sign appeared back in May, when a customer reported a phishing email and a phone call impersonating SafePal staff, pushing a fake "firmware update" for a supposed security flaw. SafePal treated it as an isolated case at the time.
| Trezor / ShipMonk | SafePal | |
|---|---|---|
| Customers affected | ~13,700 | 39,798 |
| Where it broke | Shipping partner (via Metabase flaw) | Own site's order-tracking plug-in |
| Data exposed | Name, email, phone, shipping address | Name, email, phone, address, order details |
| Order window | May 10 – Aug 8, 2026 | Mar 2, 2025 – Apr 11, 2026 |
| Coins / keys affected | No | No |
| Data for sale | Not reported | Claimed by threat actor |
And this isn't a two-company story. Ledger notified users of a third-party data breach earlier this year, and even Valve warned buyers of Steam hardware about a breach of customer records. Across industries, SentinelOne counts data breaches up 17% over 2025. The pattern is consistent: the weak link isn't the wallet — it's the web shops, plug-ins and shipping systems around it.
Let's be precise, because both panic and complacency get people hurt. Nobody can steal your coins with your name and address. What they can do falls into two buckets.
The common risk: precision phishing. Generic crypto phishing is easy to spot. Phishing that opens with your real name, references the exact device you bought and roughly when, and arrives at the email you used for the order — that's a different animal. Expect fake "security incident" emails, fake firmware-update prompts (the exact lure already used against SafePal customers in May), fake support calls, even physical letters. Every one of them will eventually steer you toward the same goal: getting you to type your recovery seed somewhere. That is the whole game. No legitimate wallet company will ever ask for your seed — not by email, not by phone, not on a website, not in an app update.
The rare but serious risk: physical targeting. A home address tied to a confirmed hardware wallet purchase is precisely the data pattern behind what the industry grimly calls wrench attacks. Chainalysis counts more than $30 million stolen in violent, in-person attacks in the first half of 2026 — on pace to pass 2025's $58 million. After Ledger's 2020 breach exposed 272,000 customer records, affected users reported ransom emails, threatening texts, and calls from people who spoke as if they knew them. To be clear: with roughly 14,000 and 40,000 records in these leaks, the odds any individual customer is physically targeted remain very low. But it's the reason data minimization — the next section — is worth taking seriously.
Honesty requires covering the incident that breaks this article's headline — because in the Coldcard case, the coins were very much not safe. Starting July 30, attackers drained roughly 1,816 BTC — about $116 million — from more than 5,200 addresses in four waves, the third-largest crypto theft of 2026 and, in the words of more than one analyst, the worst single blow to bitcoin self-custody to date. One victim put it bluntly: he never shared his seed, his device never touched the internet, it sat in a safety deposit box — and 18.25 BTC left his addresses overnight.
How is that possible? A firmware integration error shipped in March 2021 quietly routed seed generation to a predictable software random-number generator instead of the device's dedicated hardware randomness chip — weakening key strength from 128 bits to, in the worst cases, roughly 40. That's brute-forceable. Attackers reconstructed candidate seeds entirely offline, matched them against the public blockchain, and waited. No phishing, no physical access, no user mistake: the flaw sat in open-source code for over five years before someone weaponized it — Coinkite's CEO has speculated AI-assisted code review may have found it.
Where it stands now (August 19): investigators traced the attacker to a paid account at a blockchain data service provider whose internal logs matched the theft pattern; the leads are with law enforcement, and Galaxy Research's Alex Thorn says the first-wave attacker's identity may already be known. About 1,082 BTC from the first wave still sits untouched in attacker addresses. Coinkite shipped emergency firmware on July 31, halted sales and destroyed affected inventory — but a firmware update cannot repair an existing seed. If you ever generated a seed on a Coldcard between March 2021 and the patch, the only fix is migrating funds to a fresh wallet with a newly generated seed.
The category difference matters. Trezor and SafePal leaked shopping data — your keys stayed mathematically sound. Coldcard's flaw broke the mathematics itself. The first is an opsec problem you can manage with the playbook below; the second is a trust-in-firmware problem, and it carries its own lesson: even air-gapped hardware is only as strong as the code that generated your keys. For meaningful holdings, that's the argument for keeping firmware current, reading vendor security advisories, and — at larger sizes — spreading funds across devices from different makers or using multisig, so no single vendor's mistake can empty everything.
Check through official channels only. Trezor emailed affected customers individually; SafePal emailed on August 16 and runs an online verification tool where you enter your order number and shipping country. Type the vendor's address into your browser yourself or use an old bookmark — don't click links in messages about the breach, which is exactly the moment phishers impersonate breach notifications.
Recalibrate your suspicion. From now on, treat every unexpected message that references your wallet — email, SMS, phone call, letter — as hostile until proven otherwise. Real companies won't call you. Real firmware updates happen inside the official app, never via emailed links. If a message creates urgency ("your funds are at risk, act now"), that urgency is the attack.
Never, under any circumstances, enter your recovery seed anywhere. Not on a website, not in an app that asks after an "update," not read out on a phone call. The seed belongs on your backup medium and nowhere else. If you have already entered it somewhere: treat the wallet as compromised, create a new wallet on a trusted device, and move your funds now.
Harden the accounts the leak touches. The exposed email is now a phishing target beyond crypto: enable two-factor authentication (an authenticator app, not SMS) on your email account, and consider a unique alias for anything crypto-related going forward.
Break the address link. Ship to a parcel locker or PO box, not your home. This one habit removes the physical-risk tail of every future breach.
Or skip shipping entirely. Hardware wallets are increasingly sold by authorized physical retailers — Tangem is stocked at chains like Best Buy, Walmart and MediaMarkt, and Ledger and Trezor have authorized resellers in most regions. Buying in person, ideally paying cash, leaves no order record with your name and address attached. Just buy only from authorized channels, never second-hand: a used or tampered device is a far worse risk than any data leak.
Minimize what they can lose. A dedicated email alias for crypto purchases, a phone number only where legally required, and no more personal data than checkout demands. Vendors can't leak what they never had.
Watch for the industry's fixes. Trezor is launching an Anonymous Delivery option — locker pickup, neutral packaging, generic sender, automatic deletion of shipping identifiers — in the EU in September 2026 and in the US by year-end. Both Trezor and SafePal now cap order-data retention at 90 days, which is quietly becoming the industry standard this incident wave forced into existence.
No — and it's worth saying plainly, because "hardware wallet company breached" headlines can push people back toward keeping everything on exchanges. That would be learning the wrong lesson. These breaches exposed shopping data, not keys; meanwhile, exchange failures and account takeovers keep costing users actual funds. The honest takeaway is narrower: hardware wallets protect your coins brilliantly and your personal data not at all — so protect the data yourself, with the delivery and email habits above. Our hardware wallet hub compares the current devices side by side, and we'll be watching how Trezor's anonymous delivery and the industry's new retention standards hold up.
Transparency note: HomeCryptoInvest earns affiliate commissions from several hardware wallet makers, including Trezor and Ledger. That doesn't change how we cover their incidents — our readers' safety comes first, which is exactly why this article exists. Facts above are sourced from official Trezor, SafePal and Coinkite disclosures and reporting by BleepingComputer, Bloomberg, The Block, TRM Labs, Galaxy Research and Chainalysis, verified August 18–19, 2026. Crypto assets are volatile; nothing here is financial advice.