Your Coins Are Safe.
Your Address Isn't.

In one week, two hardware wallet makers disclosed data breaches: Trezor's shipping partner leaked ~13,700 customer records, and SafePal exposed nearly 40,000 — with the stolen data reportedly up for sale. No coins were touched. But names, phone numbers and home addresses of confirmed crypto holders are now in criminal hands. Here's what happened, and exactly what to do about it.

⚡ Update — September 14, 2026: the predicted phishing wave arrived — in our own inbox. On September 9, four identical emails landed at our site's address, apparently from "Trezor Security": a Critical Security Alert about an "STM32 entropy vulnerability" producing 40-bit seeds, with a browser "entropy check tool" that asks you to enter your recovery phrase to "verify" it. Every technical detail was lifted from the real Coldcard incident described below — and pinned on Trezor, where it doesn't apply. It's a seed-harvesting phish, and a sophisticated one: the emails went out through a compromised third-party email provider Trezor actually uses, to Trezor's own newsletter database — Trezor confirmed the impersonation in a warning the next day. This is precisely the precision-phishing playbook this article warned about: real breach data plus a real news story, weaponized. The rule stands and will always stand: no wallet maker will ever ask you to type your seed phrase into a website — not to "check entropy," not to "validate your backup," not for anything. If you entered yours, move your funds to a freshly generated wallet now.
📆 Updated September 29, 2026 — three more data points for the same lesson. (1) D'CENT wallets drained: on September 28, attackers drained more than 12.4 million XRP from over 7,000 D'CENT wallets — the year's second-largest XRP theft — plus assets on other chains; maker IoTrust confirmed at least 110 reports of abnormal transfers. The cause has not been published yet, and that is the point: D'CENT is a hardware wallet with an app-heavy design, and until the post-mortem lands, treat any wallet whose seed touched an internet-connected companion app as suspect. We will update when IoTrust explains it. (2) The Bitget hack ($351.6M, September 25) was an exchange breach, not a wallet one — our summary — but it is the reason the exchange-vs-self-custody math below matters. (3) Wrench attacks are still the threat data leaks feed: in Taverny near Paris, a family was held at gunpoint, the wife and 10-year-old tied up and the husband tasered, by a gang trying to seize his crypto; six suspects were handed to prosecutors on September 11. Leaked shipping addresses are the target list. Meanwhile SEC Commissioner Hester Peirce called self-custody "a very fundamental American right" this week — good to hear; the practical side is below.
⚠️ The short version: if you bought a Trezor shipped to the US, UK, Sweden, Colombia, Brazil, Italy or Portugal between May 10 and August 8, 2026, or a SafePal device ordered between March 2, 2025 and April 11, 2026 — assume your name, address, phone and email are in criminal hands, and treat every unexpected message about your wallet as a phishing attempt. Your device and your coins are not affected by those two. Coldcard is the different story: if you generated a seed on any Coldcard between March 2021 and the July 31, 2026 patch, treat that wallet as compromised and migrate your funds now — attackers have already drained ~$116 million. And in every case: never enter your recovery seed anywhere online — no legitimate company will ever ask for it.

Two breaches in one week

On August 13, Trezor disclosed that ShipMonk — the fulfillment company that stores and ships its devices — had suffered unauthorized access to systems holding customer order data. According to breach notifications reviewed by BleepingComputer, the attackers got in by exploiting a vulnerability in Metabase, a third-party analytics platform ShipMonk uses. The damage: 11,742 customers with full exposure (name, email, phone number, shipping address) and 1,947 with partial exposure (name, city, email) — with Trezor now verifying whether that second group includes older orders than first thought. Affected orders shipped to the US, UK, Sweden, Colombia, Brazil, Italy and Portugal between May 10 and August 8, 2026. It is the first breach in Trezor's 13-year history to expose customer phone numbers and shipping addresses — and the exposure window stayed narrow only because Trezor requires partners to delete order data after 90 days.

Three days later, SafePal disclosed a bigger one: 39,798 customers exposed through an authorization flaw in an order-tracking plug-in on its own e-commerce site, which under certain conditions let one buyer view another buyer's order details. The affected window is long — orders from March 2, 2025 to April 11, 2026 — and the aftermath uglier: a threat actor claims to be selling the stolen data on a cybercrime forum, and SafePal has already taken down more than 30 phishing websites linked to the breach. A warning sign appeared back in May, when a customer reported a phishing email and a phone call impersonating SafePal staff, pushing a fake "firmware update" for a supposed security flaw. SafePal treated it as an isolated case at the time.

Trezor / ShipMonkSafePal
Customers affected~13,70039,798
Where it brokeShipping partner (via Metabase flaw)Own site's order-tracking plug-in
Data exposedName, email, phone, shipping addressName, email, phone, address, order details
Order windowMay 10 – Aug 8, 2026Mar 2, 2025 – Apr 11, 2026
Coins / keys affectedNoNo
Data for saleNot reportedClaimed by threat actor

And this isn't a two-company story. Ledger notified users of a third-party data breach earlier this year, and even Valve warned buyers of Steam hardware about a breach of customer records. Across industries, SentinelOne counts data breaches up 17% over 2025. The pattern is consistent: the weak link isn't the wallet — it's the web shops, plug-ins and shipping systems around it.

What criminals can actually do with this

Let's be precise, because both panic and complacency get people hurt. Nobody can steal your coins with your name and address. What they can do falls into two buckets.

The common risk: precision phishing. Generic crypto phishing is easy to spot. Phishing that opens with your real name, references the exact device you bought and roughly when, and arrives at the email you used for the order — that's a different animal. Expect fake "security incident" emails, fake firmware-update prompts (the exact lure already used against SafePal customers in May), fake support calls, even physical letters. Every one of them will eventually steer you toward the same goal: getting you to type your recovery seed somewhere. That is the whole game. No legitimate wallet company will ever ask for your seed — not by email, not by phone, not on a website, not in an app update.

The rare but serious risk: physical targeting. A home address tied to a confirmed hardware wallet purchase is precisely the data pattern behind what the industry grimly calls wrench attacks. Chainalysis counts more than $30 million stolen in violent, in-person attacks in the first half of 2026 — on pace to pass 2025's $58 million. After Ledger's 2020 breach exposed 272,000 customer records, affected users reported ransom emails, threatening texts, and calls from people who spoke as if they knew them. To be clear: with roughly 14,000 and 40,000 records in these leaks, the odds any individual customer is physically targeted remain very low. But it's the reason data minimization — the next section — is worth taking seriously.

The third story: Coldcard — when the coins weren't safe

Honesty requires covering the incident that breaks this article's headline — because in the Coldcard case, the coins were very much not safe. Starting July 30, attackers drained roughly 1,816 BTC — about $116 million — from more than 5,200 addresses in four waves, the third-largest crypto theft of 2026 and, in the words of more than one analyst, the worst single blow to bitcoin self-custody to date. One victim put it bluntly: he never shared his seed, his device never touched the internet, it sat in a safety deposit box — and 18.25 BTC left his addresses overnight.

How is that possible? A firmware integration error shipped in March 2021 quietly routed seed generation to a predictable software random-number generator instead of the device's dedicated hardware randomness chip — weakening key strength from 128 bits to, in the worst cases, roughly 40. That's brute-forceable. Attackers reconstructed candidate seeds entirely offline, matched them against the public blockchain, and waited. No phishing, no physical access, no user mistake: the flaw sat in open-source code for over five years before someone weaponized it — Coinkite's CEO has speculated AI-assisted code review may have found it.

Where it stands now (August 19): investigators traced the attacker to a paid account at a blockchain data service provider whose internal logs matched the theft pattern; the leads are with law enforcement, and Galaxy Research's Alex Thorn says the first-wave attacker's identity may already be known. About 1,082 BTC from the first wave still sits untouched in attacker addresses. Coinkite shipped emergency firmware on July 31, halted sales and destroyed affected inventory — but a firmware update cannot repair an existing seed. If you ever generated a seed on a Coldcard between March 2021 and the patch, the only fix is migrating funds to a fresh wallet with a newly generated seed.

The category difference matters. Trezor and SafePal leaked shopping data — your keys stayed mathematically sound. Coldcard's flaw broke the mathematics itself. The first is an opsec problem you can manage with the playbook below; the second is a trust-in-firmware problem, and it carries its own lesson: even air-gapped hardware is only as strong as the code that generated your keys. For meaningful holdings, that's the argument for keeping firmware current, reading vendor security advisories, and — at larger sizes — spreading funds across devices from different makers or using multisig, so no single vendor's mistake can empty everything.

The protection playbook

If you're (possibly) affected

Check through official channels only. Trezor emailed affected customers individually; SafePal emailed on August 16 and runs an online verification tool where you enter your order number and shipping country. Type the vendor's address into your browser yourself or use an old bookmark — don't click links in messages about the breach, which is exactly the moment phishers impersonate breach notifications.

Recalibrate your suspicion. From now on, treat every unexpected message that references your wallet — email, SMS, phone call, letter — as hostile until proven otherwise. Real companies won't call you. Real firmware updates happen inside the official app, never via emailed links. If a message creates urgency ("your funds are at risk, act now"), that urgency is the attack.

Never, under any circumstances, enter your recovery seed anywhere. Not on a website, not in an app that asks after an "update," not read out on a phone call. The seed belongs on your backup medium and nowhere else. If you have already entered it somewhere: treat the wallet as compromised, create a new wallet on a trusted device, and move your funds now.

Harden the accounts the leak touches. The exposed email is now a phishing target beyond crypto: enable two-factor authentication (an authenticator app, not SMS) on your email account, and consider a unique alias for anything crypto-related going forward.

For everyone buying hardware wallets

Break the address link. Ship to a parcel locker or PO box, not your home. This one habit removes the physical-risk tail of every future breach.

Or skip shipping entirely. Hardware wallets are increasingly sold by authorized physical retailers — Tangem is stocked at chains like Best Buy, Walmart and MediaMarkt, and Ledger and Trezor have authorized resellers in most regions. Buying in person, ideally paying cash, leaves no order record with your name and address attached. Just buy only from authorized channels, never second-hand: a used or tampered device is a far worse risk than any data leak.

Minimize what they can lose. A dedicated email alias for crypto purchases, a phone number only where legally required, and no more personal data than checkout demands. Vendors can't leak what they never had.

Watch for the industry's fixes. Trezor is launching an Anonymous Delivery option — locker pickup, neutral packaging, generic sender, automatic deletion of shipping identifiers — in the EU in September 2026 and in the US by year-end. Both Trezor and SafePal now cap order-data retention at 90 days, which is quietly becoming the industry standard this incident wave forced into existence.

Does this change the self-custody math?

No — and it's worth saying plainly, because "hardware wallet company breached" headlines can push people back toward keeping everything on exchanges. That would be learning the wrong lesson. These breaches exposed shopping data, not keys; meanwhile, exchange failures and account takeovers keep costing users actual funds. The honest takeaway is narrower: hardware wallets protect your coins brilliantly and your personal data not at all — so protect the data yourself, with the delivery and email habits above. Our hardware wallet hub compares the current devices side by side, and we'll be watching how Trezor's anonymous delivery and the industry's new retention standards hold up.

FAQ

Were any crypto funds stolen in the Trezor or SafePal breaches?
No. Both incidents exposed customer order data — names, email addresses, phone numbers and shipping addresses — held in shipping and order-tracking systems. Devices, seed phrases, private keys and wallet software were not compromised at either company, and neither breach gives attackers any direct way to access funds.
How do I know if I'm affected?
Trezor emailed all affected customers individually; the exposure covers orders shipped to the US, UK, Sweden, Colombia, Brazil, Italy and Portugal between May 10 and August 8, 2026. SafePal emailed affected customers on August 16 from its official security address and runs an online verification tool where you enter your order number and shipping country. If you're unsure, check those official channels directly — never a link from an unexpected message.
What can criminals actually do with my name and address?
Two things. First, targeted phishing: convincing fake emails, texts or calls referencing your real purchase — like the fake 'firmware update' emails already seen in the SafePal case. Second, in the worst case, physical targeting: a leaked address tied to a confirmed hardware wallet purchase is exactly the data pattern behind so-called wrench attacks, which stole over $30 million in the first half of 2026 according to Chainalysis. The phishing risk is common; the physical risk is rare but real, which is why minimizing your data trail matters.
Should I move my coins to a new wallet?
Not because of these breaches alone — your keys were never exposed. Move funds immediately only if you have ever entered your recovery seed into a website, app or form, or shared it with anyone claiming to be support. In that case, treat the wallet as compromised: create a new wallet on a trusted device and transfer funds to it.
What about the Coldcard hack — weren't coins actually stolen there?
Yes — and it's a different category of incident. A March 2021 firmware flaw made Coldcard-generated seeds predictable, letting attackers reconstruct private keys offline and drain roughly 1,816 BTC (~$116 million) from over 5,200 addresses starting July 30, 2026. No customer data leak was involved and no user did anything wrong. Coinkite patched the firmware on July 31, but updating cannot fix an existing seed: anyone who generated a seed on a Coldcard between March 2021 and the patch should migrate funds to a freshly generated wallet immediately. The Trezor and SafePal incidents, by contrast, exposed shopping data only — keys and coins were never at risk there.
Is it still safe to buy a hardware wallet online?
Yes — and self-custody remains safer than leaving significant funds on an exchange. But order smart: ship to a parcel locker or PO box rather than your home, use a dedicated email alias, and consider buying in person from an authorized retailer. Vendors are adapting too: Trezor is launching an Anonymous Delivery option in the EU in September 2026, and both companies now limit order-data retention to 90 days.

Transparency note: HomeCryptoInvest earns affiliate commissions from several hardware wallet makers, including Trezor and Ledger. That doesn't change how we cover their incidents — our readers' safety comes first, which is exactly why this article exists. Facts above are sourced from official Trezor, SafePal and Coinkite disclosures and reporting by BleepingComputer, Bloomberg, The Block, TRM Labs, Galaxy Research and Chainalysis, verified August 18–19, 2026. Crypto assets are volatile; nothing here is financial advice.

📚 Also Read
Comparison
Best Hardware Wallets 2026
Review
Crypto Scams: How to Spot Them
Review
MiCA: Which Exchanges Work in the EU
Review
3 Exchanges Shut Down in One Month
Guide
Crypto Exchange Fees 2026
Hardware Wallets
Trezor vs Ledger 2026
Ask Harvey 🦀
Harvey
The crypto crab 🦀 — your AI investing advisor
€500/month strategy Best exchange Crypto taxes EU Bitcoin DCA
Your guide