A Perfect Storm: Two Major Breaches in Four Days

The crypto community faced a double blow last week when Trezor and SafePal, two of the industry’s most trusted hardware wallet providers, disclosed data breaches within four days of each other. Combined, the incidents exposed personal information for at least 53,487 customers—a shocking reminder that hardware wallets protect your assets but not your privacy.

Trezor disclosed on August 10 that ShipMonk, one of its shipping providers, suffered a breach affecting 13,689 customers. SafePal followed with its own announcement on August 16, revealing that nearly 40,000 customers’ data was exposed through a third-party order-tracking plug-in.

What Was Actually Exposed

This is where understanding the breach becomes crucial for protecting yourself. Let’s be clear about what was and wasn’t compromised:

Exposed:

  • Full names
  • Email addresses
  • Phone numbers
  • Shipping addresses
  • Purchase order dates and amounts

NOT Exposed (critically important):

  • Private keys
  • Seed phrases
  • Wallet passwords
  • Cryptocurrency itself

Both companies have confirmed that the core security of the hardware wallets—the private key infrastructure—was never compromised. Your Bitcoin, Ethereum, or other crypto holdings remain exactly where you left them, still secured by your hardware wallet and only accessible with your private key.

The Real Danger: Targeted Attacks

While your cryptocurrency is safe, your personal safety may not be. Chainalysis, the blockchain analysis firm, has warned that leaked customer lists from hardware wallet breaches now fuel targeted physical and social engineering attacks against crypto holders.

Here’s the concern: attackers now know your name, address, phone number, and that you own crypto. They can use this information to:

  • Send convincing phishing emails posing as wallet support
  • Conduct SIM-swapping attacks on phone numbers
  • Target you with fraudulent “recovery services” or fake wallet updates
  • Potentially identify high-net-worth targets for physical threats

This is different from a typical database breach. Because these are hardware wallet customer lists, attackers are specifically targeting people they know hold cryptocurrency.

How It Happened: Third-Party Vulnerabilities

Both breaches originated not from the wallet hardware or software itself, but from external services:

Trezor’s Breach: ShipMonk, a logistics provider managing Trezor shipments, had its systems breached. The exposed data included names and addresses of everyone who received a Trezor shipment—a clear signal that they own hardware wallet hardware.

SafePal’s Breach: An order-tracking plug-in used on SafePal’s website had an authorization flaw. The vulnerability allowed unauthorized access to customer information during the order process. SafePal stated the issue resulted from “an issue with a third-party order-tracking plug-in.”

Both companies are pointing fingers at external vendors, which raises an uncomfortable truth: even hardware wallet makers can’t control every third party in their supply chain.

The Pattern: Why Wallet Companies Get Targeted

Hardware wallet breaches follow a predictable pattern because customer data itself is valuable to criminals. A leaked list of hardware wallet owners represents a pre-screened, high-probability target list of people who care about crypto security—and therefore likely hold significant crypto assets.

This is why the combination of the two breaches matters. Attackers can cross-reference the lists to identify people who bought from both Trezor and SafePal, or they can simply work through individual lists knowing that every person on it owns crypto.

What You Should Do Now

Immediate Actions:

  1. Enable 2FA on everything - Email, exchange accounts, and any crypto platforms
  2. Assume your address and email are public - Treat any wallet-related email with extreme skepticism
  3. Watch for phishing - Don’t click links in unsolicited emails claiming to be from Trezor, SafePal, or other wallet providers
  4. Consider a VPN - This hides your location from attackers who may try to correlate other data

Longer-term:

  1. Update support information - Change your recovery email and phone number on crypto exchanges
  2. Treat your shipping address as public knowledge - Use a PO box or alternate address for future hardware wallet purchases if possible
  3. Monitor credit reports - The exposed data could be used for identity theft
  4. Consider separate emails - Use distinct email addresses for different platforms so a breach doesn’t cascade

Bottom Line

The good news: your cryptocurrency is still secure in your hardware wallet. The bad news: you’ve been identified as a crypto holder, and that information is now in the hands of attackers who specifically target people like you. The hardware wallet itself remains one of the safest places for your keys, but this incident shows that buying a Trezor or SafePal now adds you to a list of known targets.

For the companies involved, this should be a watershed moment. Trezor and SafePal need to demonstrate that they’re taking third-party security as seriously as the security of their core products. For users, this is a reminder that hardware wallet security and personal privacy are two different things—one protects your assets, the other doesn’t.

Advertisement

Sources and review

This article was checked against the primary or authoritative sources below .

Frequently asked questions

Is my crypto actually stolen if my data was breached?

No. The breaches exposed personal information (names, addresses, emails) but NOT private keys, seed phrases, or wallet credentials. Your crypto itself is safe unless attackers gain access to your wallet through physical or phishing attacks using the exposed data.

What personal information was exposed?

Names, email addresses, phone numbers, shipping addresses, and purchase order details. Trezor and SafePal both confirmed that private keys, seed phrases, and wallet passwords were NOT compromised.

What should I do if I was affected?

Monitor your email and phone for phishing attempts. Be extra cautious of unsolicited messages claiming to be from wallet providers or offering security updates. Enable two-factor authentication on all crypto accounts and consider using a VPN. Do not click links in unsolicited emails.

How did this happen to hardware wallets, which are supposed to be secure?

Both breaches came from third-party software services, not the hardware wallets themselves. Trezor used a shipping provider (ShipMonk) whose systems were breached. SafePal used an order-tracking plug-in with an authorization flaw. The vulnerabilities were in customer-facing services, not wallet security.

Does this mean hardware wallets aren't safe?

No. Hardware wallets remain one of the most secure ways to store crypto because private keys never leave the device. These breaches exposed customer data, not wallet security. However, the incident highlights that using hardware wallets doesn't make you immune to targeted attacks by people who know you own crypto.

Advertisement

V

Vijay Rathod

Independent crypto and financial-markets analyst covering Bitcoin, altcoins, macroeconomics, and trading news. More about the author →