A cluster of data breaches has swept across the cryptocurrency hardware wallet industry over the past several days, exposing personal information belonging to tens of thousands of customers a
A cluster of data breaches has swept across the cryptocurrency hardware wallet industry over the past several days, exposing personal information belonging to tens of thousands of customers at SafePal and Trezor — two of the most widely used hardware wallet manufacturers — while a separate incident at Israeli crypto broker Bits of Gold has potentially compromised data for another 200,000 users.
None of the breaches exposed seed phrases, private keys, or funds directly, but security researchers warn the leaked personal information creates serious downstream risks for crypto holders, from targeted phishing to physical “wrench attacks.”
SafePal: Nearly 40,000 Customers Affected
SafePal disclosed on August 16 that it had identified an authorization flaw in the order-tracking function of a plug-in connected to its customer order system. Under specific conditions, the flaw allowed unauthorized third parties to access order information belonging to other customers. The company said it remediated the vulnerability upon discovery and implemented additional security measures.
According to SafePal’s disclosure, the exposed data affects customers who placed orders between March 2, 2025, and April 11, 2026, and includes names, email addresses, shipping addresses, phone numbers, and purchase details. In total, SafePal confirmed the incident affects approximately 39,798 customers. All affected users were individually notified by email from [email protected] on August 16, with the subject line “[Important] Your SafePal Order Information Has Been Affected.”
SafePal was explicit that seed phrases, private keys, and wallet passwords were not exposed in the breach, meaning affected users do not need to move their assets solely because of this incident. However, the company warned that anyone who separately entered or shared their seed phrase or private key in response to a suspicious message should treat that wallet as compromised, create a new wallet using a trusted SafePal device or official app, and transfer remaining assets immediately.
SafePal’s core security guidance for affected users is straightforward: never share a seed phrase, private key, or password with anyone — including someone claiming to represent SafePal support, since the company says it will never request this information by phone, email, or any other channel.
Users should avoid clicking links or scanning QR codes in unsolicited messages, manually type SafePal’s web address rather than following links (the company noted it has previously taken down phishing sites that replaced the letter “l” in its domain with a capital “I”), and report any suspicious contact through SafePal’s official channels rather than social media.
Trezor: Breach Traced to Shipping Partner ShipMonk
Just three days before SafePal’s disclosure, Trezor announced its own data exposure incident on August 13, though the root cause differed meaningfully. According to Trezor’s official blog post, the breach originated not from Trezor’s own systems but from ShipMonk, one of the company’s third-party shipping and fulfillment providers, which experienced a data breach exposing customer order information.
Trezor stated plainly that its hardware devices remain secure and were not compromised in any way. The exposed data includes full names, shipping addresses, phone numbers, and email addresses tied to orders shipped between May 10 and August 8, 2026, specifically affecting customers in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal.
Trezor provided a precise breakdown of the incident’s scope: ”
The incident affects 11,742 customers with full exposure (name, email, phone number, shipping address) and 1,947 customers with partial exposure (name, city, email).”
The company attributed the relatively contained scale of the breach to its strict 90-day data storage policy — a retention limit it says it successfully negotiated with fulfillment partners as well, meaning older order data had already been deleted before the breach occurred. Customers uncertain whether they were affected were advised to check their inboxes for a notification from [email protected].
Trezor’s Privacy Recommendations Going Forward
In response to the incident, Trezor outlined several steps customers can take to reduce data exposure on future orders. The company recommended using an anonymous email address not linked to one’s real identity when placing orders, and suggested paying with cryptocurrency rather than a credit card where possible — or using disposable digital cards for online purchases if crypto payment isn’t an option. Trezor also suggested using a P.O. Box to limit address exposure, while noting that identification is typically still required for package collection and that postal services retain their own data records regardless.
Trezor additionally teased an upcoming “Anonymous Delivery” feature, designed to let customers receive hardware wallets more privately through a dedicated checkout process, locker pickup options, neutral packaging, generic sender details, and automatic deletion of shipping identifiers following delivery.
Bits of Gold: A Third Breach in Israel
Adding to the pattern, Bits of Gold — Israel’s largest regulated cryptocurrency broker — separately reported a potential data breach affecting up to 200,000 clients, though fewer technical details have been made public compared to the SafePal and Trezor incidents. The near-simultaneous timing of three separate crypto-industry data exposures within roughly the same week has amplified concern across the sector about the security practices of vendors and partners handling crypto customer data.
Why These Breaches Matter Even Without Stolen Funds
Security researchers have repeatedly emphasized that even when seed phrases and private keys remain untouched, breaches exposing names, addresses, and purchase details tied specifically to cryptocurrency hardware purchases carry outsized risk compared to typical e-commerce data leaks.
A leaked customer list confirming that a specific person owns a hardware crypto wallet — and knows their home address — provides exactly the targeting information needed for sophisticated phishing campaigns, fraudulent “customer support” outreach, and, in more extreme cases, physical confrontation or coercion, sometimes referred to in the industry as “wrench attacks.”
Part of a Broader Pattern of Sensitive Data Exposure
These crypto-specific incidents are unfolding against a backdrop of other major data breaches with similar targeting implications. In France, a leak reportedly exposed data belonging to 678,000 taxpayers, including income figures, addresses, and property details — information that, while not crypto-related, provides exactly the kind of financial profiling criminals use to identify and select wealthy targets for extortion or robbery, independent of whether victims hold cryptocurrency at all.
What Affected Users Should Do Now
For anyone who has purchased a hardware wallet from SafePal or Trezor, or who holds an account with Bits of Gold, security experts recommend treating any unexpected communication referencing a past purchase — by phone, email, text, or physical mail — with heightened suspicion. This includes unsolicited firmware update requests, refund offers, or “support” calls asking for seed phrases or private keys under any circumstance. Genuine hardware wallet companies do not request this information through outbound contact.
Users should verify any communication through official company channels by manually navigating to the company’s known website rather than clicking links, and report suspicious contact through the companies’ dedicated reporting channels rather than social media, where scammers can more easily impersonate support staff.