Trezor and SafePal Both Disclose Customer Data Breaches Days Apart

Two of the best-known names in hardware wallets disclosed customer data breaches within days of each other, and neither involved the wallets themselves being compromised.
SafePal said an authorization flaw in a third-party order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of roughly 39,798 customers who ordered between March 2025 and April 2026. Trezor separately disclosed that its fulfillment partner ShipMonk was breached by the group ShinyHunters through a Metabase SQL injection, exposing full contact and shipping details for 11,742 customers and partial details for another 1,947. In both cases, the companies say seed phrases, private keys, wallet passwords, and payment card data were never accessible.
That distinction matters less than it might sound for the people affected. Chainalysis has flagged a rising trend of attackers using exactly this kind of leaked shipping and purchase data to identify likely crypto holders for targeted phishing, impersonation scams, and in the worst documented cases, physical home invasions.
Neither breach touched the cryptographic core of either product, hardware wallets remain hardware wallets, but the incident is a reminder that a self-custody device’s security model doesn’t extend to the retailer, fulfillment partner, or support plug-in a company relies on to actually ship it. Both companies are urging affected customers to watch for suspicious contact referencing their real order details.
Want to understand how hardware wallets actually protect private keys, and what self-custody does and doesn’t cover? Learn more in the Bitcoin Academy.
