Trezor, SafePal Data Breaches Raise Security Risks for Hardware Wallet Owners

Trezor and SafePal customer data exposures highlight new hardware wallet security risks, including targeted phishing and potential physical attacks on owners.

Aug 17, 2026 - 11:34
 6
Trezor, SafePal Data Breaches Raise Security Risks for Hardware Wallet Owners
Image Credit: Chatgpt

Recent customer-data exposures involving hardware wallet makers Trezor and SafePal are highlighting a security problem that storing cryptocurrency keys offline cannot solve: attackers may still obtain personal information that identifies where wallet owners live and how to contact them. Neither incident compromised customers’ private keys or hardware wallets, but both exposed information that could be used for targeted phishing or other attacks.

Trezor said shipping provider ShipMonk suffered a breach affecting about 13,689 customers. Of those, 11,742 had information, including their names, email addresses, phone numbers, and shipping addresses, exposed, while another 1,947 had more limited information accessed. Trezor said its own systems and devices were not compromised.

SafePal separately disclosed that a flaw in an order-tracking plug-in allowed unauthorised access to information belonging to approximately 39,798 customers. The records included names, email addresses, shipping addresses, phone numbers, and purchase information from customers who placed orders between March 2, 2025 and April 11, 2026. Palal said. Seed phrases, private keys, and cryptocurrency funds were not exposed.

Hardware wallet data leaks create risks beyond online hacking

Hardware wallets are designed to keep the private keys used to control cryptocurrency away from internet-connected systems. The recent incidents show that the companies and services surrounding those devices can still hold sensitive customer information required to process purchases and deliveries.

For cryptocurrency holders, exposing a home address can carry risks beyond conventional identity theft. Security researchers have documented a rise in so-called wrench attacks, in which criminals use kidnapping, home invasions or other forms of physical coercion to force victims to surrender access to cryptocurrency.

CertiK documented 72 verified incidents of physical coercion worldwide in 2025, a 75% increase over the previous year, with confirmed losses exceeding $40.9 million. Chainalysis, which uses its own methodology, estimated that violent crypto attacks resulted in $58 million stolen during 2025 and more than $30 million through mid-2026.

Chainalysis said home invasions accounted for 37% of documented incidents in 2026, while kidnappings represented 52%. The firm also noted that leaked personal information can help criminals identify potential victims, citing a separate breach of records on high-net-worth cryptocurrency holders in France as a likely factor behind a surge in attacks there.

Trezor and SafePal have urged affected customers to remain alert for phishing and impersonation attempts. Information such as a customer’s name, phone number, email address and purchase history can make fraudulent messages appear more convincing, even when an attacker has no direct access to the wallet itself.

Coldcard flaw exposed a different hardware wallet risk

The data exposures follow a separate security incident involving Coinkite’s Coldcard Bitcoin hardware wallets. Coinkite disclosed in July that a firmware flaw affected the generation of some wallet seeds, leaving certain seeds with less randomness than intended and potentially allowing attackers to determine them.

Blockchain intelligence firm TRM Labs attributed the theft of 1,816 bitcoin, valued at about $116 million at the time of its analysis on August 5, to the exploitation of the Coldcard vulnerability. Other reports put the value of stolen cryptocurrency at over $130 million as the incident unfolded.

Coinkite warned that simply installing updated firmware does not repair a recovery seed generated by affected software. Its advisory says potentially affected users should generate a new seed using fixed firmware and move their funds. In contrast, seeds created with at least 50 independent private dice rolls receive additional protection from the specific weakness.

Together, the incidents demonstrate two distinct risks for hardware wallet owners. Offline key storage can reduce exposure to conventional remote attacks. Still, it does not protect personal information held by merchants and service providers, nor can it compensate for flaws in the software that generates the cryptographic secrets on which a wallet depends.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Angry Angry 0
Sad Sad 0
Wow Wow 0
Shivangi Yadav Shivangi Yadav reports on startups, technology policy, and other significant technology-focused developments in India for TechAmerica.Ai. She previously worked as a research intern at ORF.