Two separate data leak incidents have recently affected users of Trezor and SafePal hardware wallets around the same time. As a result of these events, personal data belonging to tens of thousands of users was exposed, paving the way for potential large-scale phishing attacks targeting their inboxes and contact information.
Trezor reported the first leak, which compromised approximately 14,000 of its users. The issue did not originate from Trezor’s internal systems, but rather through ShipMonk, a third-party shipping service provider they use. Affected Trezor users include customers who received products in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. The incident specifically targeted those whose items were shipped between May 10 and August 8.
Meanwhile, hardware wallet provider SafePal disclosed a separate issue stemming from its platform’s architecture. There was an authorization flaw in the order tracking plugin within its internal shopping system. This vulnerability allowed one customer to view another customer’s order profile. The impact was widespread: a total of 39,798 customers who placed orders between March 2, 2025, and April 11, 2026, were confirmed to be affected by this flaw.
The data exposed in the SafePal incident includes names, physical addresses, contact details, and overall purchase information. Nevertheless, the company emphasized that the leak was limited to shipping profiles. Seed phrases, private keys, and users’ crypto asset holdings are confirmed to remain secure.
Patching Vulnerabilities and Eliminating Scam Sites
In response to these findings, SafePal acted to close the authorization flaw in its order tracking plugin to prevent unauthorized access. The company also hired a third-party security firm to mitigate risks, as well as identify and take down more than 30 fraudulent websites and phishing links deliberately created to catch users off guard.
As a measure of transparency, SafePal released a verification tool on its official website, allowing users to check directly if their personal data was caught up in the incident. To prevent future occurrences, the company’s order processing system now limits customer data retention to a maximum of 90 days.
Why Wallet Diversification Is Now Mandatory
These dual incidents occurred shortly after a Coldcard hardware wallet hack that resulted in the loss of $120 million worth of bitcoin. This series of breaches has prompted security experts to once again point out the limitations of storage technology: no single crypto storage solution is entirely risk-free.
Therefore, dividing assets across several different wallets has now become an essential step to reduce the risk of loss. For users who might have already compromised their private keys or seed phrases through phishing links, the advice is clear: immediately evacuate all assets to a new wallet before hackers empty the remaining balance.
Reported from CoinDesk.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




