SafePal Breach Exposes 40,000 Addresses, Pushing Weekly Wallet Leak Past 53,000
SafePal's data breach hit nearly 40,000 users' home addresses, adding to Trezor's 13,689-customer leak from the same week.

Two hardware wallet makers disclosed data breaches within the same week, pushing the combined tally of exposed crypto customers past 53,000. SafePal confirmed a leak affecting nearly 40,000 users’ home addresses, coming just days after Trezor reported that 13,689 customer records had been compromised through a third-party shipping partner.
Read more: Trezor Breach at ShipMonk Exposes Data of 13,689 Customers, Wallets Safe
What leaked, and how much
SafePal’s breach exposed home addresses belonging to close to 40,000 customers, according to reporting on the incident. That figure alone dwarfs many single-company leaks in the crypto hardware space and, combined with Trezor’s separate disclosure, brings the week’s total exposed users to more than 53,000.
Trezor’s breach originated at ShipMonk, the mailing and fulfillment provider it uses to ship devices, rather than at Trezor itself. The exposure covered customers in the UK, US, Sweden, Colombia, Brazil, Italy and Portugal who placed orders between May 10 and August 8, 2026. Of the 13,689 affected, roughly 12,000 had full name, physical address, phone number and email address exposed, while around 2,000 had name, city and email leaked.
No wallets or private keys touched — but phishing risk is real
Trezor says the intruder gained “unauthorized access” to ShipMonk’s systems and that its own infrastructure — devices and private keys — was not affected. The company was informed of the breach on August 10 and said it is still gathering details before deciding on the future of its partnership with ShipMonk.
Trezor credited its 90-day data retention policy — which deletes or anonymizes order data three months after delivery — with limiting the scope of the leak. The company said it is also rolling out an “anonymous delivery” option this year and reminded customers that “Nobody from Trezor ever asks for a wallet backup.”
For SafePal users, no comparable technical breakdown of the incident is yet available, but the scale — nearly 40,000 home addresses — puts it among the larger disclosures to hit the hardware wallet sector this year.
Why the numbers matter for holders
Neither breach compromised seed phrases or private keys, so funds held on affected devices remain secure as long as owners never share their recovery phrase. The real danger is downstream: leaked names, addresses, phone numbers and emails are prime material for targeted phishing, fake support calls, or even physical theft attempts against known crypto holders.
Ledger, another major hardware wallet maker, suffered similar customer-data leaks in 2020 and again in 2026, both of which were followed by waves of phishing emails and fake device replacements sent to affected users. With more than 53,000 crypto owners now exposed across the SafePal and Trezor incidents this week, security teams are urging customers who receive unsolicited “support” contact referencing their order to treat it as a scam and never enter a seed phrase anywhere outside the physical device itself.
Sources
Related articles
Trezor’s Email Provider Breached, Fake STM32 Vulnerability Alert Sent to Users
Trezor confirms a third-party email vendor was breached, sending a fake STM32 vulnerability warning; two independent sources verify the incident.
Trezor Breach Grows by 67,000 US Records After ShipMonk Data Wasn’t Deleted
Trezor confirms 67,000 more US customers exposed via ShipMonk; three outlets agree on the figure, but initial breach counts differ.
Ledger Ethereum App Flaw: Patched in v1.22.2 on Aug 13, Company Says
OneKey says it reproduced a transaction-swap bug in Ledger's Ethereum app v1.22.1. Ledger says the fix shipped weeks earlier.