
The SafePal breach and a recent Trezor shipping-partner leak together exposed 53,487 hardware-wallet customer records, sharpening concerns over phishing and physical-security risks tied to self-custody buyer data.
SafePal said an authorization flaw in an order-tracking plugin exposed the personal and purchase information of 39,798 customers who placed orders between March 2, 2025 and April 11, 2026, while saying seed phrases, private keys and crypto assets were not compromised. The company framed the incident as a failure in the operational commerce layer around wallet sales rather than in wallet custody or cryptographic design, and it has not publicly clarified whether the affected records were housed on its own systems or with a third-party fulfillment provider. Names, email addresses, shipping addresses, phone numbers and purchase details were exposed, creating material phishing, fake-delivery and broader social-engineering risks even without direct wallet compromise. SafePal said it escalated the issue after a phishing report in early May, confirmed the flaw during a July review and rebuild of its order-processing pipeline, found a separate configuration error that halted scheduled data cleanup between September 2025 and April 2026, and has since notified users, added an order-check tool, taken down more than 30 phishing sites and links, reduced data retention in the affected environment to 90 days and hired an independent security firm to review the fix and broader order-processing systems. The disclosure came days after Trezor said a breach at shipping partner ShipMonk exposed customer details for 13,689 users, bringing the combined total across the two incidents to 53,487 records and renewing concern that hardware-wallet buyer data can be used for phishing and even physical targeting.