Key Takeaways: Personal data of 54,000 hardware wallet owners was exposed in separate Trezor and SafePal breaches, fueling phishing and physical attack risks.
Key Takeaways: Personal data of 54,000 hardware wallet owners was exposed in separate Trezor and SafePal breaches, fueling phishing and physical attack risks.

Data from 54,000 crypto wallet users was exposed in separate breaches at Trezor and SafePal, raising the risk of targeted phishing attacks against hardware wallet owners.
Chainalysis called such leaks a primary driver of rising physical attacks on crypto investors in 2026, according to the firm's August analysis.
Trezor's breach affected 13,689 customers through its U.S. shipping partner ShipMonk, exposing names, addresses, and phone numbers for orders placed between May and August. SafePal's incident exposed names, addresses, phone numbers, and order details of nearly 40,000 customers. SafePal first learned of the problem in May but disclosed it only this week.
The 2020 Ledger breach, which exposed 270,000 customers, set a grim precedent: French authorities documented 77 cases of physical extortion tied to crypto ownership in the first half of 2026. With shipping addresses now in the hands of attackers, hardware wallet owners face risks that extend beyond their devices.
The Trezor incident originated at ShipMonk, a third-party logistics provider, rather than in Trezor's own infrastructure. The SafePal breach stemmed from a broken object-level authorization vulnerability in a third-party order-tracking plugin, compounded by a misconfigured data cleanup script that failed silently between September 2025 and April 2026, extending the exposure window to 13 months.
Neither company reported that private keys, seed phrases, or financial data were compromised. But the leaked datasets — full names, home addresses, phone numbers, and specific hardware models purchased — give attackers a curated directory of confirmed crypto holders. Attackers have already deployed typosquatted domains to run personalized phishing and voice phishing campaigns, referencing exact delivery dates and device models to appear legitimate.
The incidents follow a separate Coldcard firmware bug that drained roughly 1,083 BTC, worth about $70.2 million, from 1,196 addresses on July 30, according to Galaxy Research. Three different attack routes in the same year have put the hardware wallet industry's security claims under scrutiny.
Bitcoin traded around $63,500 on Aug. 17, holding within the $62,000–65,000 range it has occupied since early July. Ethereum stayed above $1,900. Both assets declined for the week ending Aug. 16 — BTC lost about 3 percent and ETH about 2 percent. The Fear and Greed Index sat at 31, in "Fear" territory.
BTC-based exchange-traded funds ended the trading week to Aug. 14 with outflows of nearly $390 million, while ETH funds saw outflows under $3 million.
Regulatory uncertainty persists. Donald Trump is expected to meet with crypto company leaders at the White House on Aug. 19, with CFTC's Michael Selig and SEC's Paul Atkins expected to join. Galaxy analysts estimate the CLARITY Act's passage odds this year at just 10 percent.
Ethereum's Hegota upgrade, expected in early 2027, remains a key focus for the network's development trajectory.
This article is for informational purposes only and does not constitute investment advice.