Share
WALLET DATA LEAK - WHAT COMES NEXT

53,487 wallet owners lost no crypto at all. Most of them lost their home addresses.

Two hardware wallet makers disclosed customer data exposures three days apart. No seed phrases, no funds, nothing touched on the devices. What leaked is the paperwork around the purchase, which turns out to be the more useful thing to steal.

SafeBrowz Threat Research Security Research · · 9 min read

The brief

Your crypto is fine. The wallets themselves were never compromised, and SafePal confirms no seed phrases, private keys or funds were involved. What was exposed is your name and email, and for most of those affected the phone number and shipping address too, tied to the fact that you bought a hardware wallet. Expect calls, emails, texts and printed letters that quote real order details back to you. Judge every one of them by going to the vendor yourself, and if a message carries a link, check where that link actually leads before you open it, because the leaked details make the message read as genuine no matter what the link does.

SafeBrowz reads the page a link opens, so a claim page dressed as your wallet vendor is judged on where it lives. Add to Chrome, free Get the free Android app or scan a URL now →

What actually happened, in both cases

Trezor confirmed first, on 13 August 2026: a breach at ShipMonk, one of its fulfilment partners, exposed personal data belonging to 13,689 customers across seven countries. Trezor splits that figure: 11,742 had full exposure of name, email, phone and shipping address, while 1,947 had partial exposure, name, city and email only, with no shipping address. Three days later, on 16 August 2026, SafePal disclosed that an authorization flaw in an order-tracking plug-in on its store had exposed names, email addresses, shipping addresses, phone numbers and purchase details for roughly 39,798 customers. Together that is 53,487 people.

SafePal says the affected orders were placed between 2 March 2025 and 11 April 2026, and it is worth reading that precisely: those dates describe when the orders were placed, not the window during which the flaw could be exploited. The company has not said when the unauthorized access started or stopped, or how many parties reached the records. It has said it first received a report consistent with the issue in early May and began a full review and rebuild of its order-processing pipeline in July, and that a failed data-cleanup job between September 2025 and April 2026 is why the affected range reaches back to March 2025. No CVE has been assigned.

Neither incident touched a wallet. SafePal is explicit that seed phrases, private keys, wallet passwords and funds were not involved; Trezor states that no Trezor system, product or service was affected and that the parcel contents were not exposed. A hardware wallet stays offline by design, which is exactly why the attackers went around it instead.

Why a shipping list is worth more than a password dump

A leaked password database is a commodity. This is not that. Each record here ties a named individual to a home address and to one specific purchase: a device for storing cryptocurrency. That combination does something a password never does. It identifies, with high confidence, a person who plausibly holds crypto, and it says where they sleep.

For the scam side, which is our lane, it removes the guesswork that normally gives phishing away. The message no longer has to open with a vague "dear customer". It can carry your name, your address, and details of an order you actually placed, which is precisely the evidence people use to decide a message is genuine.

There is a second, heavier risk, and it would be dishonest to skip it. Because the records point to home addresses, security reporting on these leaks has focused on physical attacks, where a seed phrase is taken by force rather than by trickery. Blockchain security firm CertiK recorded dozens of such attacks during 2025, up roughly 75% on the previous year, and Chainalysis puts this year's losses near $30 million. Nothing in this article, and no browser tool, helps with that. If you are on either list and you have ever discussed holdings publicly, that is a conversation to have with people who handle physical security, not software.

The list is being offered for sale, which is why this is not over

SafePal's own update on 18 August addresses it directly: the company says it is aware of individuals claiming to hold the affected customer dataset and offering it for sale, and that it cannot verify whether those claims are genuine. Take it at that weight. But a list that is being advertised at all is a list more than one operator may end up working from, and that is what stretches the timeline: contact does not arrive in a single wave and then stop.

It also means the sensible planning horizon is months, not days. Whoever ends up holding that list has no reason to use it while everyone is still reading the news.

The one email worth memorising

SafePal notified affected customers individually on 16 August 2026 from [email protected], with the subject line "[Important] Your SafePal Order Information Has Been Affected."

Knowing the real one matters, because copying it is the obvious next move for anyone holding the list. Expect that exact subject to be reused, and expect the copy to be better than usual: whoever sends it can quote your order back to you. The tell will not be the wording. The tell is that a genuine breach notice tells you what happened and what to watch for, and never routes you to a page that wants a recovery phrase.

SafePal itself published what customers should expect: fraudulent phone calls, emails, text messages, letters, refund offers, firmware-update requests, fake customer-support communications and malicious websites. That is a vendor telling you the shape of the next three months.

The letter is the part people underestimate

Three of the channels on that list are electronic and one is not. A printed letter, arriving at the address the attacker now has, carries an authority that email lost a decade ago. Nobody expects a scam to cost postage.

This is not hypothetical for wallet owners. After Ledger's own customer list leaked, owners received exactly that: a physical letter on convincing letterhead, referencing their device, carrying a QR code that led to a page asking for the recovery phrase. We took that campaign apart in the Ledger post-quantum upgrade letter scam, and the playbook transfers directly to these two lists. A QR code in a letter is a link you cannot read before you follow it, which is the whole reason it is printed rather than written out.

What does not follow from this leak

Worth stating plainly, because the messages arriving will imply the opposite. Nothing in the fields SafePal published, name, email, shipping address, phone and purchase details, tells anyone what a customer holds. No wallet addresses, no balances. Whoever has the list knows you bought a wallet. They do not know whether it holds fifty dollars or five hundred thousand.

So a message that claims to know your balance, references a specific transaction, or warns that "your funds are at risk" is guessing, and guessing is a tell. The leaked data cannot support any of those claims.

Handling anything that arrives now

  1. Assume contact is hostile, whatever channel it uses. For the next few months, a message referencing your wallet order is more likely to be from the list than from the vendor. That is a sorting rule, not paranoia.
  2. Verify by going there yourself. Open the vendor's own app, or type the address you already know. Never use a number, link or QR code supplied by the message that needs verifying.
  3. Firmware never arrives by message. Updates come through the vendor's official application. A firmware prompt reaching you by email, SMS or paper is the attack, in every version of this we have seen.
  4. Check the destination before the page loads. If a message does carry a link and you need to judge it, look at where it actually goes rather than what it says, because the leaked order details make everything around the link look right.
  5. The recovery phrase has exactly one home. It is typed into your own device, during setup or recovery, and nowhere else, ever, for any reason anyone gives you. If you have entered one anywhere else, move the funds now and read what to do when a seed phrase is stolen.

When the attacker already knows your name and address

Most phishing advice quietly assumes the sender is guessing about you. This leak removes that assumption, so the advice has to move to the only thing the attacker still cannot control: where their link goes.

That is the gap SafeBrowz works in. Layer 1 reads the shape of a link in the browser before the page renders. Layer 2 checks the destination server-side against reputation feeds, a brand database of over 550 names, and our blocklist, which is where wallet-vendor lookalikes land. Layer 3 is the AI deep scan (Premium, with one free scan a day) reading what the page actually serves, so a recovery-phrase form wearing a vendor's branding on a fresh domain reads as what it is rather than what it claims. SafePal has already had more than 30 fraudulent sites taken down off the back of this leak, which is the volume this creates.

Honest scope, and it is wider than usual here. We judge links and pages. A phone call has no link. A printed letter has a QR code we can only help with once it is opened on a device that has us installed. And the physical-safety risk this leak creates is entirely outside what any browser tool can do. On those, the rules above are the defence, not us.

Got a message about your wallet order? Check the link before it opens. Stop a fake vendor page → Get the free Android app
🛡 LIVE CHECK

Not sure where an email link goes?

Paste it here instead of clicking it. Our 3-layer engine (Local + APIs + AI) returns a verdict in about 3 seconds. Free, no signup.

Full scan with deep AI analysis → · No URL is logged to your identity.

Frequently asked questions

Were my crypto or seed phrase stolen in the SafePal or Trezor leak?

No. SafePal states that no seed phrases, private keys, wallet passwords or funds were involved, and Trezor says no Trezor system, product or service was affected. The hardware wallets themselves were not compromised. What leaked is the paperwork around your purchase: name and email for everyone affected, and for most of them the phone number and home address too. That is a different problem, not a smaller one, because it tells a stranger who you are and where you live.

What did SafePal's real notification email look like?

SafePal says it emailed affected customers individually on 16 August 2026 from [email protected], with the subject line "[Important] Your SafePal Order Information Has Been Affected." Knowing the real one matters because copies of it are the obvious next move for anyone holding the leaked list. A genuine breach notice never asks you to enter a seed phrase, and never links you to a page that does.

Does the leaked data show how much crypto I hold?

No, and this is worth holding onto before you panic. The fields SafePal published are name, email, shipping address, phone and purchase details. No wallet addresses, no balances, nothing that indicates what a customer holds. Whoever has the list knows you bought a hardware wallet, not that you are wealthy. The messages that arrive will imply otherwise, because implying it is free.

I have been contacted about a replacement device or a firmware update. Is it real?

Treat it as fake until you prove otherwise, and prove it by going to the vendor yourself rather than through anything in the message. SafePal specifically listed fraudulent calls, emails, texts, letters, refund offers, firmware-update requests and fake support contacts as what customers should expect. Firmware comes from the vendor's own app, never from a link, a QR code or an enclosed card.

A letter arrived in the post about my wallet. Can a physical letter be a scam?

Yes, and this leak makes it likelier because the attackers now have verified home addresses. Ledger owners saw exactly this after their own customer list leaked: a printed letter on convincing letterhead, a QR code, and a page that asked for the recovery phrase. Paper carries authority that email lost years ago, which is the entire point of using it.

What should I actually change right now?

Nothing on the wallet itself, because the wallet was not breached and rotating a seed phrase you still control is unnecessary risk. Change how you handle contact instead: assume any message referencing your order is hostile, verify through the vendor's own app or a typed address, and never type a recovery phrase anywhere for any reason. If you have already entered one, treat it as compromised and move the funds immediately.

Follow on Google