Key TakeawaysSafePal disclosed on Sunday, August 16, 2026 that a flaw in the order tracking plugin on its store exposed the names, home addresses and phone numbers of 39,798 hardware wallet buyers.TheKey TakeawaysSafePal disclosed on Sunday, August 16, 2026 that a flaw in the order tracking plugin on its store exposed the names, home addresses and phone numbers of 39,798 hardware wallet buyers.The

Trezor and SafePal Data Leaks Expose 53,000 Crypto Holders: How to Survive the Coming Phishing Wave

Key Takeaways
SafePal disclosed on Sunday, August 16, 2026 that a flaw in the order tracking plugin on its store exposed the names, home addresses and phone numbers of 39,798 hardware wallet buyers.
The announcement came just three days after Trezor confirmed a breach at its shipping partner ShipMonk exposed personal data on 13,689 customers across seven countries, the first incident in the company's history to leak phone numbers and shipping addresses.
No private keys, seed phrases or funds were compromised in either incident, and both companies say their own systems and devices remain secure. The danger is what criminals do with the contact data next.
The Ledger breach of 2020 shows the playbook: targeted phishing emails, fake support calls, counterfeit devices and recall letters sent by post, and extortion attempts that continue six years later. Chainalysis data cited by Trezor counts roughly $30 million stolen in violent crypto attacks by mid 2026, with home invasions making up 37% of incidents.
Affected users should treat every unsolicited message as hostile, never enter a recovery phrase anywhere online, and verify all communication through official channels only.
 
 

Two Breaches in One Week

The hardware wallet industry just suffered its worst week for customer privacy since the Ledger leak of 2020, and not a single coin was stolen to cause it. On Thursday, August 13, Trezor disclosed that ShipMonk, the logistics partner that stores and ships its devices in several markets, had been breached. ShipMonk notified Trezor on August 10 that an intruder accessed systems holding customer records: 11,742 buyers had their full names, email addresses, phone numbers and shipping addresses exposed, while another 1,947 lost names, cities and emails, bringing the total to 13,689 people across the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal.
Three days later, Binance backed SafePal published a disclosure of its own. A vulnerability in the order tracking plugin on its online store allowed unauthorized access to the names, home addresses and phone numbers of 39,798 buyers. SafePal called the timing an unfortunate coincidence, said it found no evidence that wallets or funds were compromised, and reported taking down more than 30 fraudulent websites and phishing links already impersonating the brand. Former Binance CEO Changpeng Zhao amplified the warning to users. Between the two incidents, roughly 53,500 people who bought a device specifically to be safe now have their home addresses circulating in criminal hands.
 
 

Why Leaked Addresses Are So Dangerous for Crypto Holders

The instinctive reaction, that no funds were touched so no harm was done, misses how these attacks actually work. A hardware wallet purchase record is a targeting list: it tells criminals exactly who owns crypto, where they live, and how to reach them. As one analysis put it, a seed phrase can be replaced and a password reset, but a home address cannot.
The Ledger breach of 2020, which exposed over a million email addresses and hundreds of thousands of order records, kicked off a phishing and extortion campaign that has never fully stopped. Victims received convincing fake security emails, letters by post announcing bogus device recalls, counterfeit replacement wallets pre loaded with malicious firmware, and ransom demands leveraging their home addresses. Trezor's own disclosure cites Chainalysis figures showing about $30 million stolen in violent, in person crypto attacks by mid 2026, with home invasions accounting for 37% of incidents. The digital route is just as active: only days before the Trezor disclosure, a user reportedly lost 24 BTC to a phishing advertisement impersonating Trezor at the top of Google search results.
 

A Bruising Stretch for Self Custody

The leaks land on an already shaken self custody community. The Coldcard firmware exploit that surfaced on July 30 has now drained more than $130 million in Bitcoin from wallets generated with a flawed random number generator, and Ledger dealt with a separate payment processor leak in January. The pattern across all of these incidents is consistent: the cryptography keeps holding, while the surrounding infrastructure, firmware pipelines, shipping vendors, store plugins and search ads, keeps failing. For attackers, the customer database has become a softer target than the wallet itself.
 

What Affected Users Should Do Right Now

If you have ever ordered from Trezor or SafePal, assume your details may be in circulation and raise your baseline of suspicion permanently. Treat any unsolicited email, phone call, text, letter or courier delivery referencing your wallet as hostile until proven otherwise, especially anything urgent about a security problem, refund, recall or replacement device. Neither company will ever ask for your recovery phrase, and no legitimate process ever requires typing a seed phrase into a website, app or support chat. Navigate to official sites directly rather than through search ads or emailed links, and verify any claimed communication through the companies' official channels.
Longer term hygiene helps too. Use a dedicated email address not tied to your real name for crypto purchases, consider a delivery address that is not your home, add a BIP39 passphrase so a physical device alone cannot expose funds, and be conscious of physical security given the rise in doorstep scams. Anyone who receives an unexpected hardware wallet in the mail should treat it as compromised and never use it.
 

What It Means for Traders on MEXC

These leaks do not change the case for careful self custody, but they are a reminder that security is a full stack problem covering data, devices and behavior, not just keys. The same discipline applies to exchange accounts: enable two factor authentication, use a unique password, be wary of any message claiming to be from an exchange, and confirm announcements through official channels before acting. MEXC will never ask for passwords or recovery phrases, and users can review account protections in their security settings.
Market Opportunity
Orderly Network Logo
Orderly Network Price(ORDER)
--
----
USD
Orderly Network (ORDER) Live Price Chart

Description:Crypto Pulse is powered by AI and public sources to bring you the hottest token trends instantly. For expert insights and in-depth analysis, visit MEXC Learn.

The articles shared on this page are sourced from public platforms and are provided for reference only. They do not represent the position or views of MEXC. All rights belong to OoJae. If you believe any content infringes upon the rights of a third party, please contact service@support.mexc.com for prompt removal. MEXC does not guarantee the accuracy, completeness, or timeliness of any content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be interpreted as a recommendation or endorsement by MEXC. For expert insights and in-depth analysis, visit MEXC Learn.

Latest Updates on Orderly Network

View More
Tesla Phone Release Date: What Buyers Should Know Before Pre-Ordering in 2026

Tesla Phone Release Date: What Buyers Should Know Before Pre-Ordering in 2026

Search interest in the tesla phone release date has grown steadily, but much of the available information online mixes speculation with marketing claims. This article focuses specifically on how to interpret release date announcements, what verification steps make sense, and what buyers should plan for if they intend to pre-order. The aim is to deliver practical guidance rather than repeat general product overviews.
2026/04/28
Dell’s AI Server Forecast and $9.7B Pentagon Win Put Infrastructure Demand Back in Focus

Dell’s AI Server Forecast and $9.7B Pentagon Win Put Infrastructure Demand Back in Focus

Dell drew fresh market attention after raising its fiscal 2027 AI server revenue forecast to about $60 billion, up from a previous $50 billion forecast, while first-quarter revenue rose 88% to $43.84 billion and shares surged after the results. The same tape also included a roughly $9.7 billion Pentagon agreement tied to Microsoft enterprise software, cloud subscriptions, and licensing, though that contract is not a direct AI server order. The market signal is broader: Dell is being repriced less as a traditional hardware vendor and more as an infrastructure supplier sitting between AI data-center demand, enterprise deployment, and government digital procurement. The key test is whether this demand continues to show up in backlog, margins, and future order guidance.
2026/05/29
Pakistan National Cricket Team vs South Africa National Cricket Team Match Scorecard

Pakistan National Cricket Team vs South Africa National Cricket Team Match Scorecard

The Pakistan national cricket team vs South Africa national cricket team match scorecard is one of the most searched cricket topics because both teams have a long and competitive history across Tests, ODIs, and T20Is. Pakistan and South Africa often produce matches shaped by fast bowling, middle-order pressure, spin control, and unpredictable batting collapses.
2026/06/09
View More