The SafePal Breach Exposed 13 Months. Trezor's, 90 Days.

SafePal's breach exposed 39,798 customers with order data going back 13 months. A near-identical Trezor breach days earlier reached only 90 days.

Jan Whitfield News

The SafePal breach exposed order records that stretched back 13 months. That is the number worth sitting with. On August 16 the crypto wallet maker told 39,798 customers their names, email addresses, shipping addresses and phone numbers had leaked through an authorization flaw in an order-tracking plugin. Wallets, seed phrases and private keys were untouched, the company said. The customer histories were not.

Three days earlier, Trezor disclosed a breach that looked almost identical. A shipping partner named ShipMonk exposed personal data on close to 14,000 buyers. Same categories of data, same phishing risk. One detail separated the two events, and it was not the customer count.

Trezor lost 90 days of data, SafePal lost more than a year

Trezor's exposure was capped by design. Its breach reached only customers who had received an order within the previous 90 days, because that is as far back as the leaked order data went. SafePal's records ran from March 2, 2025 to April 11, 2026. More than a year of names and addresses, held in a system that one plugin bug pried open.

Wallet makerCustomers exposedData reached backDisclosed
Trezorabout 13,68990 daysAugust 13, 2026
SafePal39,798about 13 months (March 2025 to April 2026)August 16, 2026

SafePal's own fix tells you it agrees. After the SafePal breach the company said it would now keep personal order data for 90 days. That is the same window Trezor already used. The cap arrived after the leak, not before it, which means the records that hurt customers were records the company had no working reason to still be storing.

An old address is a targeting list

Order data reads as harmless next to a private key. In this business it is not. A real name tied to a home address and a phone number is precisely what a phishing crew wants, and it is what turns a data leak into a physical risk, the same targeting pattern that has preceded on-chain thefts like the Coldcard case earlier this year. Changpeng Zhao made the point bluntly after the disclosure: stolen names and addresses feed social engineering, and in the worst cases they feed home invasions.

SafePal said it removed more than 30 fraudulent websites and phishing links aimed at its customers, part of the same scam economy that European regulators have started to push against under MiCA. Security researchers reported the SafePal breach records already listed for sale on a cybercrime forum, with the seller's dates matching the company's own timeline. There is no confirmation the sample is authentic, but the match is not reassuring.

Retention is the variable nobody markets

Both companies build devices whose entire pitch is that your keys never leave your hands. The SafePal breach touched no key, and neither did Trezor's. What leaked was the paperwork around the sale, and the difference in damage came down to a boring back-office choice about how long to keep it. For anyone comparing hardware wallets, that is the question the spec sheets skip: not how the device guards a seed, but how long the shop behind it keeps your address on file.

Disclaimer The information provided on Coinliva is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency investments are highly volatile and involve risk. While we strive to provide accurate and up-to-date information, some details may change over time. Always conduct your own research before making any financial decisions.
Tags:
Jan Whitfield
Author

Jan Whitfield

Jan Whitfield is the founder and Editor-in-Chief of Coinliva. His coverage focuses on the macro crypto landscape, including regulatory developments, institutional adoption, and structural shifts shaping the digital asset industry. He tracks how policy decisions, ETF flows, and corporate treasury moves connect to broader market dynamics, drawing on primary regulatory filings, official statements, and on-chain data.