The SafePal breach exposed order records that stretched back 13 months. That is the number worth sitting with. On August 16 the crypto wallet maker told 39,798 customers their names, email addresses, shipping addresses and phone numbers had leaked through an authorization flaw in an order-tracking plugin. Wallets, seed phrases and private keys were untouched, the company said. The customer histories were not.
Three days earlier, Trezor disclosed a breach that looked almost identical. A shipping partner named ShipMonk exposed personal data on close to 14,000 buyers. Same categories of data, same phishing risk. One detail separated the two events, and it was not the customer count.
Trezor lost 90 days of data, SafePal lost more than a year
Trezor's exposure was capped by design. Its breach reached only customers who had received an order within the previous 90 days, because that is as far back as the leaked order data went. SafePal's records ran from March 2, 2025 to April 11, 2026. More than a year of names and addresses, held in a system that one plugin bug pried open.
| Wallet maker | Customers exposed | Data reached back | Disclosed |
|---|---|---|---|
| Trezor | about 13,689 | 90 days | August 13, 2026 |
| SafePal | 39,798 | about 13 months (March 2025 to April 2026) | August 16, 2026 |
SafePal's own fix tells you it agrees. After the SafePal breach the company said it would now keep personal order data for 90 days. That is the same window Trezor already used. The cap arrived after the leak, not before it, which means the records that hurt customers were records the company had no working reason to still be storing.
An old address is a targeting list
Order data reads as harmless next to a private key. In this business it is not. A real name tied to a home address and a phone number is precisely what a phishing crew wants, and it is what turns a data leak into a physical risk, the same targeting pattern that has preceded on-chain thefts like the Coldcard case earlier this year. Changpeng Zhao made the point bluntly after the disclosure: stolen names and addresses feed social engineering, and in the worst cases they feed home invasions.
SafePal said it removed more than 30 fraudulent websites and phishing links aimed at its customers, part of the same scam economy that European regulators have started to push against under MiCA. Security researchers reported the SafePal breach records already listed for sale on a cybercrime forum, with the seller's dates matching the company's own timeline. There is no confirmation the sample is authentic, but the match is not reassuring.
Retention is the variable nobody markets
Both companies build devices whose entire pitch is that your keys never leave your hands. The SafePal breach touched no key, and neither did Trezor's. What leaked was the paperwork around the sale, and the difference in damage came down to a boring back-office choice about how long to keep it. For anyone comparing hardware wallets, that is the question the spec sheets skip: not how the device guards a seed, but how long the shop behind it keeps your address on file.