Over 53,000 Crypto Owners Lost Something This Week That Isn’t Money

A seed phrase can be replaced. A password can be reset. A home address cannot. The SafePal data breach disclosed Sunday exposed nearly 40,000 of them.
Three days earlier, Trezor leaked 13,689 more. Together the two hardware wallet makers put 53,487 customer records into the open. Neither company lost a single coin.
What the SafePal Data Breach Exposed
SafePal said 39,798 customers were affected. The leak covered names, emails, phone numbers, shipping addresses, and order details.
The cause was a flaw in the plugin SafePal uses to track orders. In some cases, one customer could open another customer’s record.
Affected orders ran from March 2, 2025 to April 11, 2026. That window stayed open for more than 13 months.
Seed phrases, private keys, bank details, and card numbers were not touched. SafePal has patched the flaw and cut order data retention to 90 days, according to its disclosure.
SafePal Token (SFP) barely moved on Sunday, trading near $0.23. That is the point. Nothing financial happened here.
Why Leaked Addresses Outlast Leaked Passwords
Trezor learned of its own customer data breach on August 10. Its shipping partner, ShipMonk, had been compromised.
Full details leaked for 11,742 Trezor buyers, according to the company’s notice. Names, emails, phone numbers, and home addresses all went out.
The two failures differ at the root. Trezor’s data left through a supplier. SafePal’s left through a system it ran itself.
However, both lists are worth the same to an attacker. Buying a hardware wallet suggests you hold enough crypto to move it off an exchange.
So these records are narrower than a typical exchange leak. They match a likely self-custody holder to a confirmed front door.
Prosecutors Have Already Seen This Playbook
In May, US prosecutors announced charges against three Tennessee men over a $6.5 million robbery spree across California.
The men posed as delivery people to reach victims inside their homes, the indictment says.
A leaked shipping record hands that script to the next crew. It names the buyer, gives the address, and says what arrived in the box.
Phishing is the smaller problem. SafePal has removed more than 30 fake websites and scam links tied to the stolen data.
Real notices came from [email protected]. Anything from another address should be treated as an attack.
Ledger shows how long this tail runs. Its 2020 breach exposed roughly 272,000 postal addresses, names, and phone numbers, per the company’s statement.
Six years on, Ledger still warns customers about phishing letters arriving by post. The company does not tie those letters to the 2020 leak.
Scam domains come down. Inboxes get filtered. Addresses do not expire.
Trezor now plans an anonymous delivery option, reaching the European Union in September and the US by year end. It arrives too late for the 53,487 records already in circulation.
Source: BeInCrypto
Cryptocurrency News
Random quote about money
"Те, кто считает, что деньги могут все, в действительности могут все ради денег."














* to search the proxy database, just enter a country name, e.g. Russia, USA, Thailand