Key Takeaways
SafePal disclosed on Sunday, August 16, 2026 that a flaw in the order tracking plugin on its store exposed the names, home addresses and phone numbers of 39,798 hardware wallet buyers.
The announcement came just three days after Trezor confirmed a breach at its shipping partner ShipMonk exposed personal data on 13,689 customers across seven countries, the first incident in the company's history to leak phone numbers and shipping addresses.
No private keys, seed phrases or funds were compromised in either incident, and both companies say their own systems and devices remain secure. The danger is what criminals do with the contact data next.
The Ledger breach of 2020 shows the playbook: targeted phishing emails, fake support calls, counterfeit devices and recall letters sent by post, and extortion attempts that continue six years later. Chainalysis data cited by Trezor counts roughly $30 million stolen in violent crypto attacks by mid 2026, with home invasions making up 37% of incidents.
Affected users should treat every unsolicited message as hostile, never enter a recovery phrase anywhere online, and verify all communication through official channels only.
Two Breaches in One Week
The hardware wallet industry just suffered its worst week for customer privacy since the Ledger leak of 2020, and not a single coin was stolen to cause it. On Thursday, August 13, Trezor disclosed that ShipMonk, the logistics partner that stores and ships its devices in several markets, had been breached. ShipMonk notified Trezor on August 10 that an intruder accessed systems holding customer records: 11,742 buyers had their full names, email addresses, phone numbers and shipping addresses exposed, while another 1,947 lost names, cities and emails, bringing the total to 13,689 people across the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal.
Three days later, Binance backed SafePal published a disclosure of its own. A vulnerability in the order tracking plugin on its online store allowed unauthorized access to the names, home addresses and phone numbers of 39,798 buyers. SafePal called the timing an unfortunate coincidence, said it found no evidence that wallets or funds were compromised, and reported taking down more than 30 fraudulent websites and phishing links already impersonating the brand. Former Binance CEO Changpeng Zhao amplified the warning to users. Between the two incidents, roughly 53,500 people who bought a device specifically to be safe now have their home addresses circulating in criminal hands.
Why Leaked Addresses Are So Dangerous for Crypto Holders
The instinctive reaction, that no funds were touched so no harm was done, misses how these attacks actually work. A hardware wallet purchase record is a targeting list: it tells criminals exactly who owns crypto, where they live, and how to reach them. As one analysis put it, a seed phrase can be replaced and a password reset, but a home address cannot.
The Ledger breach of 2020, which exposed over a million email addresses and hundreds of thousands of order records, kicked off a phishing and extortion campaign that has never fully stopped. Victims received convincing fake security emails, letters by post announcing bogus device recalls, counterfeit replacement wallets pre loaded with malicious firmware, and ransom demands leveraging their home addresses. Trezor's own disclosure cites Chainalysis figures showing about $30 million stolen in violent, in person crypto attacks by mid 2026, with home invasions accounting for 37% of incidents. The digital route is just as active: only days before the Trezor disclosure, a user reportedly lost 24 BTC to a phishing advertisement impersonating Trezor at the top of Google search results.
A Bruising Stretch for Self Custody
The leaks land on an already shaken self custody community. The
Coldcard firmware exploit that surfaced on July 30 has now drained more than $130 million in Bitcoin from wallets generated with a flawed random number generator, and Ledger dealt with a separate payment processor leak in January. The pattern across all of these incidents is consistent: the cryptography keeps holding, while the surrounding infrastructure, firmware pipelines, shipping vendors, store plugins and search ads, keeps failing. For attackers, the customer database has become a softer target than the wallet itself.
What Affected Users Should Do Right Now
If you have ever ordered from Trezor or SafePal, assume your details may be in circulation and raise your baseline of suspicion permanently. Treat any unsolicited email, phone call, text, letter or courier delivery referencing your wallet as hostile until proven otherwise, especially anything urgent about a security problem, refund, recall or replacement device. Neither company will ever ask for your recovery phrase, and no legitimate process ever requires typing a seed phrase into a website, app or support chat. Navigate to official sites directly rather than through search ads or emailed links, and verify any claimed communication through the companies' official channels.
Longer term hygiene helps too. Use a dedicated email address not tied to your real name for crypto purchases, consider a delivery address that is not your home, add a
BIP39 passphrase so a physical device alone cannot expose funds, and be conscious of physical security given the rise in doorstep scams. Anyone who receives an unexpected hardware wallet in the mail should treat it as compromised and never use it.
What It Means for Traders on MEXC
These leaks do not change the case for careful self custody, but they are a reminder that security is a full stack problem covering data, devices and behavior, not just keys. The same discipline applies to exchange accounts: enable two factor authentication, use a unique password, be wary of any message claiming to be from an exchange, and confirm announcements through official channels before acting. MEXC will never ask for passwords or recovery phrases, and users can review account protections in their security settings.