Separate customer-data incidents involving Trezor and SafePal affected approximately 53,487 users, exposing personal and order information that could increase the risk of targeted phishing, impersonation and social-engineering attacks.
Neither company reported that private keys, recovery phrases or wallet passwords were compromised. Instead, the incidents occurred within systems surrounding the wallets themselves: a third-party shipping provider in Trezor’s case and an authorization flaw affecting SafePal’s order-tracking infrastructure.
That distinction is critical.
For much of crypto’s history, security has been framed around protecting private keys, securing wallet software and defending blockchain protocols. Those protections remain fundamental, but the attack surface is expanding beyond the cryptographic layer.
As core custody systems become harder to compromise directly, attackers have greater incentive to target the infrastructure around them.
A secure private key does not automatically mean a secure user.
The breach happened outside the wallet
Trezor disclosed that ShipMonk, one of its shipping providers, experienced unauthorized access to systems containing customer information. The affected data included names, email addresses, telephone numbers, shipping addresses and other order-related information. Trezor said its own systems were not compromised and its devices remained secure.
SafePal separately disclosed an authorization flaw affecting an order-tracking function. Under certain conditions, the issue allowed unauthorized access to customer-order information, including names, email addresses, shipping addresses, telephone numbers and purchase details. SafePal said seed phrases, private keys and wallet passwords were not exposed.
The technical distinction matters because neither case represents a direct compromise of wallet cryptography.
The vulnerabilities existed further up the stack.
A modern digital-asset security model now has to account for several interconnected layers:
- Cryptographic security, which protects private keys and transaction authorization.
- Application security, which protects software, APIs, plug-ins and databases.
- Identity and privacy security, which protects customer information and behavioral data.
- Supply-chain security, which protects vendors, fulfillment providers and external software dependencies.
- Operational security, which governs access controls and internal processes.
- Human security, which protects users against impersonation, phishing and manipulation.
The failure of one layer does not necessarily compromise another.
But it can still create a practical path toward the asset.
Customer metadata is becoming part of asset security
The value of exposed data changes when context is added.
An email address by itself is personal information.
An email address associated with the purchase of a hardware wallet tells an attacker substantially more.
When combined, leaked information can potentially establish:
Identity → cryptocurrency ownership → wallet provider → purchase history → communication channel → physical location
That context can make attacks significantly more convincing.
Instead of sending generic crypto phishing messages, attackers may be able to impersonate the correct wallet provider, reference a known product, fabricate firmware alerts, offer fraudulent refunds or direct users toward fake customer-support environments.
SafePal warned affected customers about precisely these types of attacks, including fraudulent calls, emails, text messages, refund offers, firmware-update requests and malicious websites. The company said it had already identified and taken down more than 30 fraudulent websites and phishing links associated with scam activity.
The attacker does not necessarily need to break the wallet. They may only need to convince the owner to unlock it for them.
That is where privacy becomes inseparable from security.
Self-custody changes where the risk sits
The incidents do not invalidate self-custody.
Self-custody continues to reduce an important category of counterparty risk by allowing users to maintain direct control over their cryptographic authorization.
What it does not do is eliminate every surrounding dependency.
When assets are no longer held by a centralized intermediary, the person controlling the asset becomes a more valuable endpoint.
For security teams, the question therefore becomes broader:
What is the lowest-cost path available to an attacker seeking control over the asset?
That path may involve:
- - A vulnerable web application
- - A compromised vendor
- - An exposed customer database
- - A malicious browser extension
- - An impersonated support representative
- - A fraudulent firmware update; or
- - A targeted social-engineering attempt.
- The attacker does not need to defeat the strongest component of the system.
They need to find the cheapest exploitable one.
The same dependency problem appears at the regulatory layer
The industry is simultaneously confronting another type of external dependency through the Digital Asset Market Clarity Act.
Galaxy Research recently lowered its estimate for the legislation passing in 2026 to 10%, citing unresolved political negotiations, stakeholder pressure and a compressed Senate calendar.
The CLARITY Act debate is not directly connected to the Trezor or SafePal incidents.
The structural observation, however, is similar.
A blockchain may operate without a centralized ledger administrator. A user may independently control a private key. Yet the broader ecosystem can still depend on software providers, logistics companies, financial institutions, regulators and governments.
Decentralization therefore exists at specific layers rather than across an entire technology stack.
That distinction becomes increasingly important as crypto infrastructure becomes more deeply integrated into mainstream commerce and finance.
The Block Tides point
The central takeaway from the Trezor and SafePal incidents is not that hardware wallets failed.
It is that the definition of digital-asset security is becoming wider.
Protecting private keys remains essential, but providers now need to treat customer information, vendor access, commerce infrastructure and identity data as part of the same security perimeter.
That means the industry should increasingly prioritize:
- data minimization;
- stricter customer-information retention policies;
- stronger authorization controls;
- deeper third-party security assessments;
- tighter monitoring of plug-ins and external software;
- faster phishing detection and takedown;
- and incident-response plans that extend beyond the initial breach.
“Crypto has spent more than a decade strengthening cryptographic ownership, custody and blockchain infrastructure. The next phase of security requires the same discipline across every system surrounding those technologies. If an attacker cannot break the private key but can identify the owner, understand the wallet they use and manipulate them into surrendering access, the vulnerability has not disappeared. It has moved elsewhere in the stack.”
Myrtle Anne Ramos, Founder and CEO, Block Tides
Closing
The Trezor and SafePal incidents show that the next generation of digital-asset security will not be defined solely by stronger cryptography.
The industry is moving into a phase where privacy architecture, application security, third-party risk and human behavior are becoming part of asset protection itself.
A blockchain can remain secure.
A hardware wallet can remain secure.
And the user can still be exposed.
That is the security gap the next generation of crypto infrastructure will have to close.
Securing the chain was the first challenge. Securing everything connected to it is the next.