Trezor and SafePal data breaches happened at the courier
Thousands of hardware wallet buyers had names, home addresses, phone numbers and emails taken in separate breaches at shipping partners, per TechCrunch. No key was touched, and the threat model changed anyway.
Nothing failed inside the devices. That is what makes this one worth reading twice.
Trezor and SafePal have each told customers that personal data was taken in separate breaches at their shipping partners, TechCrunch reported on 17 August. Thousands of customers across the two companies are affected, per that report, and the stolen fields were names, home addresses, email addresses and phone numbers. Both makers warned customers to stay alert to phishing aimed at those numbers and inboxes. The breaches sat outside the devices: what the couriers held was contact and delivery data, and the hacks did not affect the security of the wallets themselves, per that report.
Which is precisely why it is worth attention. A courier record that pairs a full home address with a hardware wallet order is not an ordinary mailing list. It is a filtered index of households that plausibly keep crypto within arm’s reach, sorted by street.
Two threats, ranked
The common one is phishing, and it will not read like spam. It will read like the manufacturer: your model, your order, a firmware advisory, a link inviting you to verify your backup. Anyone holding those leaked fields can open with details you assume only the vendor knows, and that assumption is the whole attack. Both companies flagged this risk themselves, per the report.
The rarer one is physical. TechCrunch frames the exposure of names and home addresses as exposing owners to attacks that take the recovery phrase by force rather than the box protecting it. The absolute counts remain small: the same report cites CertiK on dozens of such cases reported during 2025, up about 75% on the year before. Small and rising is still the reason a leaked address means something different at a wallet maker than it does at a shoe shop.
The briefing, again
No manufacturer, courier, support agent, recovery service or firmware update has ever needed your recovery phrase. Not typed into a page, not photographed, not read aloud on a call, not parked in a cloud note, not entered anywhere a screen can be recorded. A message that asks for it is the attack, whatever letterhead it arrives on.
Past that, three habits. Treat any inbound contact that quotes your order details as hostile until you have verified it through a channel you picked yourself, not one the message handed you. Where it is practical, arrange future deliveries so that the address a device ships to is not the address it lives at. And learn what your model offers by way of a passphrase and a duress PIN before the day you need them, rather than after.
The same instinct that governs what you agree to sign governs what you agree to tell a stranger. Crypto assets carry high risk, and this time the risk arrived by post rather than by chain — so check where your own details sit, and satisfy yourself about any support channel before you answer it.