bitcoinbtcmarket-newssecurityhardware-walletsafepaltrezorcoldcard

A Second Hardware Wallet Breach in One Week Raises a Harder Question Than Any Single Hack

August 19, 2026
8 min read

Two of the crypto industry's most trusted hardware wallet brands disclosed customer data breaches within days of each other this week. Neither exposed funds directly. Both expose something else worth taking seriously: how much of your security actually depends on systems that have nothing to do with your seed phrase.

Key Takeaways

  • SafePal disclosed a breach affecting 39,798 customers after a flaw in its order-tracking plugin exposed names, addresses, and purchase data, funds and seed phrases were not compromised, but a threat actor is now actively selling the stolen data on a cybercrime forum

  • Trezor separately confirmed its shipping partner ShipMonk was hacked days earlier, exposing order data for roughly 14,000 customers across seven countries

  • Galaxy Research has assessed that attackers behind the earlier Coldcard exploit likely used unrestricted AI models to identify the underlying vulnerability in the first place

  • Bitcoin holds near $64,400 to $64,700, still range-bound, while Trump's White House crypto summit is underway with concrete outcomes still pending as of this writing, full detail on the summit's setup is in TradeMesa's earlier coverage

Today's Market Snapshot

Bitcoin is trading near $64,400 to $64,700 this morning, holding the recovery ground gained since Monday's lows near $62,600. The asset remains inside the same $63,000 to $65,000 band it's occupied for much of the past week, unable yet to force a decisive break in either direction. Ethereum sits near $1,920, up modestly on the day and ETH continues to hold up better than Bitcoin in relative terms, consistent with the institutional flow divergence covered in yesterday's coverage.

Bitcoin's 52-week range now spans from $57,832 to $126,186, a useful reminder of just how much ground has been given up since last October's peak, even with this week's modest recovery intact. Traders are treating today's session as a holding pattern ahead of two genuine catalysts: whatever emerges from the White House summit after 2:30 p.m. ET, and Wednesday's FOMC minutes, due the same day, which could reset near-term rate expectations independent of anything coming out of Washington's policy conversation.

A Separate, Smaller Incident Worth Flagging Briefly

Away from the hardware wallet story, a Maya Protocol exploit was reported draining assets and significantly reducing the affected liquidity pool's value. Details remain limited as of this writing; worth watching for confirmation rather than treating as settled, but it's a reminder that today's security headlines aren't confined to a single incident type.

What Actually Happened at SafePal

SafePal disclosed the breach Sunday, confirming that an authorization flaw in a third-party order-tracking plugin let unauthorized parties view other customers' order information, names, email addresses, phone numbers, shipping addresses, and purchase details, for anyone who placed an order between March 2025 and April 2026. The company was direct about the boundary: seed phrases, private keys, wallet passwords, and funds were not involved, and it found no evidence any wallet was actually compromised.

That distinction matters, but it isn't the whole story. A threat actor is now advertising the stolen dataset on a cybercrime forum, and SafePal itself warned that attackers could use the leaked details to make phishing attempts look convincingly official, a fake "SafePal support" email referencing your actual name, address, and order history is a meaningfully more effective lure than a generic one. SafePal is backed by Binance Labs, and going forward says it will retain customer order data for only 90 days rather than indefinitely, a real, if overdue, fix to the underlying exposure window.

Trezor's Breach Wasn't SafePal's, and That's the Point

Days before SafePal's disclosure, Trezor confirmed a separate incident: its shipping partner, ShipMonk, was hacked, exposing order information for roughly 14,000 customers across seven countries. Different company, different vendor, same underlying pattern, a hardware wallet maker whose actual device security held up, undone at the edges by a third-party system handling something as mundane as shipping logistics.

Two unrelated companies disclosing customer-data breaches inside the same week isn't necessarily coordinated, but it's a real signal worth naming plainly: the weakest point in hardware wallet security increasingly isn't the wallet itself. It's the surrounding business infrastructure, order systems, shipping vendors, customer databases, that most users never think about because it has nothing to do with their actual keys.

The Coldcard Story Just Got a New, Uncomfortable Detail

TradeMesa has covered the Coldcard hardware wallet exploit extensively as it escalated past $130 million in losses. One new detail from Galaxy Research this week is worth flagging on its own: attackers likely used unrestricted AI models to help identify and exploit the underlying firmware vulnerability. If accurate, that's a real shift in how these vulnerabilities get found, not a lone researcher patiently auditing five-year-old firmware line by line, but AI-assisted vulnerability discovery applied at a scale and speed that changes the threat model for every device running similarly aged code, not just Coldcard's.

Taken together, three distinct hardware wallet incidents in a matter of weeks, Coldcard's device-level exploit, and now two separate customer-data breaches at SafePal and Trezor's shipping partner, describe a genuine pattern rather than isolated bad luck. None of them argue against self-custody as a concept. They argue for treating every layer around your keys, not just the keys themselves, as part of your actual security posture.

Read full

Coldcard article →

What This Actually Means for Your Own Setup

None of this week's incidents argue for abandoning self-custody, they argue for being specific about what you're actually protecting against. Three practical distinctions are worth applying directly, rather than treating "hardware wallet security" as a single, undifferentiated concern.

Separate your key security from your account security. A breach at the company level, an order database, a shipping vendor, a customer support system, doesn't touch your seed phrase if you've never entered it anywhere except your own device. That's precisely why SafePal and Trezor's incidents this week, serious as they are, remain fundamentally different from Coldcard's, and it's worth knowing which category any future headline actually falls into before reacting to it.

Treat unsolicited "support" contact as a red flag by default, especially now. With genuine customer order data circulating from two separate breaches this week, a phishing attempt referencing your real name, address, and purchase history is going to look more convincing than the generic version most people are trained to spot. The rule doesn't change: no legitimate wallet provider needs your seed phrase to resolve a support issue, ever, regardless of how specific or personalized the request appears.

Confirm your firmware is current, and understand what an update does and doesn't fix. Coinkite's own guidance on the Coldcard exploit remains the clearest example: a firmware update patches the vulnerability going forward, but it doesn't repair a wallet whose seed was already generated under the flawed version. If you're on affected hardware and haven't already migrated to a newly generated seed, that's the action this week's news should actually prompt, not just heightened general awareness.

What Was Actually New at the Summit, and What Wasn't

Trump's White House crypto summit is taking place today, bringing together executives from Coinbase, Ripple, Gemini, Robinhood, Polymarket, and Kalshi alongside SEC Chair Paul Atkins and CFTC Chair Michael Selig. TradeMesa covered the summit's full context, why it matters, who's attending, and how it connects to the SEC's stalled Regulation Crypto vote, in detail yesterday; that background hasn't changed today and is worth reading there rather than repeated here.

What is new: Polymarket's own odds on CLARITY Act passage in 2026 have settled around 20% today, a different specific figure than Galaxy Digital's own 10% estimate from earlier this week, worth noting as two distinct sources rather than a contradiction, prediction markets and analyst estimates don't always converge on the same number, and the gap itself is informative about how much genuine uncertainty remains. As of this writing, the summit's concrete outcomes, any actual statements or rulemaking signals, hadn't yet emerged; markets are watching the period after 2:30 p.m. ET specifically for that.

For future updates follow TradeMesa Market News →

A Real Institutional Signal, Away From Washington

One quieter development this week deserves attention on its own. Bank Leumi, Israel's largest bank, announced a partnership with Galaxy to offer Bitcoin, Ether, and Solana trading through its investment app starting in early 2027, reportedly reaching roughly a quarter of Israel's crypto-active users through existing banking infrastructure. It's a slower-moving story than a Washington summit, but arguably a more durable one: a major, established bank building direct crypto access into a product millions of people already use, rather than requiring a separate exchange account entirely.

Where This Leaves Traders

Nothing this week changes crypto's fundamentals, but it sharpens a distinction worth internalizing. Device-level security and account-level security are genuinely different problems; a hardware wallet can be cryptographically sound while the company selling it still handles your name and address through a third-party system with its own separate vulnerabilities. Reviewing how self-custody actually works, including what a breach like this does and doesn't expose, is worth doing now rather than after a phishing attempt referencing your real order history lands in your inbox.

Browse Verified Analyst published

Crypto Trading Signals →

This article covers market conditions as of publication time, ahead of today's SEC vote and Retail Sales release, and does not constitute financial advice. Crypto markets are highly volatile. Full Risk Disclaimer →

The TradeMesa Editorial Team consists of experienced writers, researchers, and trading specialists who create and review educational content covering crypto and forex markets, trading strategies, risk management, and platform guides. Our content is researched, fact-checked, and regularly reviewed to maintain accuracy and relevance.

Ready to Trade
on Verified Information?

Create a free account and browse the entire signal feed and course library before spending anything. Find something worth your attention, unlock it once, and keep it for good.

No credit card required · Tokens never expire

⚠ Financial Risk Disclaimer

Trading financial instruments including cryptocurrencies, foreign exchange, and stocks carries a high level of risk and may not be suitable for all investors. The value of investments can decrease as well as increase. You may lose more than your initial investment. Past performance of trading signals is not indicative of future results. Nothing published on TradeMesa constitutes financial advice, an investment recommendation, or a solicitation to buy or sell any financial instrument. TradeMesa is not a licensed financial advisor, broker, or investment firm. Always conduct your own research and consult a qualified financial advisor before making trading decisions. Only invest capital you can afford to lose.