In a stark reminder that hardware wallets are not an island of security, SafePal, one of the most widely used self-custody hardware wallet brands, has disclosed a data breach affecting approximately 40,000 customers. The incident, which came to light in late August 2026, reveals that the company’s e-commerce order tracking system suffered from a broken access control vulnerability, allowing unauthorized access to personally identifiable information (PII) including names, email addresses, physical addresses, phone numbers, and purchase details. Adding to the severity, SafePal admitted that a scheduled data cleanup process, designed to delete customer data 30 days after order delivery, was misconfigured and had failed to execute for over a year, leaving customer records exposed far longer than promised.
This breach is not an isolated event. It is part of a troubling pattern of escalating security failures across the hardware wallet industry. Just weeks earlier, Ledger and Trezor disclosed separate data leaks through third-party service providers, and Coldcard—a brand previously considered a gold standard for air-gapped security—revealed a critical vulnerability in its key generation process that led to the theft of over $100 million in Bitcoin. Together, these incidents shatter the long-held assumption that hardware wallets are a bulletproof solution for crypto self-custody.
The SafePal Incident: A Failure of Web2 Hygiene in a Web3 World SafePal’s explanation points to two independent technical failures. The first was an authorization flaw in the order tracking system, which allowed an attacker to query customer data without proper authentication. The second was a configuration error in the monthly data cleanup routine, which meant that even after SafePal promised to delete records after 30 days, the data remained in the system for more than a year. The combination of these two mistakes allowed the attacker to extract a large volume of PII before the vulnerability was discovered and patched.
Crucially, SafePal emphasized that private keys, recovery phrases, wallet passwords, and payment card numbers were not compromised. The breach was limited to the company’s e-commerce infrastructure, not the wallet firmware or the hardware itself. Yet the implications are far-reaching. With 40,000 user profiles now in the hands of malicious actors, the risk of targeted phishing, social engineering, and even physical attacks has increased dramatically. As one security expert quoted in the report noted, “The data is a roadmap for attackers. They know who owns crypto, where they live, and what hardware they use.”
The Broader Industry: A Pattern of Infrastructure Leaks The SafePal breach is the fourth such incident in a string of hardware wallet data leaks. Trezor’s leak originated from a third-party shipping provider, exposing customer names and addresses. Ledger’s leak was traced to a payment processor, Global-e, revealing order histories and contact details. These incidents share a common thread: the weakest link is not the hardware itself but the centralized Web2 infrastructure that surrounds it—order management systems, logistics partners, and payment gateways.
Coldcard’s vulnerability stands apart in both severity and nature. The flaw was in the wallet’s key generation process, where a weakness in the random number generator (RNG) reduced the entropy of private keys, making them theoretically predictable. The result was a direct loss of over $100 million in Bitcoin, as attackers were able to derive private keys from the compromised entropy. This is the most dangerous type of hardware wallet vulnerability because it bypasses all user precautions: even a perfectly executed offline setup could still produce an insecure private key.
The Unspoken Risk: From Data Leak to Physical Threat The most alarming aspect of these data breaches is the chain reaction they can trigger. The leaked PII includes home addresses, which are invaluable for criminals who engage in physical attacks. Chainalysis data cited in the report shows that in the first half of 2026 alone, there were approximately $30 million in crypto thefts involving violent attacks, including home invasions and kidnappings. This represents a 50% increase over the annual rate of $58 million in 2025. The SafePal breach adds 40,000 potential targets to this ecosystem.
Binance founder Changpeng Zhao (CZ) weighed in on the situation, warning that the combination of data leaks and physical attack vectors is a serious threat. “The industry needs to take user data protection as seriously as smart contract security,” he said in a statement. “A hardware wallet can protect your keys, but it cannot protect your home address.”
Contrarian View: The Narrative of Absolute Security Is a Liability For years, the marketing narrative of hardware wallets has been that they offer “absolute security” for self-custody. The ledger never lies, only the narrative does. These incidents prove that security is not binary: it is a system of interdependent components, and the weakest link often resides outside the device. The belief that cold storage is invulnerable has led users to let their guard down on peripheral security—such as securing their email accounts, using unique passwords, and being skeptical of unsolicited communications.
Moreover, the data suggests that the main risk to users is not a flaw in the wallet’s cryptographic design but the human and organizational failures around it. SafePal’s cleanup failure is a classic case of security debt: a process that was supposed to run automatically was never properly tested or monitored. Similarly, Trezor and Ledger’s reliance on third-party vendors without rigorous security audits reflects a systemic oversight.
Evidence and Next Steps The SafePal incident is a clear violation of data minimization principles. The company’s own policy promised deletion after 30 days, but the actual retention exceeded one year. This could trigger regulatory action under GDPR (for European users) or Singapore’s PDPA, potentially resulting in fines equal to a percentage of global revenue. Coldcard faces even more severe liability: its key generation flaw may lead to class-action lawsuits, as users who lost funds argue that the product was defective.
For users, the immediate action is to be vigilant for phishing attempts. SafePal has already identified over 30 fake domains impersonating its site. Users should also consider using a passphrase wallet or multi-signature setup to add layers of protection. The silence from the industry on these issues has been a warning sign in itself. As one analyst put it, “Chaos in the market is just noise without context. The context here is that the security model of self-custody is being stress-tested, and it is failing in new ways.”
Takeaway Hardware wallets remain a critical tool for self-custody, but they are not a panacea. The industry must evolve from focusing solely on device-level security to embracing a holistic security architecture that includes data lifecycle management, third-party vendor auditing, and user education. The ledger never lies, but the infrastructure around it can. The next test will be whether the industry can rebuild trust by treating data security with the same rigor as key generation.
Over the next quarter, the market will be watching for SafePal’s response to regulatory inquiries, the outcome of Coldcard’s firmware update, and whether Ledger and Trezor adopt stricter vendor controls. Until then, users should assume that their PII is compromised and act accordingly. Trust the hash, question the headline. The hash of this story is that hardware wallets are only as secure as the systems that support them.