Wave of data leaks of cryptocurrency owners. How to protect yourself? – Bitcoin.pl

Within days, a series of security incidents were revealed involving SafePal, Trezor and Israeli broker Bits of Gold. The first two cases alone contain data from at least 53,487 customers. Cryptocurrencies, private keys and seed phrases remained safe, but for some users something was leaked that in practice may turn out to be equally dangerous: names, addresses, telephone numbers and information allowing to associate a specific person with cryptocurrencies.

The largest confirmed incident involves SafePal. The company reported unauthorized access to order data of 39,798 customers. A few days earlier, Trezor confirmed the data leak of 13,689 people after an attack on the logistics company ShipMonk. In parallel, Bits of Gold is investigating a separate incident that potentially revealed, among others: ID numbers, banking information and public wallet addresses.

In none of these cases, there was no confirmed seizure of cryptocurrencies or private keys. The problem lies elsewhere: Today, a criminal can simultaneously receive a name, telephone number, home address and information that the victim is interested in cryptocurrencies or has a hardware wallet. That’s why this series of leaks is much more serious than the lack of lost BTC might suggest.

SafePal: almost 40,000 data customers

SafePal reported on August 16 an incident affecting approximately 39,798 customers. The problem was not a compromise of the wallets themselves, but an authorization error in the order tracking system.

According to the company, the vulnerability allowed access to other customers’ order information between March 2, 2025 and April 11, 2026. The available data included, among others: names, addresses and purchase information.

SafePal emphasizes that seed phrase, private keys, wallet passwords, information about bank accounts, payment cards and identity document numbers have not been disclosed. This means that the incident itself does not give attackers direct access to users’ cryptocurrencies.

However, this does not end the problem, as the company admits that the stolen information can be used for precisely crafted phishing and SafePal impersonation. The manufacturer has already identified and removed over 30 fake websites and phishing links related to the incident. SafePal has fixed the vulnerability and announced additional security measures, and personal data related to order processing will now be stored for a maximum of 90 days.

Trezor: criminals learned the addresses of hardware wallet owners

A few days earlier, a similar problem was revealed by Trezor. This time, the attackers did not get into the infrastructure of the wallet manufacturer, but into the systems of ShipMonk, one of the companies handling its orders.

The full scope of data was leaked for 11,742 customers. This includes name, email address, telephone number and exact shipping address. For another 1,947 people, exposure was limited primarily to name, city and email. In total, the incident concerns approx 13,689 customers.

Trezor emphasizes that its systems have not been compromised and its devices remain secure. Wallet backups and private keys were also not leaked. However, the problem is special precisely because it concerns buyers of devices used to independently store cryptocurrencies.

If someone knows your name, surname, telephone number and the exact delivery address of the hardware wallet, they can most likely assume that a person with digital assets lives at this address. This is a completely different risk category than the classic email address leak.

This is the first time that Trezor has revealed such an incident

According to Trezor, this is the first time since the company’s founding in 2013 that a security breach has exposed customer phone numbers and shipping addresses. The company warns that victims may receive more credible fake e-mails, phone calls, letters and even messages from people impersonating banks, cryptocurrency exchanges or Trezor itself.

The scale of the incident was limited thanks to the data retention policy. Trezor requires logistics partners to delete or anonymize most order information after 90 days, which prevented ShipMonk’s systems from having complete records of everyone who had ever purchased the device.

The company intends to go further. The option is to be launched in the European Union in September 2026 Anonymous Deliverywhich is to allow, among others, to collect the device from a vending machine or point, use neutral packaging and automatically remove shipping identifiers after the package is delivered. This is an interesting change because it shows that hardware wallet manufacturers are starting to treat the privacy of the purchase itself as part of the product’s security.

Bits of Gold: possible leak of much more sensitive data

The third case involves Bits of Gold, one of the largest and longest-standing regulated cryptocurrency entities in Israel. The company reported unauthorized access to an external system used for customer support and data analysis.

According to the findings so far, access could include:

  • name and surname,
  • identification number,
  • e-mail address and telephone number,
  • IP address,
  • bank account details,
  • public cryptocurrency wallet address.

The last element is particularly important, because combining KYC data with a public blockchain address can allow a specific on-chain activity to be assigned to a real person. Bits of Gold also ensures that customer funds, cryptocurrencies, passwords, scans of ID documents, full credit card details and CVV codes have not been compromised. The company has also seen no signs of any use of the potentially exposed data so far.

Did 200,000 leak? Bits of Gold records?

The figure appears on social media and in some industry publications at approximately 200 thousand customerswhose data was supposed to end up in the hands of the attackers. However, at this stage it should not be presented as a confirmed fact.

Bits of Gold did not officially disclose the number of injured. The company serves over 300,000 registered clients, but the message sent to users does not specify how many records were actually read or copied. Therefore, the confirmed number of people affected by the three incidents described may be much higher than 53,487, but cannot be reliably determined at this time.

A common problem: it wasn’t the wallets that were attacked, but the companies around them

The most interesting thing in the whole story is that in none of these cases did the criminals have to break Bitcoin cryptography, steal the seed phrase or take over the wallet hardware itself. In the case of Trezor, the problem occurred with a logistics partner, in SafePal the weak point was the order processing system, and Bits of Gold associates its incident with external software also used by other companies.

This is a classic problem supply chain. A company can secure its keys, servers and products very well, but it still has to use courier services, CRM systems, analytical tools, helpdesk or payment operators. Each such partner becomes another place where user data is located.

In the cryptocurrency industry, the consequences are especially serious because the leak does not just say: “this person bought a product from an online store.” It may say something much more valuable to the criminal: “this person probably has cryptocurrencies and this is their home address.”

The biggest risk doesn’t start with Bitcoin theft

The first threat is phishing. A fraudster who knows the model of the purchased device, name, phone number and address can prepare a message that looks much more credible than typical spam.

It may call you as a “security department”, inform you about an alleged wallet breach and ask you to urgently transfer funds. It may send a fake “seed phrase verification” page or a mailer that looks like the manufacturer’s official correspondence.

One of the most important safety rules applies here: no wallet hardware manufacturer needs your seed phrase to solve a problem with your device or account. If anyone asks you to enter your recovery phrase on a website, send it via email, or provide it during a phone call, consider it an attempted theft.

There is also a much more disturbing scenario

Leaking the exact home address of someone known to have purchased a cryptocurrency storage device also creates potential physical risks. The problem is not purely theoretical, because in recent years the number of robberies and kidnappings targeting cryptocurrency holders has been increasing.

Of course, this does not mean that people in the SafePal or Trezor databases will automatically become targets of criminals. However, it shows why linking a residential address with information about cryptocurrency ownership is much more sensitive than a simple leak of marketing data.

What to do if you use SafePal or Trezor?

There is no need to transfer cryptocurrencies just because your data was included in the leak. Wallets and private keys have not been compromised, so making sudden transfers out of fear may paradoxically increase the risk of making a mistake.

However, in the coming weeks it is worth treating any communication regarding the portfolio with great suspicion. Especially messages that cause time pressure, information about the need to “update”, “verify” or transfer funds to a new address.

Trezor recommends checking messages for official company announcements and absolutely avoiding entering your wallet backup online. SafePal, however, warns against phishing and impersonating its employees. It is also worth assuming that data once leaked can remain in circulation for many years, so a fraud attempt does not have to happen tomorrow or next week.

The paradox of hardware wallets

The hardware wallet is intended to solve one of the biggest problems of cryptocurrencies: the dependence of the security of our funds on a third party. The keys remain offline, the user retains control over Bitcoin, and the bankruptcy of the exchange or hacking of its servers should not be enough to lose funds.

However, recent incidents show a second level of the problem. Can be perfectly secured keysand at the same time much worse protection the identity of their owner.

Trezor, SafePal and Bits of Gold did not lose their customers’ Bitcoins in these incidents. From the user’s point of view, however, this does not mean that nothing serious has happened. In a world where blockchain transactions are public and digital assets can be transferred irreversibly in seconds, the data to answer the question “who owns cryptocurrencies and where do they live?” can be extremely valuable.

Perhaps the next stage of self-custody development will not consist solely in building increasingly safer devices. It will become equally important that their producers know about their customers as little as possible.