A string of security problems has recently affected several prominent hardware wallet brands, drawing attention from the cryptocurrency community. Crypto researcher Stacy Muur highlighted the pattern in a recent post, noting incidents involving Coldcard, Trezor, and SafePal in relatively close succession following commentary from on-chain investigator ZachXBT.
The timing has raised eyebrows among observers tracking self-custody risks.
The latest development involves SafePal, a widely used non-custodial wallet provider backed by major industry players.
Since this @zachxbt post:
• Coldcard – a Bitcoin hardware wallet, was hacked for $40 million.
• Trezor – one of the largest cold wallets, experienced a major data leak.
• SafePal – one of the largest cold wallets, experienced a major data leak.Incredible timing. https://t.co/OGq1YfkMCT pic.twitter.com/eq8f9oRYOm
— Stacy Muur (@stacy_muur) August 16, 2026
On August 16, 2026, the company disclosed that a vulnerability in its order-tracking plug-in allowed unauthorized external access to certain customer order data.
The flaw, related to authorization checks in the system handling purchase records, affected roughly 39,798 individuals who ordered products between March 2, 2025, and April 11, 2026.
Exposed details consisted of personal identifiers such as full names, email addresses, physical shipping addresses, phone numbers, and specifics about the purchases themselves.
Critically, the company stressed that core wallet security elements remained untouched.
Seed phrases, private keys, device passwords, banking details, payment card numbers, and official identification documents were not part of the compromised information.
SafePal emphasized that its architecture keeps sensitive cryptographic material isolated from e-commerce systems.
Upon discovering the issue, the team promptly corrected the authorization weakness and added further protective controls.
An independent security firm has been brought in to review the fix and examine the broader order-processing setup.
The company also shortened data retention periods in the relevant systems to 90 days where legally permissible, notified every impacted customer via individual emails from a dedicated security address, and launched an online verification tool.
Users can enter their order identifier and shipping country on the official site to confirm whether their records were involved.
SafePal has taken down more than 30 phishing sites and domains linked to potential follow-on scams and continues active monitoring.
It has opened a specialized support channel for those affected and is coordinating with logistics partners to ensure the problem did not extend further.
The firm issued strong guidance against sharing recovery phrases or credentials under any circumstances and urged vigilance against unsolicited contacts that might reference the leaked order information.
This disclosure arrives amid other high-profile challenges for hardware wallet makers.
Coldcard, a Bitcoin-focused cold storage device, suffered a major exploit stemming from an older firmware flaw that weakened seed generation entropy.
Attackers were able to recreate private keys remotely and drain substantial amounts—reports place losses in the range of tens of millions of dollars, with figures climbing past $100 million across multiple waves of activity beginning in late July 2026.
Around the same period, Trezor faced a separate incident in which a third-party fulfillment partner experienced unauthorized system access.
That event exposed names, contact details, phone numbers, and shipping addresses for nearly 14,000 customers, primarily those receiving devices in recent months across several countries.
Trezor’s own systems and devices were not compromised, but the leak elevated phishing risks.
Community voices have pointed to the concentration of these events as noteworthy.
While the underlying causes differ—ranging from firmware entropy issues and third-party logistics breaches to an internal order-tracking authorization gap—the cumulative effect has fueled discussion about the resilience of the broader hardware wallet ecosystem.
Personal data exposure, even without direct key compromise, creates avenues for sophisticated social engineering that can still threaten users’ assets.
Hardware wallets remain a cornerstone of self-custody strategies for many, valued for keeping private keys offline.
Yet these successive incidents underscore that peripheral systems—order processing, shipping partners, and supporting software—introduce additional attack surfaces.
Users are advised to treat any unexpected outreach referencing past purchases with extreme caution, verify communications only through official channels, and maintain strong operational security practices.
Providers continue issuing updates and remediation steps. The community will likely watch closely for further disclosures and independent audits as the sector responds to these overlapping challenges.