The most immediate practical consequence is not an attacker remotely emptying a wallet. It is that names, email addresses, phone numbers, shipping addresses, and—in SafePal’s case—purchase details can make a fraudulent call, email, text message, or physical letter look convincing enough to persuade a victim to reveal the information that actually unlocks funds. Forbes first brought the two disclosures together, but the public record indicates they should be treated as two distinct incidents rather than one confirmed shared breach.
Trezor said on August 13 that a breach at shipping provider ShipMonk exposed full contact and delivery data for 11,742 customers, plus partial data for another 1,947. SafePal subsequently said an order-tracking plug-in flaw exposed records for approximately 39,798 customers who placed orders between March 2, 2025, and April 11, 2026.
The arithmetic behind Forbes’ 53,487 figure checks out: 11,742 fully exposed Trezor records, 1,947 partly exposed Trezor records, and 39,798 SafePal records. But that number is an aggregate of notifications from different companies and does not establish that 53,487 unique people were caught in one campaign, nor that the same attacker accessed both datasets.
Trezor customers face a delivery-data exposure
Trezor says ShipMonk notified it on August 10 of unauthorized access to systems containing customer information. The company says the affected group consists of customers in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal who received an order within the 90 days before August 8.
For the 11,742 customers with full exposure, Trezor says the leaked fields include full name, email address, phone number, and shipping address. The additional 1,947 partially exposed records contained name, city, and email address. Trezor says its own systems and hardware wallets were not compromised, and that its fulfillment-data retention policy limited the scope of the exposure.
That retention claim is worth reading carefully. A 90-day deletion practice may have restricted the amount of shipment data retained by the fulfillment provider, but it did not eliminate risk for customers whose data was still present when the compromise occurred. More importantly, Trezor has acknowledged that some partially exposed records may be tied to older orders while it verifies the precise timeframe with ShipMonk.
Trezor also says orders fulfilled through its official Amazon stores were not part of this incident because they use a different partner. Customers who bought directly through the Trezor Shop and received a notification from the company should assume their contact data was exposed. Customers who did not receive Trezor’s notice should not treat that as a reason to lower their normal guard against wallet scams; it only means they were not identified in this particular notification.
The compromised data does not need to include a recovery seed to be valuable. A caller who knows a customer’s name, street address, phone number, and recent order relationship can plausibly claim to be a Trezor support agent, a delivery company, a bank fraud specialist, or a law-enforcement officer responding to an alleged wallet compromise. The goal will be to get the victim to reveal their recovery phrase, install remote-access software, approve a transaction, or send funds to a supposedly protected address.
SafePal says an order-tracking plug-in was the entry point
SafePal’s disclosure describes a different mechanism: unauthorized access through a flaw in an order-tracking plug-in. The company says the issue has been fixed and that added security measures have been deployed.
SafePal says the affected records included names, email addresses, shipping addresses, phone numbers, and purchase details. That final category creates an additional targeting problem. Unlike a generic list of contact details, purchase data can give an attacker enough context to tailor a believable message around the exact type of product a victim bought, an apparent order date, or a fake replacement-device recall.
The company says private keys, seed phrases, wallet passwords, bank-account information, payment-card numbers, and government-issued identification were not involved. That narrows the immediate technical impact, but it does not mean affected customers can simply disregard the incident. An exposed address and a verified hardware-wallet purchase form a durable profile that cannot be changed as easily as an account password.
SafePal says it has notified affected customers individually and offers an official method for customers to check whether their order was included. Do not reach that tool through a link in an unexpected message. Open a new browser session and manually navigate to SafePal’s official site, or use the vendor’s established support channels from inside its app or official documentation.
The ShipMonk–Metabase connection remains unconfirmed in public reporting
Forbes reported that ShipMonk had received extortion emails from the ShinyHunters group and connected the incident to a critical Metabase SQL-injection zero-day. That link requires caution.
BleepingComputer reported on August 7 that Metabase Cloud and self-hosted Metabase versions 1.58 and later had been targeted through an actively exploited, unauthenticated SQL-injection vulnerability that Metabase rated critical. The flaw could allow an attacker to gain administrative access to a Metabase instance, steal database credentials, access data available through connected sources, and export it. BleepingComputer named Framework and Tally as known affected organizations in that report.
However, BleepingComputer’s Metabase report did not identify ShipMonk as a confirmed victim, and neither Trezor’s public notification nor SafePal’s disclosure attributes its incident to Metabase. ShipMonk has not publicly provided the technical details necessary to independently confirm the Forbes account. Readers should therefore distinguish between three established points and one unverified attribution:
- Trezor has confirmed a ShipMonk-related exposure of customer delivery data.
- SafePal has confirmed an order-tracking plug-in exposure involving customer records.
- Metabase has confirmed active exploitation of a critical SQL-injection vulnerability.
- A direct technical chain connecting ShipMonk’s incident to the Metabase flaw remains attributed to Forbes’ reporting rather than confirmed by the vendors involved.
That distinction matters for enterprise defenders. A breach involving a logistics provider, a storefront plug-in, and an analytics platform can produce similar victim outcomes—highly convincing social engineering—without sharing an attacker, vulnerability, or operational failure. Treating them as one breach risks sending administrators toward the wrong mitigation.
What affected wallet owners should do now
Affected customers should expect attackers to capitalize on the breach notices themselves. A message saying “your data was leaked” is unusually effective bait because it arrives during a real incident and can contain information the attacker legitimately knows.
Use these rules for any message or call that mentions Trezor, SafePal, a wallet update, a shipping problem, account verification, an exchange, or an alleged theft investigation:
- Never enter a wallet recovery phrase, private key, or backup words into a website, chat, form, application, or support ticket. A legitimate wallet vendor will not request them.
- Do not install remote-support tools or browser extensions at the direction of an unsolicited caller or message. Remote-access software can turn a phishing contact into a full device compromise.
- Do not use links, QR codes, attachment files, or phone numbers delivered in an unexpected email, text, direct message, or letter. Independently locate the vendor’s official support channel.
- Treat caller-ID information as untrusted. Phone numbers can be spoofed, and a caller with your address or order details has not proved they represent Trezor, SafePal, a bank, or police.
- Review account passwords and enable phishing-resistant multi-factor authentication where available. Since neither vendor says wallet credentials were exposed, the priority is stopping account takeover through password reuse and social engineering, not changing a seed phrase solely because of this data exposure.
- Ask your mobile carrier about an account PIN or port-out protection, particularly if your exposed phone number is used to receive account-recovery codes.
For Windows users, there is an additional practical layer: keep Microsoft Defender, browsers, and operating-system updates current, but do not mistake patched software for complete protection. The critical decision in these scams is often made before malware ever runs—when a victim discloses recovery words or approves an action after being persuaded by a credible-looking message.
A customer list can outlive the incident
The uncomfortable fact in both disclosures is that stolen contact data cannot be recalled. Trezor’s devices may remain secure and SafePal’s wallets may remain technically uncompromised, but an exposed list can be copied, resold, combined with public records, and reused long after the vendor finishes its investigation.
Chainalysis reported this month that home invasions accounted for 37 percent of documented violent incidents targeting crypto holders during the first half of 2026, up from 26 percent in 2023. That does not mean every exposed customer faces a physical threat, and companies should not use extreme scenarios to create panic. It does mean a hardware-wallet purchase is more sensitive than an ordinary retail transaction because it can identify a household as a possible cryptocurrency holder.
Trezor and SafePal customers should now assume that a polished scam may include real details from their purchase history. The secure response is simple but absolute: a real breach notice never creates a reason to disclose a recovery phrase, transfer assets, or let an unknown person control a PC.