When SafePal recently admitted to a major data breach, it closed a frustrating loop for users inside a string of hardware wallet failures that ZachXBT has been tracking in real time.
Three separate incidents have landed back to back: Coldcard was hacked for $40 million, Trezor suffered a major data leak, and now SafePal has confirmed one too. After a customer publicly accused the hardware wallet maker of a data leak back in May, only to be met with a flat denial, the company has now confirmed a genuine breach affecting nearly 40,000 customers, and the timing has left a community that already felt dismissed deeply unwilling to simply move on.
None of this is happening in a vacuum, and ZachXBT has been the one keeping score in public. In a recent post, he laid out the tally plainly: since his warning, Coldcard, a Bitcoin hardware wallet, was hacked for $40 million; Trezor, one of the largest cold wallets, experienced a major data leak; and now SafePal, also one of the largest cold wallets, has experienced a major data leak of its own.
What makes that list land as hard as it does is the sequencing. This isn't three unrelated companies each having an unlucky month in isolation. It's the same category of product, hardware self-custody, failing in three distinct ways, a security exploit, a vendor data leak, and now a second vendor data leak, within a tight enough window that a single running list from one investigator can capture all three. Whatever you make of ZachXBT's broader style, this specific tally is hard to argue with, and it's exactly the kind of pattern that turns three separate news stories into one uncomfortable trend.
SafePal posted the disclosure directly through its official X account, opening with the reassurance that matters most to any hardware wallet user: your seed phrase, private keys, and wallet itself remain secure.
According to the company, the actual point of failure was a flaw in its order-tracking plugin, which led to unauthorized access to a subset of customer information. SafePal said the issue has since been fixed, with additional security measures introduced on top of the patch. The incident affects approximately 39,798 customers who placed orders between March 2, 2025 and April 11, 2026, and the exposed data includes names, email addresses, shipping addresses, phone numbers, and purchase details.

SafePal confirmed it individually notified every affected customer by email, and published a dedicated verification page on their site, letting customers check whether they were impacted using their order ID and shipping country. The company was explicit about what wasn't exposed too: no seed phrases, private keys, wallet passwords, bank details, payment card numbers, or government IDs were involved.


Here's the context that turns this from a routine breach disclosure into a genuine trust problem. Back in May 2026, a SafePal customer publicly reported receiving a phishing email containing accurate, detailed order information tied to their SafePal S1 purchase, complete with order number, purchase date, billing address, and payment method. When they raised it with SafePal support, the company's reported response was a flat denial, with the customer describing being told there was no breach, and no explanation offered for how a scammer had obtained their exact order details regardless.
That earlier denial is exactly why this confirmation is landing as badly as it is. SafePal's support team apparently told at least one affected customer that the company doesn't have access to customer data at all, and that any leak might be the customer's own fault, all while, per the timeline SafePal has now confirmed itself, a genuine breach had already occurred and was already affecting people. That's not a minor communication misstep; it's a company denying a problem existed while, according to its own later disclosure, that exact problem had already happened.
The replies under SafePal's announcement carry a mix of genuine anger and something closer to conspiracy fatigue, and both reactions are worth taking seriously rather than dismissing outright. One user described being contacted by a fake caller posing as SafePal staff who somehow already knew their name, address, and order details, and said they'd flagged the underlying issue to SafePal months before this official confirmation ever went out.
Another commenter pointed to a broader pattern, arguing that at this rate, it feels inevitable that everything crypto-related eventually gets hacked or leaked in some form. A third response captured something genuinely important context for this entire industry: simply holding your own keys doesn't mean the rest of your identity and purchase history are automatically safe, self-custody protects your crypto specifically, not everything a company knows about you as a customer.
There's also a more skeptical thread running through the community, with some users suggesting the timing and pace of recent crypto-adjacent data leaks feels suspicious enough to hint at deliberate manufactured FUD, aimed at spooking retail holders into selling so larger players can accumulate at a discount.
That theory doesn't hold up well against what is actually known here, SafePal's own confirmed timeline, the plugin vulnerability, and the specific customer window all point toward a genuine technical failure rather than a coordinated narrative campaign but the fact that this theory is circulating at all tells you how much trust has already eroded.
SafePal's situation doesn't exist in isolation, and that's part of what makes it worth taking seriously rather than treating as an isolated stumble. Trezor confirmed a strikingly similar breach recently, also tied to a third-party provider, also exposing names, addresses, and contact details rather than wallet credentials, and also affecting tens of thousands of customers. Coldcard, separately, suffered a genuine security exploit rather than a data leak, with a firmware flaw allowing attackers to drain roughly $40 million in Bitcoin from affected wallets. Three of the industry's recognizable hardware wallet brands disclosing serious security incidents within weeks of each other suggests the vulnerability sitting behind these incidents isn't really about any single company's carelessness; it's about how much sensitive shipping and order data hardware wallet makers inherently have to collect just to get a physical device into a customer's hands, and how thin the security often is around the third-party plugins, firmware, and fulfillment tools processing that data.

For anyone who ordered from SafePal within the affected window, the practical guidance is straightforward, even if the trust damage isn't easily undone. Check the company's dedicated verification page directly using your order ID and shipping country to confirm whether you were affected. Since exposed data includes full names, addresses, phone numbers, and purchase history rather than financial credentials, the realistic risk here is targeted phishing and impersonation attempts, not direct financial theft.
SafePal itself reinforced the core rule that matters most regardless of what data was or wasn't exposed: never share your seed phrase, private key, or wallet password with anyone, under any circumstance, especially not to someone who calls claiming to be SafePal support and already knows your personal details, since that combination is precisely what makes these follow-up phishing attempts so convincing.
The honest read here is that SafePal did the right thing in this disclosure itself: transparent scope, a clear affected timeframe, a verification tool, individual notifications, and explicit confirmation that wallet-critical credentials weren't touched. That's a genuinely responsible way to handle a breach once you've decided to actually acknowledge one. The problem is entirely about sequencing.
A company that reportedly denied a customer's breach report months before confirming that exact breach publicly has handed its own community a very reasonable reason to distrust its next statement too, whatever that statement turns out to be. And with ZachXBT now publicly tracking SafePal alongside Coldcard and Trezor as part of the same pattern, this isn't a story that ends when SafePal moves on to its next update. Rebuilding that credibility is going to take more than one well-written disclosure; it's going to take SafePal actually being the company that flags problems early next time, rather than the one that has to be caught denying them first, and rather than the third name added to someone else's running list.
Disclosure: This is not trading or investment advice. Always do your research before buying any cryptocurrency or investing in any services. Follow us on X @nulltxnews