Subscribe Now
Trending News

Blog Post

54,000 HARDWARE WALLET BUYERS JUST GOT DOXXED — TREZOR AND SAFEPAL HANDED THE PHISHERS YOUR HOME ADDRESS
News

54,000 HARDWARE WALLET BUYERS JUST GOT DOXXED — TREZOR AND SAFEPAL HANDED THE PHISHERS YOUR HOME ADDRESS 

You bought a hardware wallet to get out of the system. Congratulations. The company that sold it to you just handed the scammers your name, your phone number, and your home address.

Trezor admitted this week that its shipping partner ShipMonk got hacked. Roughly 14,000 customers are exposed. Names. Addresses. Emails. Phone numbers. Buyers in the US, UK, Sweden, Colombia, Brazil, Italy and Portugal who ordered between May 10 and August 8 are now sitting targets for phishing scams — and Trezor itself warned this is the first time its customers’ shipping data has ever been compromised.

That’s the Trezor breach. The same week, SafePal confessed that a flaw in its order-tracking plugin leaked the personal data of nearly 40,000 customers — 39,798 to be precise. Names, contact info, shipping addresses, purchase history. And here’s the part that should make you furious: SafePal said it first learned about the problem in MAY. It waited until August 16 to tell anyone. Three months. Your data was floating in the wind for three months while the company fiddled with its plugin.

Neither company lost your seed phrase. Your keys are safe. Great. But that’s exactly the problem — they keep telling you your coins are safe while the scammers just learned exactly where you live.

This is the dirty secret of the hardware wallet industry: your wallet is cold, but your identity is a marketing database. Trezor knows who you are. SafePal knows who you are. The shipping company knows who you are. And the phishers who stole that data now know who you are. A ‘cold’ wallet does nothing against a phishing email that names your street, your city, your order date and your exact wallet model. That’s social engineering on a silver platter.

Worse: this is a physical attack vector, not just a digital one. Your name plus your address plus your known Bitcoin holdings is a wrench-attack checklist. The French tax authority leak that exposed 678,000 records and the Coldcard wallet exploit that drained over $112 million already proved the pattern — the more personal data the system holds on you, the closer the attackers get to your coins. Now the wallet vendors themselves are the leak.

The crowd that says “not your keys, not your coins” is only half right. If your wallet vendor keeps a file on you, then it’s not your data either. Read our guide on choosing a Bitcoin wallet and think about how much identity every option really requires.

Hardware wallets are still the right answer for storing keys. The wrong answer is handing the vendor your entire identity to buy one. That is the part of the supply chain nobody audits, nobody secures, and nobody apologizes for — until 54,000 people are exposed in a single week.

If you’re going to hold your own coins, buy them without feeding the data machine. Bull Bitcoin lets you buy Bitcoin and hardware wallets without the surveillance pile. Use coupon code LOVEISBITCOIN and go to https://loveisbitcoin.com/bull — self-custody without the data hoarding.

So tell me: your wallet company knows where you sleep. Your shipping provider knows what you bought. The phishers now know both. Still think “cold” means safe?

Previous

54,000 HARDWARE WALLET BUYERS JUST GOT DOXXED — TREZOR AND SAFEPAL HANDED THE PHISHERS YOUR HOME ADDRESS

Related posts

Leave a Reply

Please authenticate to comment:

Required fields are marked *

⚡ Zap This!

Support this content with sats on Nostr

Zap QR

Lightning Address (tap to copy):

✅ Copied!

Or zap via Nostr client:

🟣 Open in Primal