Summary

  • SafePal reported a vulnerability in an order-tracking plug-in that led to the exposure of personal information for approximately 39,798 customers, including names, emails, addresses, and purchase details.
  • This breach heightens the risk of physical attacks, as evidenced by a rise in wrench attacks, with Chainalysis noting 46 violent incidents and over $30 million stolen in the first half of 2026, potentially marking a record year.
  • SafePal is among several wallet providers that have faced data leaks, following incidents involving Trezor and Ledger that compromised thousands of customer records.

SafePal, a Bitcoin and cryptocurrency wallet manufacturer, announced on Saturday that a flaw in an order-tracking plug-in allowed unauthorized access to the personal information of about 39,798 customers. This incident has raised alarms regarding the safety of users of hardware wallets.

According to a statement shared on X, the compromised data pertains to customers who made purchases between March 2, 2025, and April 11, 2026, revealing names, email addresses, shipping addresses, phone numbers, and transaction details.

SafePal reassured users that wallet credentials were not compromised, clarifying that seed phrases, private keys, wallet passwords, bank information, payment card numbers, and government IDs remain secure. The company, which is a non-custodial wallet solution backed by Binance and Animoca Brands and claims to serve 30 million users, has rectified the issue, informed affected individuals via email, and created a webpage for users to check their exposure.

Beware of phishing attempts! šŸ‘‡

Disclosure: SafePal is a YZiLabs portfolio company (minority investor). https://t.co/pCPjTbYWjT

— CZ šŸ”¶ BNB (@cz_binance) August 16, 2026

While no funds were stolen directly, the combination of names, home addresses, and proof of cryptocurrency ownership presents a clear risk, as it may attract criminals targeting high-net-worth individuals. This concern is particularly pronounced given the recent surge in wrench attacks, where victims are coerced or assaulted into surrendering their cryptocurrencies.

Chainalysis has reported 46 violent incidents in the first half of 2026, with losses exceeding $30 million, suggesting that this year could be one of the worst on record, with home invasions increasingly replacing kidnappings.

SafePal's breach adds to a growing list of wallet companies that have suffered data leaks. Just days earlier, Trezor revealed that a breach at its shipping partner, ShipMonk, compromised data for around 13,700 customers. The most notable incident remains Ledger's 2020 leak, which exposed details of roughly 272,000 customers and resulted in significant phishing attempts and ransom threats.

This breach comes at a time of heightened anxiety for self-custody users, especially following the Coldcard exploit, which drained dormant Bitcoin due to a firmware vulnerability and contributed to industry-wide losses nearing $130 million.

SafePal has issued an apology to its users and will provide updates on its investigation through its blog.

Daily Debrief Newsletter

Stay informed with the latest news stories, original features, podcasts, videos, and more.