Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
SafePal data breach exposes personal information of nearly 40,000 crypto wallet customers
00

SafePal data breach exposes personal information of nearly 40,000 crypto wallet customers

Aug 16, 2026

Cryptocurrency wallet provider SafePal disclosed a data breach on August 16, 2026, that exposed the personal order details of 39,798 customers. While digital assets, private keys, and passwords remained secure, the leak of physical addresses and phone numbers has raised concerns over targeted phishing and physical "wrench attacks." The breach, caused by an authorization flaw in a third-party order-tracking plug-in, follows a similar leak of 13,689 Trezor customer records just three days prior.

SafePal data breach incident

  • ▪The SafePal data breach did not compromise cryptocurrency funds, seed phrases, private keys, wallet passwords, bank details, payment card numbers, or government-issued identification.
  • ▪The SafePal data breach affected customers who placed orders between March 2, 2025, and April 11, 2026, exposing names, physical addresses, email addresses, phone numbers, and purchase details.
  • ▪Cryptocurrency wallet provider SafePal disclosed a data breach on August 16, 2026, that exposed the personal order information of 39,798 customers.
  • ▪A threat actor is advertising the stolen SafePal customer records for sale on a cybercrime forum, using order IDs and shipping countries to verify the data.

Third-party plug-in vulnerability

  • ▪The vulnerability that caused the SafePal data breach is characterized as an insecure-direct-object-reference bug sitting in a bolt-on tool.
  • ▪The SafePal data breach was caused by an authorization flaw in a third-party order-tracking plug-in that allowed attackers to view other customers' order details by manipulating order numbers.

Physical targeting of holders

  • ▪Chainalysis recorded 46 violent cryptocurrency robberies globally through late June 2026, resulting in approximately $30 million stolen, compared to $58 million stolen in all of 2025.
  • ▪Leaked physical addresses of cryptocurrency holders raise the risk of physical "wrench attacks," where criminals coerce victims in person to hand over their digital assets.

SafePal breach response measures

  • ▪SafePal patched the authorization flaw immediately, emailed affected users on August 16, 2026, and provided a tool for customers to check if their details were leaked.
  • ▪SafePal identified and removed more than 30 fraudulent websites and phishing links associated with scam activities following the data breach.
  • ▪SafePal reduced its personal data retention window in the order-processing environment to 90 days and engaged an independent security firm to validate its security fix.

Hardware wallet customer leaks

  • ▪The ShipMonk data breach affecting Trezor customers was the first leak of its kind for Trezor since the company was founded in 2013.
  • ▪Trezor disclosed on August 13, 2026, that a data breach at its fulfillment partner ShipMonk exposed the personal details of 13,689 customers.

3 sources

Thedefiant
SafePal Breach Exposes 39,798 Buyers as Stolen Records Hit Cybercrime Forum
View source article
Thenextweb
SafePal breach leaks the addresses but not the crypto, which may be the bigger problem
View source article
Businesstimes
Crypto wallet provider SafePal discloses data breach affecting nearly 40,000 users’ order information
View source article

Story comments

Loading comments…

Related Projects

SafePalBinance

Topics

Bitcoin wallets & custodyCryptoCrypto privacy & surveillanceCrypto security