TL;DR
- SafePal revealed that a flaw in an order tracking plugin exposed personal data of approximately 39,798 customers.
- The leaked information includes names, emails, shipping addresses and phone numbers; no private keys or seed phrases were compromised.
- Chainalysis documented 46 physical attacks linked to cryptocurrencies in the first half of 2026, with over $30 million stolen, putting the year on track for an annual record.
SafePal confirmed that a vulnerability in an order tracking plugin allowed unauthorized access to personal information of approximately 39,798 customers. This latest security breach exposes hardware wallet users to the risk of being physically located and attacked. The company published a statement on X detailing that the compromised data corresponds to orders placed between March 2, 2025 and April 11, 2026.
The exposed information includes names, email addresses, shipping addresses, phone numbers and purchase details. The company, however, stressed that wallet credentials remain intact: seed phrases, private keys, passwords, banking data, card numbers and identity documents were not affected.
Dear community,
While your SafePal wallet, seed phrase, and private keys are secure; we identified a flaw in the order-tracking plug-in that led to unauthorized access to information of a subset of customers.
The issue has been fixed with additional security measures…
— SafePal – Crypto Wallet (@SafePal) August 16, 2026
SafePal is a non-custodial wallet suite backed by Binance and Animoca Brands that claims to have 30 million users. The platform stated that the issue has already been fixed, that it notified affected users by email and that it launched a page to verify exposure.
SafePal: The Specter of Wrench Attacks
Although no funds were directly stolen, the leak of names, real home addresses and evidence of cryptocurrency holdings is exactly the type of data that can direct criminals toward high-net-worth holders. Chainalysis documented 46 violent incidents in the first half of 2026, with over $30 million stolen, and projected that the year is on track to become the worst on record for this type of attack: home invasions are increasingly outpacing kidnappings.
The Track Record of Exploits in the Wallet Industry
The SafePal case adds to a long list of breaches affecting companies in the sector. Days earlier, Trezor reported that a breach at its logistics partner ShipMonk compromised data of approximately 13,700 customers.
The most severe precedent remains that of Ledger: a breach recorded in 2020 exposed the information of approximately 272,000 users. This triggered a wave of phishing attacks and physical violence threats against some of those affected.
The situation for self-custody users is already dire enough, further shaken by the Coldcard exploit, where Bitcoin was stolen through a firmware entropy flaw and pushed industry losses toward $130 million. SafePal offered apologies to its community and announced that it will publish updates on its blog as the investigation progresses.







