SafePal, a manufacturer of cryptocurrency hardware wallets, has confirmed a data breach affecting nearly 40,000 customers. The company disclosed on Sunday that personal information of individuals who placed orders between March 2, 2025, and April 11, 2026, was compromised. Stolen data includes names, email addresses, shipping addresses, phone numbers, and purchase specifics.
The breach stemmed from a flaw identified in the order-tracking function of a plug-in used for customer order information. SafePal stated that under specific conditions, this vulnerability allowed unauthorized access to other customers' order details. The company has since remediated the issue. SafePal emphasized that the security of its hardware wallets, seed phrases, and private keys remains unaffected.
All impacted customers have received email notifications, and SafePal has established a website where users can verify if their information was compromised. The company issued a warning that affected individuals are likely targets for sophisticated phishing attempts, which may include fraudulent phone calls, emails, text messages, fake refund offers, and deceptive customer support communications.
This incident follows recent security issues at other hardware wallet manufacturers, including Trezor and Coinkite, which also saw customer data exposed. A hacker reportedly advertised information allegedly stolen from SafePal on a dark web cybercriminal forum.
Data breaches involving cryptocurrency holders are particularly concerning due to the risk of "wrench attacks," a term for violent, in-person incidents where individuals are coerced into surrendering their digital assets. According to blockchain security audit firm CertiK, the first half of 2026 has seen a 33% year-over-year increase in such attacks, with 52 incidents reported globally through June, up from 39 in the same period of 2025. Losses from these attacks have reached $124 million this year, a significant increase from $10.5 million in the first half of 2025.






