In short
- SafePal disclosed that an order-tracking plug-in flaw gave attackers entry to non-public information—names, emails, transport addresses, telephone numbers and buy particulars—for roughly 39,798 clients.
- The uncovered mixture of addresses and proof of crypto possession raises the chance of bodily focusing on as wrench assaults surge, with Chainalysis documenting 46 violent incidents and over $30 million stolen within the first half of 2026, on tempo for a document 12 months.
- SafePal joins a string of pockets corporations hit by leaks—Trezor’s current ShipMonk breach uncovered ~13,700 clients, and Ledger’s 2020 leak of ~272,000 led to ransom threats.
Bitcoin and crypto pockets maker SafePal mentioned Saturday {that a} flaw in an order-tracking plug-in gave attackers unauthorized entry to the non-public data of roughly 39,798 clients, the newest breach to place a {hardware} pockets firm’s customers liable to being bodily focused.
In an announcement posted to X, SafePal mentioned the uncovered information spans clients who positioned orders between March 2, 2025, and April 11, 2026, and contains names, e-mail addresses, transport addresses, telephone numbers, and buy particulars.

The corporate careworn that pockets credentials themselves have been untouched, saying seed phrases, non-public keys, pockets passwords, financial institution particulars, cost card numbers and authorities IDs weren’t concerned. SafePal, a non-custodial pockets suite backed by Binance and Animoca Manufacturers that claims it serves 30 million customers, mentioned it has fastened the difficulty, notified affected clients by e-mail, and arrange a web page to verify publicity.
Whereas no funds have been instantly stolen, the combo of names, dwelling addresses, and proof of crypto possession is exactly the form of information that may steer criminals towards high-net-worth holders. That concern has sharpened alongside an increase in so-called wrench assaults, by which victims are threatened or assaulted till they give up their crypto.
Chainalysis documented 46 violent incidents within the first half of 2026 with greater than $30 million stolen, calling the 12 months on tempo to be the worst on document, with dwelling invasions more and more overtaking kidnappings.
SafePal joins a rising checklist of pockets corporations whose clients have been uncovered by way of leaks. Simply days earlier, {hardware} pockets maker Trezor disclosed {that a} breach at transport associate ShipMonk compromised information on roughly 13,700 clients. The clearest cautionary story stays Ledger, whose 2020 leak of some 272,000 clients’ particulars led to a wave of phishing and, for some, ransom threats invoking violence.
The timing provides to a jittery stretch for self-custody customers nonetheless shaken by the Coldcard exploit, which drained long-dormant Bitcoin by way of a firmware entropy flaw and pushed industry-wide losses towards $130 million.
SafePal apologized to its group and mentioned it will put up updates on its weblog as its investigation continues.
Every day Debrief E-newsletter
Begin day-after-day with the highest information tales proper now, plus authentic options, a podcast, movies and extra.
