SafePal Says Order-Tracking Bug Exposed Data of 39,798 Customers
Key Takeaways
- •SafePal said attackers accessed personal information for roughly 39,798 customers through an order-tracking plug-in flaw.
- •The exposed data included names, email addresses, shipping addresses, phone numbers and purchase details.
- •SafePal said wallet credentials, seed phrases, private keys, bank details, payment card numbers and government IDs were not affected.
- •The company said it fixed the issue, emailed affected customers and created a page for users to check exposure.
- •The breach comes amid growing concern that leaked customer data can help criminals target crypto holders physically.

SafePal disclosed that an order-tracking plug-in flaw gave attackers access to personal data, including names, email addresses, shipping addresses, phone numbers and purchase details, for roughly 39,798 customers.
The exposed mix of home addresses and proof of crypto ownership raises the risk of physical targeting as wrench attacks increase, with Chainalysis documenting 46 violent incidents and more than $30 million stolen in the first half of 2026, putting the year on pace for a record.
SafePal joins a growing list of wallet companies affected by leaks. Trezor's recent ShipMonk breach exposed data on about 13,700 customers, while Ledger's 2020 leak of roughly 272,000 customers led to ransom threats.
Bitcoin and crypto wallet maker SafePal said Saturday that a flaw in an order-tracking plug-in gave attackers unauthorized access to the personal information of roughly 39,798 customers, the latest breach to put users of a hardware wallet company at risk of physical targeting.
In a statement posted to X, SafePal said the exposed data covers customers who placed orders between March 2, 2025, and April 11, 2026 — a window spanning more than 13 months — and includes names, email addresses, shipping addresses, phone numbers and purchase details.
The company said wallet credentials were not affected, adding that seed phrases, private keys, wallet passwords, bank details, payment card numbers and government IDs were not involved. Because SafePal's wallets are non-custodial, users rather than the company hold their private keys and funds; customer records of this kind typically sit in order-fulfillment systems rather than the wallet product itself. SafePal, a non-custodial wallet suite backed by Binance and Animoca Brands that says it serves 30 million users, said it has fixed the issue, notified affected customers by email and created a page for users to check whether they were exposed.
Beware of phishing attempts! 👇 Disclosure: SafePal is a YZiLabs portfolio company (minority investor). — CZ 🔶 BNB (@cz_binance) August 16, 2026
While no funds were directly stolen, the combination of names, home addresses and evidence of crypto ownership is the kind of data that can help criminals identify high-net-worth holders. That concern has grown alongside the rise of so-called wrench attacks, in which victims are threatened or assaulted until they hand over their crypto.
Chainalysis documented 46 violent incidents in the first half of 2026, with more than $30 million stolen, and said the year is on track to be the worst on record, with home invasions increasingly overtaking kidnappings.
SafePal now joins a broader set of wallet firms whose customers have been exposed through leaks. Just days earlier, Trezor said a breach at shipping partner ShipMonk compromised data on about 13,700 customers. The most prominent example remains Ledger, whose 2020 leak of some 272,000 customers' details triggered a wave of phishing and, for some, ransom threats that invoked violence.
The timing adds to a tense stretch for self-custody users, still dealing with the Coldcard exploit that drained long-dormant Bitcoin through a firmware entropy flaw and pushed industry-wide losses toward $130 million.
SafePal apologized to its community and said it will post updates on its blog as its investigation continues.