SafePal breach exposes 40,000 customers as hardware wallet attacks escalate from data leaks to $100 million theft
SafePal has develop into the most recent hardware-wallet provider to endure a safety incident after an authorization flaw uncovered private info from about 40,000 customers.
The Aug. 16 disclosure extends a run of safety issues involving hardware-wallet firms and their customers, together with latest incidents affecting Trezor, Ledger and Coldcard.
Two SafePal failures turned an order-system flaw into a bigger data publicity
SafePal revealed that the breach originated within the firm’s e-commerce infrastructure.
According to the agency, an authorization flaw in its order-tracking system allowed unauthorized entry to buyer information overlaying purchases made between March 2, 2025, and April 11, 2026. The uncovered info included names, e-mail addresses, transport addresses, telephone numbers, and buy particulars.
SafePal stated private keys, restoration phrases, wallet passwords, fee card numbers, and wallet entry weren’t uncovered. It additionally discovered no proof that the flaw itself was used to compromise buyer wallets or steal cryptocurrency.
However, the authorization weak spot was just one a part of the incident.
A separate configuration error had prevented a scheduled cleanup course of from working appropriately between September 2025 and April 2026, leaving older order information within the system for longer than meant.
That failure expanded the pool of knowledge accessible via the authorization flaw and prolonged the affected dataset again to March 2025.
The retention failure additionally conflicts with a SafePal help assertion published in 2020, which stated info related to delivered hardware-wallet orders could be retained for 30 days after which destroyed via a month-to-month cleanup course of.
Together, the 2 failures clarify each how buyer info grew to become accessible and why almost 40,000 information remained accessible: one management failed to prohibit entry, whereas one other failed to delete info that ought to now not have been saved.
Hardware-wallet incidents unfold from data leaks to nine-figure theft
SafePal’s disclosure is the most recent in a collection of safety incidents involving main hardware-wallet suppliers and their customers this 12 months.
In latest weeks, Trezor disclosed {that a} breach at its transport supplier uncovered private info belonging to nearly 14,000 customers, whereas Coldcard customers suffered direct losses after a flaw within the wallet’s key-generation course of allowed attackers to drain Bitcoin from affected addresses. Ledger customers have been additionally affected by an order-data breach involving third-party fee supplier Global-e earlier this 12 months.

The Coldcard incident has produced the biggest monetary loss among the many latest circumstances. More than $100 million in Bitcoin was stolen after a bug left some personal keys insufficiently safe, and funds have been drained throughout a number of assault waves starting in late July.
The different incidents have primarily uncovered buyer info fairly than personal keys, however safety consultants have warned that the stolen data creates one other route for criminals to goal crypto holders.
Binance co-founder Changpeng Zhao pointed out that the breaches exposing names, telephone numbers, emails and supply addresses may improve phishing, social-engineering and physical-security dangers.
Notably, SafePal issued an analogous warning after its personal breach and stated it had already taken down greater than 30 fraudulent web sites and phishing hyperlinks concentrating on customers.
Meanwhile, together with dwelling addresses raises a extra serious physical-security concern as a result of leaked buyer information can establish individuals who bought units generally used to retailer cryptocurrency.
That comes as violent attacks towards crypto holders are already rising. Chainalysis stated so-called wrench attacks, together with kidnappings and residential invasions used to drive victims to switch digital belongings, resulted in about $30 million of reported thefts throughout the first half of 2026. The complete for 2025 reached a file $58 million.
Chainalysis data additionally confirmed that home invasions accounted for 37% of violent crypto attacks recorded in 2026, whereas kidnappings made up greater than half of reported incidents tracked this 12 months.
The latest hardware-wallet incidents have due to this fact produced dangers at a number of ranges. Coldcard customers have already suffered greater than $100 million in direct Bitcoin theft, whereas breaches affecting SafePal, Trezor and Ledger have uncovered info that can be utilized for focused phishing, impersonation and probably bodily attacks.
Taken collectively, the incidents complicate the thought of hardware wallets as a single line of protection. The units might shield personal keys, however customers stay uncovered to firmware failures, buyer databases, and the broader infrastructure surrounding self-custody.
The publish SafePal breach exposes 40,000 customers as hardware wallet attacks escalate from data leaks to $100 million theft appeared first on CryptoSlate.

