SafePal Breach Exposes Personal Data of Nearly 40,000 Bitcoin Wallet Users

Quick Reads:
- Nearly 39,798 SafePal customers had names, emails, addresses, and phone numbers exposed
- The leak stems from a flaw in an order-tracking plug-in, not from wallet credentials
- Seed phrases, private keys, and payment details were reportedly untouched
- The breach follows a troubling pattern of wallet-related data leaks in 2026
- Chainalysis reports over $30 million stolen in wrench attacks so far this year
The SafePal bitcoin wallet data breach has sent fresh shockwaves through the crypto community after the company confirmed that a vulnerability in its order-tracking plug-in exposed sensitive customer information. According to a statement SafePal posted on X, the compromised data includes names, email addresses, shipping addresses, phone numbers, and purchase details tied to orders placed between March 2, 2025, and April 11, 2026.
While SafePal was quick to clarify that wallet credentials such as seed phrases, private keys, and passwords remained secure, the nature of the leaked information is what has security experts worried. When home addresses are paired with proof of crypto ownership, it creates a dangerous roadmap for criminals engaging in so-called “wrench attacks,” a term used to describe physical coercion aimed at forcing victims to hand over their digital assets.
The timing of this incident couldn’t be more concerning. Chainalysis has already documented 46 violent crypto-related incidents in just the first half of 2026, with losses exceeding $30 million, putting the year on track to be one of the worst on record for physical crypto crime.
SafePal, which is backed by Binance and Animoca Brands and claims to serve roughly 30 million users worldwide, says it has patched the vulnerability, notified affected customers, and launched a dedicated page for users to check whether their data was compromised. The company has also urged users to remain vigilant against potential phishing attempts that may follow.
This isn’t an isolated case. Just days before the SafePal incident, hardware wallet company Trezor disclosed a separate breach through its shipping partner ShipMonk, affecting close to 13,700 customers. And the industry hasn’t forgotten Ledger’s infamous 2020 leak, which exposed roughly 272,000 users and led to a wave of phishing attempts and even direct ransom threats against some victims.
As self-custody adoption grows, incidents like the SafePal bitcoin wallet data breach highlight a critical blind spot: even when core wallet security holds strong, third-party systems like order-tracking or shipping partners can become the weak link that puts users’ physical safety at risk.
SafePal has apologized to its community and promised continued updates via its official blog as investigations proceed.





