ZeroHour
The Recordpublished ()ingested

SafePal latest crypto hardware wallet maker affected by breach, with nearly 40,000 impacted

mediumData breach exploited in the wildimportance 55
AI summary · glm-5.3-flash

SafePal confirmed nearly 40,000 customers' order data was stolen, the third hardware wallet maker breached in a month after Trezor and Coinkite.

SafePal confirmed a breach exposing names, emails, shipping addresses, phone numbers, and purchase details of customers who ordered between March 2, 2025 and April 11, 2026, caused by a flaw in an order-tracking plugin. The company stressed wallets, seed phrases, and private keys remain secure, and all impacted customers were notified by email. A hacker advertised the stolen data on a dark web forum, and SafePal warned of targeted phishing via fake support calls and refund offers. CertiK data cited in the report shows 52 wrench attacks worldwide in H1 2026 with $124 million in losses, up 33% year-over-year.

  • Third hardware wallet maker breached in a month, after Trezor and Coinkite
  • Exposed order data enables targeted phishing and wrench-attack risk
  • CertiK counted 52 wrench attacks with $124M losses in H1 2026
  • No seed phrases, private keys, or wallet passwords were compromised
Full article478 words · extracted from therecord.media · click to collapse

The crypto hardware wallet company SafePal confirmed a data breach on Sunday, telling users that nearly 40,000 customers had information stolen during a recent security incident. 

The company said the incident impacted information from people who placed orders between March 2, 2025 and April 11, 2026. The stolen information includes names, email addresses, shipping addresses, phone numbers and purchase details. 

SafePal is the third hardware wallet manufacturer to be attacked over the last month after both Trezor and Coinkite dealt with security issues impacting the information for thousands of customers who own cryptocurrency. 

SafePal did not provide details on how the hackers gained access to the data, only writing in a blog post that the company recently identified a flaw “in the order-tracking function for a plug-in associated with customer order information.” 

“Under certain conditions, the flaw allowed unauthorized access to another customer's order information,” the company said, adding that the issue has since been remediated. 

The company reiterated that all SafePal wallets, seed phrases and private keys are secure. All impacted customers have been notified by email and a website has been created for people to see if they were affected. 

SafePal warned that those impacted will likely be targeted by sophisticated phishing attempts that will include phone calls, emails, texts, refund offers and fake customer support messages. A hacker last advertised information allegedly stolen from the company on a dark web cybercriminal forum. 

People use hardware wallets because they are intended to be a more secure option to store cryptocurrency. Data breaches that reveal details about digital currency holders have the potential to expose them to “wrench” attacks — the industry’s term for in-person, violent incidents where crypto owners are threatened and forced to hand over their digital assets.

According to the blockchain security audit company CertiK, the first half of 2026 has seen a 33 percent year-over-year increase in wrench attacks. Using publicly available information and other verified sources, the company found 52 wrench attacks worldwide through June, up from 39 during the same period in 2025. 

Examples include the kidnapping of a French mother and child in April, a 2025 home invasion in Minnesota and a 2024 case in Connecticut involving a carjacked Lamborghini. The losses have reached $124 million so far this year, compared with $10.5 million reported in the first half of 2025. 

Last week, a cryptocurrency investor Harry Chun Tak Yeh was found dead after falling from his luxury 30th floor apartment in Paraguay. Police found his door open and said his home ​​had been ransacked.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/safepal-crypto-hardware-breach