Bitcoin · CryptoSlate
SafePal breach exposes 40,000 customers as hardware wallet attacks escalate from data leaks to $100 million theft
Compiled by KHAO Editorial — aggregated from 2 sources. See llms.txt for citation guidance.
✓ KHAO Verified
SafePal has become the latest hardware-wallet provider to suffer a security incident after an authorization flaw exposed personal information from about 40,000 customers.
Key facts
- According to the firm, an authorization flaw in its order-tracking system allowed unauthorized access to customer records covering purchases made between March 2, 2025, and April 11, 2026
- Chainalysis said so-called wrench attacks, including kidnappings and home invasions used to force victims to transfer digital assets, resulted in about $30 million of reported thefts during the first
- The Aug. 16 disclosure extends a run of security problems involving hardware-wallet companies and their users, including recent incidents affecting Trezor, Ledger and Coldcard
- A separate configuration error had prevented a scheduled cleanup process from operating correctly between September 2025 and April 2026, leaving older order records in the system for longer
Summary
01 SafePal exposed personal and order data from about 40,000 customers after an authorization flaw was compounded by a failed data-retention process. 02 The breach extends a run of hardware-wallet security incidents that has already culminated in more than $100 million of Bitcoin losses at Coldcard. 03 Leaked names, phone numbers and home addresses raises the risk of targeted phishing and physical attacks against identifiable crypto holders. The Aug. 16 disclosure extends a run of security problems involving hardware-wallet companies and their users, including recent incidents affecting Trezor, Ledger and Coldcard.