Crypto wallet maker SafePal disclosed on August 16 that a flaw in its order-tracking system let an attacker access personal data belonging to roughly 39,798 customers, and a threat actor is now claiming to sell the stolen information on a cybercrime forum. The breach exposed names, email addresses, shipping addresses, phone numbers, and purchase details for customers who placed orders between March 2, 2025, and April 11, 2026, raising fresh concern about physical targeting of crypto holders as so-called wrench attacks continue rising worldwide.
How the Order-Tracking Flaw Was Exploited
SafePal identified an authorization flaw in a third-party order-tracking plug-in on its e-commerce site that let one customer view another customer’s shipment details under certain conditions, effectively allowing an attacker to browse other buyers’ order records by manipulating order numbers. The vulnerability sat in SafePal’s web infrastructure rather than its wallet hardware or software, and the company confirmed wallet credentials themselves were never at risk: seed phrases, private keys, wallet passwords, bank account details, payment card numbers, and government-issued identification were not exposed in the incident.
SafePal’s investigation also uncovered a separate configuration error that caused an automatic data-cleanup process to stop functioning correctly between September 2025 and April 2026, meaning order data that should have been deleted was instead retained as far back as March 2025, extending the pool of exposed records well beyond what a properly functioning system would have preserved. SafePal said it has since patched the vulnerability, added extra authorization checks to the tracking system, notified all affected customers by email on August 16, and set up a lookup page where customers can check their exposure using their order ID and shipping country. The company also said it will now limit personal data retention in its order-processing system to 90 days from the date of collection, and has retained an encrypted offline copy of the compromised data for potential law enforcement investigations while purging it from active servers.
Physical Targeting Risk Grows as Wrench Attacks Surge
While no cryptocurrency funds were directly stolen in the breach, the specific combination of exposed data, verified home addresses paired with confirmed evidence of crypto wallet ownership, is precisely the profile criminals use to identify high-net-worth targets for physical extortion. That concern has intensified alongside a documented rise in wrench attacks, incidents in which victims are threatened or physically assaulted until they surrender their crypto holdings. Blockchain analytics firm Chainalysis documented 46 violent incidents tied to crypto theft in the first half of 2026 alone, with more than $30 million stolen, putting the year on pace to be the worst on record for this category of crime, with home invasions increasingly overtaking kidnappings as the dominant tactic.
- SafePal serves an estimated 30 million users globally as a non-custodial wallet suite backed by Binance and Animoca Brands
- SafePal warned exposed customers to watch for targeted phishing attempts referencing their real purchase history, including fake firmware update requests, fraudulent refund offers, and impersonated customer support calls
Conclusion
SafePal joins a growing list of wallet companies whose customers have been exposed through third-party service breaches rather than direct compromises of wallet security itself. Hardware wallet maker Trezor disclosed days earlier that a breach at shipping partner ShipMonk compromised data for roughly 13,700 customers, and Ledger’s 2020 leak of approximately 272,000 customer records remains the clearest cautionary precedent, having led to a sustained wave of phishing attempts and, for some victims, direct ransom threats invoking violence. With stolen SafePal data now reportedly for sale and wrench attacks accelerating industry-wide, affected customers face a threat that extends well beyond their digital assets into their physical safety, a risk that no amount of wallet-level security can fully mitigate once a shipping address and proof of crypto ownership reach the wrong hands.
Sources & Methodology
Primary-source standard: Market-moving facts should link to original data releases, regulator notices, company filings or official project announcements whenever available. Secondary reporting is used for additional context, not as a substitute for original evidence.
Page last reviewed:
