Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Public Lands Are at the Forefront of Wyoming’s Primaries

    August 17, 2026

    Private Schools Where 100% of Students Use Vouchers Barely Face Any Oversight — ProPublica

    August 17, 2026

    Ebola is Back-and the IMF’s Relief Fund Is Empty by Marina Zucker-Marques

    August 17, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Public Lands Are at the Forefront of Wyoming’s Primaries
    • Private Schools Where 100% of Students Use Vouchers Barely Face Any Oversight — ProPublica
    • Ebola is Back-and the IMF’s Relief Fund Is Empty by Marina Zucker-Marques
    • French PM Lecornu booed by residents on visit to fire-ravaged southwest
    • Changing pubs into offices or homes to be made harder under new rules
    • Burnham exchanged messages with individual impersonating Trump chief of staff | Andy Burnham
    • Skylight Buddy Review (2026): Kid Routines Just Got Easy
    • DeepSeek AI Releases DeepSeek Harness in Developer Preview: An MIT-Licensed Agent Harness Where Everything is a Plugin
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, August 17
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Crypto & Blockchain

    SafePal breach exposes 40,000 customers as hardware wallet attacks escalate from data leaks to $100 million theft

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 17, 2026 Crypto & Blockchain No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    SafePal has become the latest hardware-wallet provider to suffer a security incident after an authorization flaw exposed personal information from about 40,000 customers.

    The Aug. 16 disclosure extends a run of security problems involving hardware-wallet companies and their users, including recent incidents affecting Trezor, Ledger and Coldcard.

    Two SafePal failures turned an order-system flaw into a larger data exposure

    SafePal revealed that the breach originated in the company’s e-commerce infrastructure.

    According to the firm, an authorization flaw in its order-tracking system allowed unauthorized access to customer records covering purchases made between March 2, 2025, and April 11, 2026. The exposed information included names, email addresses, shipping addresses, phone numbers, and purchase details.

    Infographic showing SafePal's 39,798 affected customers, the March 2025 to April 2026 order window, the cleanup and disclosure timeline, exposed order data, unaffected wallet credentials, and pending independent review.

    SafePal said private keys, recovery phrases, wallet passwords, payment card numbers, and wallet access were not exposed. It also found no evidence that the flaw itself was used to compromise customer wallets or steal cryptocurrency.

    However, the authorization weakness was only one part of the incident.

    A separate configuration error had prevented a scheduled cleanup process from operating correctly between September 2025 and April 2026, leaving older order records in the system for longer than intended.

    That failure expanded the pool of information available through the authorization flaw and extended the affected dataset back to March 2025.

    The retention failure also conflicts with a SafePal support statement published in 2020, which said information associated with delivered hardware-wallet orders would be retained for 30 days and then destroyed through a monthly cleanup process.

    Hardware wallet users rattled by rise in phishing emails pointing to fake Tezor websiteHardware wallet users rattled by rise in phishing emails pointing to fake Tezor website
    Related Reading

    Hardware wallet users rattled by rise in phishing emails pointing to fake Tezor website

    Fears pose as stark reminder to stay vigilant when clicking links on emails related to digital assets.

    Oct 27, 2023 · Oluwapelumi Adejumo

    Together, the two failures explain both how customer information became accessible and why nearly 40,000 records remained available: one control failed to restrict access, while another failed to delete information that should no longer have been stored.

    Hardware-wallet incidents spread from data leaks to nine-figure theft

    SafePal’s disclosure is the latest in a series of security incidents involving major hardware-wallet providers and their customers this year.

    In recent weeks, Trezor disclosed that a breach at its shipping provider exposed personal information belonging to nearly 14,000 customers, while Coldcard users suffered direct losses after a flaw in the wallet’s key-generation process allowed attackers to drain Bitcoin from affected addresses. Ledger customers were also affected by an order-data breach involving third-party payment provider Global-e earlier this year.

    Crypto Hardware Wallet Service Providers Security IncidentsCrypto Hardware Wallet Service Providers Security Incidents
    Crypto Hardware Wallet Service Providers Security Incidents (Source: Chain Ink)

    The Coldcard incident has produced the largest financial loss among the recent cases. More than $100 million in Bitcoin was stolen after a bug left some private keys insufficiently secure, and funds were drained across multiple attack waves beginning in late July.

    CryptoSlate Daily Brief

    Daily signals, zero noise.

    Market-moving headlines and context delivered every morning in one tight read.

    5-minute digest 100k+ readers

    Free. No spam. Unsubscribe any time.

    Whoops, looks like there was a problem. Please try again.

    You’re subscribed. Welcome aboard.

    The other incidents have primarily exposed customer information rather than private keys, but security experts have warned that the stolen data creates another route for criminals to target crypto holders.

    Binance co-founder Changpeng Zhao pointed out that the breaches exposing names, phone numbers, emails and delivery addresses could increase phishing, social-engineering and physical-security risks.

    Gemini users targeted in widespread phishing scam involving fake data breach claimsGemini users targeted in widespread phishing scam involving fake data breach claims
    Related Reading

    Gemini users targeted in widespread phishing scam involving fake data breach claims

    Crypto users lost around $63 million to phishing scams in August.

    Sep 4, 2024 · Oluwapelumi Adejumo

    Notably, SafePal issued a similar warning after its own breach and said it had already taken down more than 30 fraudulent websites and phishing links targeting customers.

    Meanwhile, including home addresses raises a more serious physical-security concern because leaked customer records can identify people who purchased devices commonly used to store cryptocurrency.

    That comes as violent attacks against crypto holders are already increasing. Chainalysis said so-called wrench attacks, including kidnappings and home invasions used to force victims to transfer digital assets, resulted in about $30 million of reported thefts during the first half of 2026. The total for 2025 reached a record $58 million.

    Chainalysis data also showed that home invasions accounted for 37% of violent crypto attacks recorded in 2026, while kidnappings made up more than half of reported incidents tracked this year.

    France’s crypto kidnapping surge exposes the personal data trail behind wrench attacksFrance’s crypto kidnapping surge exposes the personal data trail behind wrench attacks
    Related Reading

    France’s crypto kidnapping surge exposes the personal data trail behind wrench attacks

    France’s response shows why visible crypto wealth now demands offline threat planning, data controls, and faster law-enforcement coordination.

    Jul 2, 2026 · Liam ‘Akiba’ Wright

    The recent hardware-wallet incidents have therefore produced risks at several levels. Coldcard users have already suffered more than $100 million in direct Bitcoin theft, while breaches affecting SafePal, Trezor and Ledger have exposed information that can be used for targeted phishing, impersonation and potentially physical attacks.

    Taken together, the incidents complicate the idea of hardware wallets as a single line of defense. The devices may protect private keys, but users remain exposed to firmware failures, customer databases, and the broader infrastructure surrounding self-custody.

    attacks breach customers data Escalate exposes hardware leaks Million SafePal theft Wallet
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    French tax authority data breach affects 678,000 individuals

    Recent macOS Screen Sharing Vulnerability Exploited in Attacks

    Coinbase-Circle USDC revenue sharing, FOMC minutes, oil price: Crypto Week Ahead

    Offshore Wind Will Struggle Long After Trump’s Attacks

    Tekmar secures €1 million concrete protection contract for ‘major’ European offshore wind project

    XRP has more users, fewer sellers and still can’t escape $1

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Public Lands Are at the Forefront of Wyoming’s Primaries

    August 17, 2026

    Private Schools Where 100% of Students Use Vouchers Barely Face Any Oversight — ProPublica

    August 17, 2026

    Ebola is Back-and the IMF’s Relief Fund Is Empty by Marina Zucker-Marques

    August 17, 2026

    French PM Lecornu booed by residents on visit to fire-ravaged southwest

    August 17, 2026
    Latest Posts

    Heathrow expansion would take thousands of jobs from other UK regions, report finds | Heathrow third runway

    July 27, 2026

    Farage’s latest gamble clouds Reform’s path to power – POLITICO

    July 27, 2026

    Pauline Hanson loses bid to overturn Mehreen Faruqi racial discrimination finding | Australian Greens

    July 27, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Public Lands Are at the Forefront of Wyoming’s Primaries

    August 17, 2026

    Private Schools Where 100% of Students Use Vouchers Barely Face Any Oversight — ProPublica

    August 17, 2026

    Ebola is Back-and the IMF’s Relief Fund Is Empty by Marina Zucker-Marques

    August 17, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.