SafePal Breach Puts 40,000 Cryptocurrency Users at Risk of Physical Attacks
A vulnerability in SafePal's order-tracking system exposed personal details including addresses for nearly 40,000 customers, amplifying risks of violent theft as 'wrench attacks' surge across the crypto industry.
SafePal’s Tracking System Vulnerability Exposes Customer Information
SafePal, a non-custodial cryptocurrency wallet platform backed by investment from Binance and Animoca Brands that maintains 30 million user accounts, disclosed over the weekend that a security vulnerability in its order-tracking infrastructure had provided attackers with unauthorized access to personal information belonging to approximately 39,798 customers. The vulnerability affected all customers who had submitted orders between March 2025 and April 2026, with the exposed information encompassing full names, email addresses, home addresses, phone numbers, and purchase details.
In response, SafePal executed patches to close the vulnerability and launched a campaign to notify all affected customers through email notifications. The company stressed an important distinction: while personal details were compromised, the cryptographic elements safeguarding user wallets remained entirely secure. Seed phrases used for wallet recovery, private cryptographic keys, access passwords, banking credentials, payment card information, and government identification details were not part of the breach. No cryptocurrency assets were directly stolen from customer accounts as a result of this incident.
Physical Security Emerges as Escalating Threat in Crypto
Despite the fact that wallet credentials escaped compromise, the combination of residential addresses linked to evidence of cryptocurrency ownership creates vulnerability to a particular category of crime. These incidents, referred to colloquially as “wrench attacks,” involve perpetrators using physical force or threats to compel victims to surrender access to their digital wealth. The concern has become increasingly pressing as such crimes have risen markedly. Chainalysis, a firm specializing in blockchain analysis and security research, documented 46 violent incidents of this nature occurring during just the first half of 2026, with combined theft totaling more than $30 million. The organization indicated that 2026 is likely to establish a record year for such crimes, with home invasions becoming increasingly prevalent compared to abductions.
Recurring Pattern of Wallet Security Breaches
SafePal joins a growing roster of cryptocurrency wallet firms experiencing major security incidents. Trezor, another leading hardware wallet manufacturer, recently announced that a breach involving its shipping partner ShipMonk had exposed data on roughly 13,700 customers. Yet the most cautionary example stems from Ledger’s experience. In 2020, Ledger suffered a significant data breach affecting approximately 272,000 customers, an incident that subsequently generated waves of phishing attacks and, for some victims, extortion attempts accompanied by physical threats.
The SafePal breach arrives at a particularly turbulent moment for the self-custody movement. The recent Coldcard exploit, which abused a firmware-level flaw in the device’s entropy generation to access and transfer long-dormant Bitcoin, contributed to cumulative industry losses nearing $130 million. These accumulated incidents illustrate a fundamental challenge in crypto: securing assets against digital threats while also protecting users from the physical safety risks that knowledge of significant holdings can introduce. For all cryptocurrency participants—whether holding Bitcoin, Ripple’s XRP, or other digital assets through self-custody wallets—these breaches highlight the ongoing tension between the freedom of non-custodial ownership and the security complexities it demands.
Source: SafePal, via Decrypt. Not financial advice.