SafePal Breach Exposes 40,000 Crypto Wallet Customers Amid Rising Wrench Attacks
Cryptocurrency hardware wallet manufacturer SafePal confirmed on Sunday that nearly 40,000 customers had their personal information stolen in a recent security incident, making it the third wallet maker targeted in the past month alongside Trezor and Coinkite. The compromised data includes names, email addresses, shipping addresses, phone numbers, and purchase details from orders placed between March 2, 2025 and April 11, 2026. SafePal did not disclose how attackers initially gained access, but stated in a blog post that investigators identified a flaw in the order-tracking function of a plug-in associated with customer order information, which under certain conditions allowed unauthorized access to another customer's order data. The company has since remediated the vulnerability and emphasized that all SafePal wallets, seed phrases, and private keys remain secure.
All impacted customers have been notified by email, and SafePal launched a dedicated website where users can verify whether their information was exposed. The company warned that affected individuals will likely face sophisticated phishing attempts, including phone calls, emails, texts, fraudulent refund offers, and impersonations of customer support. A hacker was observed advertising the allegedly stolen database on a dark web cybercriminal forum. Affected users should immediately verify their exposure using an email breach checker and rotate any credentials associated with their SafePal accounts, while running a comprehensive privacy checkup on devices used to manage cryptocurrency holdings.
The breach underscores a broader threat landscape facing digital asset holders, particularly the rise of "wrench attacks," the industry's term for in-person, violent incidents where crypto owners are physically coerced into surrendering their assets. According to blockchain security auditor CertiK, the first half of 2026 saw a 33 percent year-over-year increase in such attacks, with 52 incidents recorded worldwide through June compared to 39 during the same period in 2025. Aggregate losses reached $124 million so far this year, a dramatic jump from the $10.5 million reported in the first half of 2025. Notable cases include the kidnapping of a French mother and child in April, a 2025 home invasion in Minnesota, a 2024 carjacking of a Lamborghini in Connecticut, and the recent death of cryptocurrency investor Harry Chun Tak Yeh, who was found after falling from his 30th-floor apartment in Paraguay with his door open and home ransacked. Crypto holders exposed by the SafePal breach should treat the stolen shipping addresses and phone numbers as an elevated physical security risk and review authentication on all linked services, including testing passwords against known leaks with a password checker.