SafePal Bitcoin Wallet Breach Exposes Customer Details, Raising Safety Concerns
Cryptocurrency hardware wallet maker SafePal has confirmed a data breach after a vulnerability in an order-tracking plug-in exposed the names, home addresses, and phone numbers of almost 40,000 customers. Unlike many breaches that only expose passwords or emails, this incident leaked physical addresses tied to known crypto wallet ownership, raising concerns that affected customers could become targets for real-world theft or extortion.
Because the leaked data links individuals directly to cryptocurrency holdings, security experts warn this type of breach carries risks beyond typical identity theft, including so-called "wrench attacks" where criminals use exposed personal information to physically target victims. Businesses that sell or distribute crypto-related hardware should be especially mindful of how third-party plug-ins and order systems handle sensitive customer data.
This incident is a reminder that even small, seemingly minor software add-ons — like order-tracking tools — can become a major point of failure if not properly secured. Any business handling customer address data tied to high-value assets should treat that information with extra caution.