SafePal leak exposes 40,000; Coldcard theft tops $100M

An authorization flaw and a disabled cleanup process exposed about 40,000 SafePal customers’ order records. A Coldcard key-generation bug led to over $100 million in Bitcoin theft.

SafePal disclosed on Aug. 16 that an authorization flaw in its e-commerce order-tracking system allowed unauthorized access to customer purchase records covering March 2, 2025, through April 11, 2026. Exposed fields included names, email addresses, shipping addresses, phone numbers and purchase details. The company reported that private keys, recovery phrases, wallet passwords, payment card numbers and wallet access were not exposed and that it found no evidence the flaw was used to directly drain wallets.

A separate configuration error prevented a scheduled monthly cleanup from running between September 2025 and April 2026, SafePal said. That retention failure kept older order records in the system longer than intended and extended the scope of data available through the authorization flaw. The extended retention contrasted with a 2020 support statement that said delivered hardware-wallet order information would be retained for 30 days and then deleted.

SafePal reported removing more than 30 fraudulent websites and phishing links targeting customers and urged users to exercise caution. Binance co-founder Changpeng Zhao warned, “The breaches exposing names, phone numbers, emails and delivery addresses could increase phishing, social-engineering and physical-security risks.” Security experts note that names, emails, phone numbers and delivery addresses can be used in targeted phishing and impersonation attempts.

The SafePal disclosure follows several other security incidents affecting hardware-wallet providers this year. Trezor reported a breach at a shipping provider that exposed personal data for nearly 14,000 customers. Ledger customers were affected earlier by order-data exposure tied to a third-party payments provider.

Coldcard reported a separate bug in its key-generation process that left some private keys insufficiently secure. The problem led to systematic thefts beginning in late July and resulted in more than $100 million in Bitcoin taken across multiple attack waves, according to incident summaries.

Data compiled by Chainalysis indicate so-called wrench attacks, including kidnappings and home invasions used to force victims to transfer assets, accounted for about $30 million in reported thefts during the first half of 2026. Chainalysis data show the total for 2025 reached $58 million. The same data attribute about 37% of violent crypto attacks tracked in 2026 to home invasions, while kidnappings made up more than half of reported incidents this year.

Recent incidents have involved device-level faults, e-commerce authorization errors, third-party shipping and payment providers, and targeted fraud campaigns. Companies involved reported remedial actions and urged customers to monitor accounts, update device software and be wary of phishing attempts.

Articles by this author