Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
2 clusters · 12 sources · 19 days · First seen · Last updated
Cryptocurrency service data breaches
Overview
Cryptocurrency-related service providers have reported significant data breaches affecting thousands of customers.
In August 2026, SafePal disclosed that an authorization flaw in an order-tracking plugin exposed the personal information of approximately 39,798 customers. The leaked data included names, email addresses, shipping addresses, phone numbers, and purchase history for orders placed between March 2025 and April 2026. SafePal stated that core security credentials, such as seed phrases and private keys, were not compromised.
Following this, Pocket Bitcoin confirmed a security incident occurring in August that impacted 5,411 customers. The breach involved two categories of data: bank transaction lists for 5,120 customers—including names, addresses, transfer amounts, and some IBAN numbers—and correspondence for 291 customers, which potentially included identity document copies and public Bitcoin addresses. Pocket Bitcoin reported that its transaction systems and private keys remained unaffected and has notified authorities in Switzerland and Liechtenstein.
In September 2026, hardware wallet manufacturer Trezor announced that a breach involving its third-party shipping partner, ShipMonk, impacted approximately 80,000 to 81,000 users, primarily in the United States. The exposure included names, emails, phone numbers, shipping addresses, and order details for orders placed between November 2019 and August 2021. Trezor noted that ShipMonk had provided “repeated written assurances” that data had been deleted per a 90-day retention policy, yet the records remained in the provider's systems. While private keys and funds remain secure, Trezor warned of increased risks regarding phishing, social engineering, and physical security. To mitigate future risks, Trezor plans to implement an ‘Anonymous Delivery’ feature in the EU by September 2026 and in the US by the end of the year.
Entities
Trezor · ShipMonk · SatoshiLabs · SafePal · Pocket Bitcoin
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 9 SOURCES] The data breach at shipping partner ShipMonk affects approximately 80,000 to 81,000 customers in total. bittimes.net · bitcoinethereumnews.com · blockchainreporter.net · www.cryptobreaking.com · finbold.com · +3 more
- [● 9 SOURCES] The breach included names, email addresses, phone numbers, shipping addresses, and order numbers. bittimes.net · bitcoinethereumnews.com · blockchainreporter.net · www.cryptobreaking.com · finbold.com · +3 more
- [● 8 SOURCES] The leaked data involved orders placed between November 2019 and August 2021. bittimes.net · bitcoinethereumnews.com · blockchainreporter.net · www.cryptobreaking.com · finbold.com · +2 more
- [● 8 SOURCES] ShipMonk failed to delete customer data despite receiving repeated written requests and assurances from Trezor. bittimes.net · bitcoinethereumnews.com · blockchainreporter.net · www.cryptobreaking.com · finbold.com · +2 more
- [● 7 SOURCES] Trezor's own systems, hardware wallets, private keys, and customer funds were not compromised. bittimes.net · bitcoinethereumnews.com · www.cryptobreaking.com · finbold.com · www.fortunegreece.com · +2 more
- [○ 1 SOURCE] Trezor plans to introduce 'Anonymous Delivery' features in the EU and US to mitigate future privacy risks. bittimes.net
Timeline
-
8 days ago
[TECHNOLOGY] 12 sourcesTrezor data breach expands to 80,000 customers via shipping partnerTrezor reports a data breach at shipping partner ShipMonk has expanded to affect roughly 80,000 customers, exposing names, addresses, and contact details from orders placed between 2019 and 2021.
-
27 days ago
[TECHNOLOGY] 44 sourcesSafePal discloses data breach affecting nearly 40,000 customersSafePal disclosed a data breach affecting nearly 40,000 customers due to an order-tracking plugin flaw. While personal details like names and addresses were exposed, wallet credentials and funds remain secure.
Sources
bitcoinethereumnews.com · bitcoinmagazine.com · bittimes.net · blockchainreporter.net · blogspan.net · criptotendencias.com · cryptobreaking.com · detlionblood32.wordpress.com · finbold.com · fortunegreece.com · jugem.jp · mpost.io
This summary has been updated 2 times: see revision history