< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

2 clusters · 12 sources · 19 days · First seen · Last updated

Cryptocurrency service data breaches

Overview

Cryptocurrency-related service providers have reported significant data breaches affecting thousands of customers.

In August 2026, SafePal disclosed that an authorization flaw in an order-tracking plugin exposed the personal information of approximately 39,798 customers. The leaked data included names, email addresses, shipping addresses, phone numbers, and purchase history for orders placed between March 2025 and April 2026. SafePal stated that core security credentials, such as seed phrases and private keys, were not compromised.

Following this, Pocket Bitcoin confirmed a security incident occurring in August that impacted 5,411 customers. The breach involved two categories of data: bank transaction lists for 5,120 customers—including names, addresses, transfer amounts, and some IBAN numbers—and correspondence for 291 customers, which potentially included identity document copies and public Bitcoin addresses. Pocket Bitcoin reported that its transaction systems and private keys remained unaffected and has notified authorities in Switzerland and Liechtenstein.

In September 2026, hardware wallet manufacturer Trezor announced that a breach involving its third-party shipping partner, ShipMonk, impacted approximately 80,000 to 81,000 users, primarily in the United States. The exposure included names, emails, phone numbers, shipping addresses, and order details for orders placed between November 2019 and August 2021. Trezor noted that ShipMonk had provided “repeated written assurances” that data had been deleted per a 90-day retention policy, yet the records remained in the provider's systems. While private keys and funds remain secure, Trezor warned of increased risks regarding phishing, social engineering, and physical security. To mitigate future risks, Trezor plans to implement an ‘Anonymous Delivery’ feature in the EU by September 2026 and in the US by the end of the year.

Entities

Trezor · ShipMonk · SatoshiLabs · SafePal · Pocket Bitcoin

Claims

What the coverage asserts, and how many sources carry each claim.

Timeline

  1. 8 days ago

    [TECHNOLOGY] 12 sources
    Trezor data breach expands to 80,000 customers via shipping partner

    Trezor reports a data breach at shipping partner ShipMonk has expanded to affect roughly 80,000 customers, exposing names, addresses, and contact details from orders placed between 2019 and 2021.

  2. 27 days ago

    [TECHNOLOGY] 44 sources
    SafePal discloses data breach affecting nearly 40,000 customers

    SafePal disclosed a data breach affecting nearly 40,000 customers due to an order-tracking plugin flaw. While personal details like names and addresses were exposed, wallet credentials and funds remain secure.

Sources

bitcoinethereumnews.com · bitcoinmagazine.com · bittimes.net · blockchainreporter.net · blogspan.net · criptotendencias.com · cryptobreaking.com · detlionblood32.wordpress.com · finbold.com · fortunegreece.com · jugem.jp · mpost.io

This summary has been updated 2 times: see revision history