< Back to situation

[REVISION HISTORY]

Cryptocurrency service data breaches

Updated 2 times since CLSTR started tracking revisions of this situation.

What changed

2026-09-04 21:50 UTC → 2026-09-05 18:01 UTC · added removed

Cryptocurrency-related service providers have reported significant data breaches affecting thousands of customers. In August 2026, SafePal disclosed that an authorization flaw in an order-tracking plugin exposed the personal information of approximately 39,798 customers. The leaked data included names, email addresses, shipping addresses, phone numbers, and purchase history for orders placed between March 2025 and April 2026. SafePal stated that core security credentials, such as seed phrases and private keys, were not compromised. Following this, Pocket Bitcoin confirmed a security incident occurring in August that impacted 5,411 customers. The breach involved two categories of data: bank transaction lists for 5,120 customers—including names, addresses, transfer amounts, and some IBAN numbers—and correspondence for 291 customers, which potentially included identity document copies and public Bitcoin addresses. Pocket Bitcoin reported that its transaction systems and private keys remained unaffected and has notified authorities in Switzerland and Liechtenstein. In September 2026, hardware wallet manufacturer Trezor announced that a breach involving its third-party shipping partner, ShipMonk, impacted approximately 80,000 users. This includes 67,000 U.S. customers whose to 81,000 users, primarily in the United States. The exposure included names, emails, phone numbers, shipping addresses, and order details were exposed for orders placed between November 2019 and August 2021. Trezor noted that ShipMonk failed to delete had provided “repeated written assurances” that data as contractually required. had been deleted per a 90-day retention policy, yet the records remained in the provider's systems. While private keys and funds remain secure, the company Trezor warned that of increased risks regarding phishing, social engineering, and physical security. To mitigate future risks, Trezor plans to implement an ‘Anonymous Delivery’ feature in the leaked information increases EU by September 2026 and in the risk US by the end of targeted phishing and social engineering attacks. the year.

Versions

  1. 2026-09-05 18:01 UTC Cryptocurrency service data breaches
  2. 2026-09-04 21:50 UTC Cryptocurrency service data breaches
  3. 2026-09-04 07:39 UTC Cryptocurrency service data breaches

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.