SafePal Data Breach Exposes Personal Details of 39,798 Customers
Cryptocurrency hardware wallet maker SafePal has disclosed a data breach that exposed personal and order information belonging to approximately 39,798 customers.
The incident was caused by an authorization flaw in an order tracking plug-in. Under certain conditions, the vulnerability allowed unauthorized users to access another customer's order information. SafePal has fixed the issue and said it has found no evidence that customer wallets or cryptocurrency funds were compromised.
What Information Was Exposed?
According to SafePal, the affected records could contain:
- Customer names
- Email addresses
- Shipping addresses
- Phone numbers
- Purchase and order details
The affected orders were placed between March 2, 2025, and April 11, 2026. SafePal has not disclosed exactly when unauthorized access began or ended or how many attackers accessed the information.
Importantly, SafePal said the incident did not expose:
- Seed phrases
- Private keys
- Wallet passwords
- Bank account information
- Payment card numbers
- Government issued identification documents
- Wallet addresses or balances
The company said there is currently no evidence that the breach itself provided attackers with access to customer wallets or funds.
Customers Warned About Phishing and Fraud
Although wallet credentials were not exposed, the leaked information could create significant risks for targeted phishing and impersonation attacks.
Attackers who know a person's name, phone number, home address and SafePal purchase details could create highly convincing messages pretending to be SafePal customer support.
SafePal warned customers to be cautious of unexpected:
- Phone calls
- Emails and text messages
- Letters
- Refund offers
- Firmware update requests
- Fake customer support communications
- Hardware delivery or replacement requests
The company specifically advised customers to treat unexpected communications related to their SafePal purchases as suspicious.
SafePal Began Investigation in 2026
SafePal said it first received a report consistent with the issue in early May 2026. The company initially treated the report as an isolated case but later escalated it into a formal security investigation.
In July, SafePal began a broader review and rebuild of its order processing pipeline. The company said this investigation ultimately identified the root cause of the unauthorized access.
SafePal notified affected customers individually by email on August 16, 2026.
Data Retention Reduced to 90 Days
Following the incident, SafePal said it has introduced several security improvements.
The company has:
- Fixed the authorization vulnerability
- Reduced personal data retention in the relevant order processing environment to 90 days, subject to legal requirements
- Removed affected records from active servers
- Retained a secured offline backup for potential investigations
- Engaged an independent security company to review the fix and order processing systems
- Contacted logistics and fulfillment partners
- Taken down more than 30 fraudulent websites and phishing links associated with scam activity
- Created a status checking process for affected customers
SafePal also said it is working with external specialists to help investigate potential on-chain losses.
Stolen Data Allegedly Advertised Online
The incident has also raised concerns about the possible circulation of the exposed information.
A threat actor has advertised a dataset on a cybercrime forum claiming to contain SafePal customer information. The listing reportedly referenced the same order period and customer count identified by SafePal.
However, the data advertised by the threat actor has not been independently verified as authentic.
The alleged availability of customer names and physical addresses is particularly concerning because hardware wallet users may be specifically targeted by criminals attempting to steal cryptocurrency through phishing, impersonation or physical attacks.
No Need to Move Crypto Assets Solely Because of the Breach
SafePal said customers do not need to move their cryptocurrency solely because their order information was exposed.
However, users should be extremely cautious if someone contacts them claiming to be from SafePal and asks for a seed phrase, private key, wallet password or other sensitive information.
SafePal also warned that anyone who entered a seed phrase or private key into a suspicious website or shared it with someone claiming to provide support should consider that wallet compromised.
Security Impact
The incident demonstrates that protecting cryptocurrency users requires more than securing the wallet itself.
Even when private keys and seed phrases remain protected, exposed customer information can reveal that an individual owns a hardware wallet and provide attackers with a name, phone number and physical address.
This information can be used to create highly targeted phishing campaigns and impersonation attempts. It can also increase the risk of physical attacks against cryptocurrency holders.
SafePal has now fixed the underlying issue and introduced additional security controls, but affected customers should remain alert for suspicious communications referencing their SafePal purchases.