All posts
News
6 min read

SafePal Breach Exposes Almost 40,000 Customers

Crypto hardware wallet provider SafePal has disclosed a security incident affecting nearly 40,000 customers, exposing personal hardware wallet information.

SafePal Breach Exposes Almost 40,000 Customers — cover image

According to SafePal, an authorization flaw in an order-tracking system let unauthorized parties peek at other customers' data. Around 39,798 customers who placed orders between March 2, 2025 and April 11, 2026 were hit.

The good news is that the breach did not expose private keys, seed phrases, wallet passwords or cryptocurrency funds. Still, the personal data that slipped out could make affected customers prime targets for convincing phishing and impersonation scams.

What Happened?

SafePal said it found an authorization flaw in the order-tracking function of a plug-in tied to customer orders. Under certain conditions, that weakness let someone looking at the system see another customer's order.

The leaked data included:

  • Customer names
  • Email addresses
  • Phone numbers
  • Shipping addresses
  • Purchase and order details

SafePal says the vulnerability affected about 39,798 customers whose orders were placed during the period in question. The company patched the issue once it discovered it and added extra security measures.

This was not a compromise of SafePal's hardware wallets themselves. Instead, the incident hit the infrastructure around buying and delivering those devices. That distinction matters, but it doesn't make the incident harmless.

Private Keys and Crypto Funds Were Not Exposed

SafePal says it found no evidence that the incident gave attackers access to users' wallets or cryptocurrency.

The exposed systems did not contain:

  • Seed phrases
  • Private keys
  • Wallet passwords
  • Bank account information
  • Payment card numbers
  • Government-issued identification numbers

SafePal says it never requests or stores wallet credentials such as private keys and recovery phrases in its order systems.

For users who only had their order information exposed, SafePal says there's no reason to move cryptocurrency to another wallet just because of this breach.

However, there is an important exception.

Anyone who has already entered or shared a seed phrase or private key after receiving a suspicious email, phone call, website link or other message should treat that wallet as compromised and move the remaining assets to a fresh wallet.

Why This Data Can Still Be Dangerous

Leaked names and shipping info may look less serious than stolen keys, but for crypto users it can be highly sensitive.

An attacker could learn that a person:

  1. Bought a cryptocurrency hardware wallet.
  2. Uses or is interested in cryptocurrency.
  3. May control digital assets.
  4. Can be reached via email or phone.
  5. May have a hardware wallet delivered to a specific address.

That opens the door to tightly targeted scams.

Instead of a generic phishing email about a wallet update, a scammer could reference the victim's real name, phone number, address or SafePal purchase. A message that sounds personal feels more credible.

SafePal warned customers that the exposed data could be used for fraudulent calls, emails, texts, letters, refund offers, fake firmware updates, fake support chats and malicious sites designed to harvest wallet credentials.

Phishing Is Now the Biggest Risk

The biggest immediate threat isn't a remote hack of a SafePal device. It's social engineering.

Picture an email that starts with your real name and SafePal order details:

"We detected a security issue affecting your SafePal hardware wallet. Please verify your device using the recovery tool below."

A user who knows about the breach might think the message is legit. The fake site could then ask for the user's 12- or 24-word recovery phrase.

Once a seed phrase lands on an attacker-controlled site, the attacker can control the associated crypto - no hardware wallet needed.

SafePal says it has already taken down more than 30 fraudulent sites and phishing links tied to scam activity around the incident.

That means affected users should be especially skeptical of unexpected messages about their wallets or past orders.

SafePal Notified Affected Customers

SafePal made the incident public on August 16, 2026. The company also reached out to each affected customer via email from security@safepal.com with the subject:

"[Important] Your SafePal Order Information Has Been Affected."

SafePal has set up a verification system so customers can check whether their order was affected using their order ID and shipping country.

Still, avoid clicking links in unexpected messages claiming to relate to the breach. Typing SafePal's official URL into your browser is safer.

SafePal Changes Its Data Retention Policy

SafePal says it has introduced several changes after the incident:

  • Fixed the authorization vulnerability.
  • Added extra security measures.
  • Brought in an independent third-party firm to review the fix and other order-processing systems.
  • Opened a dedicated support channel for affected customers.
  • Contacted logistics and fulfillment partners to see if the issue spread beyond SafePal's own systems.
  • Took down more than 30 fraudulent sites and phishing links.

Perhaps the most notable shift is SafePal's new approach to customer data. Personal information stored in the affected order-processing environment will now normally be kept for only 90 days, unless the law requires more.

For a company selling products built around crypto security, keeping less customer data around can cut damage from future incidents.

Hardware Wallet Privacy Is More Than Private-Key Security

The SafePal incident highlights a part of crypto security that gets overlooked.

A hardware wallet can keep private keys safe, but a separate system can expose who owns that wallet. These are two separate security problems.

A hardware wallet mainly protects the cryptographic keys that manage crypto. An online store, however, must process:

  • Names
  • Addresses
  • Contact info
  • Payments
  • Shipping info
  • Order histories

Compromising the second system doesn't automatically break the first. But linking a real identity and home address to a purchase of a crypto security device creates its own privacy risk.

For crypto users, metadata can be valuable even when no private keys are exposed.

What Affected SafePal Customers Should Do

Customers who bought SafePal products during the affected period should stay extra cautious about unexpected communication.

Most importantly:

Never give your seed phrase or private key to anyone.

SafePal says its staff will never ask for that info by email, phone or any other channel.

Users should also:

  • Avoid clicking links or scanning QR codes in unsolicited messages.
SafePal Breach Exposes Almost 40,000 Customers — AnonExch