SafePal Hardware Wallet Provider Suffers Data Breach, Customer Order Info Exposed
Cryptocurrency hardware wallet provider **SafePal** has disclosed a data breach affecting nearly 40,000 customers. An exploited flaw in an order-tracking function allowed unauthorized access to sensitive customer order information, which is now being offered for sale on cybercrime forums. While wallet funds remain secure, users are urged to be vigilant against targeted phishing attempts.
Hardware wallet provider **SafePal** has confirmed a data breach impacting approximately 39,798 customers. The breach, stemming from an exploited authorization flaw in an order-tracking plugin, exposed customer names, email addresses, shipping addresses, phone numbers, and purchase details.
### Breach Details and Exposed Data
The incident specifically affects customers who placed orders between March 2, 2025, and April 11, 2026. **SafePal** emphasizes that the breach did not compromise critical user assets such as wallet seed phrases, private keys, passwords, bank account information, payment card numbers, or government-issued identification.
In a security advisory published on Sunday, **SafePal** stated, "No evidence has been found that the incident itself compromised access to **SafePal** wallets or funds."
Impacted customers were notified via email on August 16, with the subject line "[Important] Your **SafePal** Order Information Has Been Affected." The company has also launched an [online verification tool](https://www.safepal.com/en/scam-protection) allowing users to check if their order details were compromised using their order number and shipping country.
### Stolen Data Offered on Cybercrime Forums
A threat actor is now reportedly selling the stolen **SafePal** customer data on a cybercrime forum. The seller's claims align with **SafePal**'s disclosure, referencing the same affected order period and customer count. To legitimize the sale, the threat actor is offering to share order IDs and shipping countries for verification against **SafePal**'s online tool.

*Source: DarkWebInformer*
**SafePal** warns that the exposed information could be leveraged for highly targeted phishing and social engineering attacks. Customers have already reported receiving suspicious **SafePal**-related phishing emails and phone calls as early as May.
### Vulnerability and Remediation
**SafePal** first received a report consistent with the issue in early May 2026, initially treating it as an isolated incident. However, a formal security investigation was launched, leading to the discovery of an authorization flaw in the order-tracking function of an e-commerce plugin.
"As our e-commerce system involves multiple interconnected components and external integrations, as well as third-party logistics partners, we could not immediately rule out several possible explanations," the advisory noted.
In July, **SafePal** initiated a "full review and rebuild" of its order-processing system. During this process, they identified and fixed the vulnerability that allowed unauthorized access to customer order information. The company has also implemented additional security measures and is working with a third-party security firm to validate the fix and conduct a broader review.
Further investigation revealed a separate configuration error that caused a data-cleanup process to fail between September 2025 and April 2026, leading to the retention of order data as far back as March 2025.
For affected orders, **SafePal** has purged personal data from active e-commerce servers, retaining an encrypted offline copy for potential law-enforcement investigations.
### User Recommendations
**SafePal** advises customers to remain vigilant against phishing emails and phone calls, particularly those concerning firmware upgrades, product returns, refunds, or legal investigations. The company has already taken down over 30 fraudulent websites and phishing links related to this incident.
Crucially, customers do not need to replace their hardware wallets or transfer cryptocurrency due to this breach, as wallet security was not directly compromised. However, if a user has **already shared their seed phrases or private keys** in response to a phishing attempt, they should immediately consider their wallet compromised and transfer all assets to a new, secure wallet on a trusted **SafePal** device or official application.