SafePal Data Breach Exposes 39,000 Customer Records, Sparks Phishing Concerns
Hardware wallet provider **SafePal** has disclosed an authorization flaw in an order-tracking plug-in, leading to the exposure of personal data for nearly 40,000 customers. While no wallet credentials or financial information were compromised, the incident raises significant concerns about increased phishing attempts and potential physical threats to cryptocurrency holders.
# SafePal Data Breach Exposes 39,000 Customer Records, Sparks Phishing Concerns

**SafePal**, a prominent hardware wallet manufacturer, has revealed an authorization flaw within an order-tracking plug-in that exposed sensitive customer data. Approximately 39,798 customers had their names, email addresses, shipping addresses, phone numbers, and purchase details compromised.
The company confirmed that all affected customers were individually notified via email on August 16 from `[email protected]`, with the subject line "[Important] Your SafePal Order Information Has Been Affected."
## Nature of the Compromised Data
Crucially, **SafePal** stated that the breach did not include wallet credentials, seed phrases, private keys, wallet passwords, bank account information, payment card numbers, or government-issued identification numbers. The company has found no evidence suggesting the incident directly compromised access to **SafePal** wallets or funds.
"This incident did not involve your seed phrase, private keys, wallet password, or other wallet credentials, bank account information, payment card numbers, or government-issued identification numbers," **SafePal** stated in a security update.
## The Vulnerability and Affected Period
The flaw, an authorization vulnerability in an unnamed order-tracking plug-in, allowed unauthorized access to other customers' order information under specific conditions. No **CVE** identifier has been assigned to this issue.
The affected orders were placed between March 2, 2025, and April 11, 2026. **SafePal** clarified that these dates refer to the order placement period, not the duration of the vulnerability's exploitability. Details regarding when the unauthorized access began or ended, the number of parties accessing the records, or how the flaw was initially discovered remain undisclosed.
## Heightened Risk of Social Engineering and Physical Threats
Given that the exposed records link named individuals to home addresses and purchase details, **SafePal** has issued a strong warning to affected customers. They may face an increased risk of "fraudulent phone calls, emails, text messages, letters, refund offers, firmware-update requests, [and] fake customer-support communications."
"Treat any unexpected contact or hardware delivery referencing your **SafePal** purchase as suspect, whether it arrives by phone, in the post, or in person," the company advised.
This concern is amplified by recent trends in crypto-related crime. Blockchain analytics firm **Chainalysis** documented 46 violent incidents globally through late June 2026, resulting in over $30 million stolen. These incidents often target crypto holders, who are seen as high-value targets due to the instantly and irreversibly transferable nature of their wealth.
## Delayed Discovery and Remediation Efforts
Separately, **SafePal** also identified a configuration error that caused a scheduled data-cleanup process to fail between September 2025 and April 2026, leaving older order records in the system longer than intended. While this issue didn't cause the unauthorized access, it explains the extended range of affected records.
The first report consistent with the issue reached **SafePal** in early May 2026. Initially treated as an isolated case, it was later escalated into a formal security investigation. The company began a full review and rebuild of its order-processing pipeline in July, confirming the root cause during this process.
The delay between initial reports in May and the August confirmation has raised questions, particularly after a customer reported receiving suspicious emails, letters, and phone calls claiming to be from **SafePal** in May.
## Data for Sale on Cybercrime Forums
A threat actor, known as **DarkWebInformer**, has since advertised a dataset on a cybercrime forum, citing the same order window and customer count as the **SafePal** breach. The seller offered to share order IDs and shipping countries for verification against **SafePal**'s own status-check tool. **SafePal** has not yet publicly addressed this listing.
## Mitigation Measures Implemented
**SafePal** has outlined several measures taken to address the incident and enhance security:
* The authorization flaw has been fixed, and additional security measures have been introduced.
* Retention of personal information in the relevant order-processing environment has been cut to 90 days.
* Affected records have been purged from active servers, with a secured offline backup maintained for potential investigations.
* An independent third-party security firm is being engaged to validate the fix and review order-processing systems.
* Third-party logistics and fulfillment partners have been contacted to confirm the issue had not spread within their systems.
* Over 30 fraudulent websites and phishing links "tied to the scam activities" have been taken down.
* A status-check page using an order ID number and shipping country has been published, alongside a dedicated support channel.
**SafePal** advises customers not to move assets solely due to the exposure. However, anyone who entered a seed phrase or private key in response to a suspicious message should immediately treat that wallet as compromised.
This incident echoes previous breaches in the crypto hardware space, such as **Ledger**'s 2020 disclosure of a database leak affecting 272,000 customers. Research on **Ledger**'s breach victims found increased spam, scams, phishing, and even reports of tampered devices, highlighting the long-term impact of such data exposures.
As of now, neither **SafePal** nor any mainstream news outlet has reported a confirmed financial loss directly attributable to this incident. **SafePal** has encouraged customers who believe they suffered a loss to contact its support channel and is engaging on-chain asset-tracing specialists.