Nearly 40,000 customers of crypto wallet maker SafePal now have to watch their inboxes a little more closely. The company disclosed on August 16 that a flaw in its order-tracking system had exposed personal information tied to roughly 39,798 customer accounts, marking one of the more significant SafePal data breach disclosures to hit the hardware wallet industry this year. The good news, according to SafePal, is that the breach never touched the credentials that actually protect crypto funds.
Summary
Key takeaways
- An authorization flaw in SafePal’s order-tracking plugin exposed personal data tied to approximately 39,798 customers who placed orders between March 2, 2025, and April 11, 2026.
- Exposed information includes names, email addresses, phone numbers, shipping addresses, and purchase details — but not seed phrases, private keys, wallet passwords, payment card numbers, bank details, or government IDs.
- SafePal says there is no evidence that customer wallets or funds were directly compromised by the breach itself.
- The company has taken down more than 30 phishing websites tied to the incident and cut personal data retention to 90 days.
- SafePal is hiring an independent third-party security firm to audit its fix, following similar recent data exposures at Trezor and Ledger.
What Triggered the SafePal Data Breach
The root cause was an authorization defect in a plugin SafePal used to track customer orders. Under certain conditions, that flaw let one customer view another customer’s order information simply by manipulating an order number — similar to a delivery tracking page that accidentally lets a stranger pull up someone else’s receipt.
SafePal has not said exactly when the vulnerable code was introduced or how many outside parties may have accessed the exposed records before the flaw was found and patched.
Scope and Type of Exposed Data
The exposed records cover orders placed between March 2, 2025, and April 11, 2026, according to SafePal’s incident report and reporting from The Block and CoinDesk. The data included customer names, email addresses, phone numbers, shipping addresses, and purchase details — enough personal detail to make future scam attempts look convincing.
Wallet Security Remained Intact
SafePal was explicit about what the breach did not touch. The company said Among the compromised data were seed phrases, private keys, wallet passwords, payment card numbers, bank account information, and government-issued identification numbers never exposed. SafePal added that it has found no evidence the breach itself compromised access to SafePal wallets or customer funds, a distinction that matters given how the incident is likely to be perceived.
Phishing Risk Escalates for SafePal Customers
The real danger for affected users isn’t stolen crypto — it’s convincing impersonation. Because attackers can pair real names, addresses, and order histories, phishing attempts built on this data can look far more credible than a generic scam email. SafePal alerted users that fraudsters could impersonate its staff by claiming to offer firmware updates, refunds, or device replacements hardware wallets specifically to trick victims into handing over wallet credentials.
That warning wasn’t hypothetical. Public complaints referencing accurate personal details surfaced on Reddit and Trustpilot as early as July 3 and July 4 — weeks before SafePal’s public disclosure — describing scam calls from people who already knew the customer’s name, address, phone number, email, and past order details, and who directed victims to a fraudulent site posing as SafePal support. SafePal has said it investigated an earlier report in early May but initially treated it as an isolated case, only escalating into a full review and rebuild of its order-processing pipeline in July, when the authorization flaw was confirmed as the root cause.
Takedown of Phishing Sites and Customer Alerts
SafePal says it has identified and removed more than 30 fraudulent websites and phishing links tied to the incident, and it continues monitoring for new domains attempting to exploit the leaked data. Affected customers were notified individually by email from SafePal’s security team, and the company launched a verification tool that lets users check whether their order was involved by entering their order number and shipping country.
What Affected Users Should Do
SafePal’s guidance is blunt: anyone who has already entered a seed phrase or private key on a suspicious website — whether prompted by email, phone call, or physical mail — should treat that wallet as compromised, generate a new wallet, and move any remaining funds immediately.
SafePal’s Response: Data Retention Changes and Independent Audit
Beyond patching the immediate flaw, SafePal is overhauling how long it keeps customer order data. The company says it is reducing personal data retention in the affected environment to just 90 days from the date of collection, a change meant to shrink the pool of historical data exposed to any future incident. That decision also reflects a separate problem: a configuration error a routine data-cleanup process malfunctioned during the period spanning September 2025 through April 2026, meaning older records sat in the system far longer than intended, even though SafePal says this failure did not itself cause the unauthorized access.
SafePal is also engaging an independent third-party security firm to verify the solution and perform a comprehensive security assessment of its order-processing systems, a step aimed at reassuring customers that the underlying authorization issue has actually been closed rather than just patched over.
A Pattern Emerging Across Hardware Wallet Providers
SafePal’s disclosure lands just days after a similar episode at rival hardware wallet maker Trezor, whose shipping partner ShipMonk exposed personal data belonging to nearly 14,000 customers. Earlier this year, Ledger notified customers of a comparable exposure traced to Global-e, the third-party commerce provider handling some purchases through Ledger’s website. In each of these cases — SafePal, Trezor, and Ledger — the companies involved maintained that wallets and private keys remained secure throughout.
Taken together, the pattern points to a recurring weak point in the hardware wallet industry: it isn’t the cryptography protecting private keys that’s failing, it’s the surrounding commerce and logistics infrastructure — order-tracking plugins, shipping partners, third-party payment processors — that keeps leaking customer names and addresses into the hands of scammers. For an industry built on the promise of self-custody security, that distinction may offer little comfort to a customer fielding a convincing phone call from someone who already knows exactly what they ordered and where it was shipped.
FAQ
What caused the SafePal data breach?
An authorization flaw in SafePal’s order-tracking plugin allowed unauthorized access to customer order information.
What types of customer data were exposed in the breach?
Exposed data included names, email addresses, phone numbers, shipping addresses, and purchase details.
Were wallet credentials like seed phrases or private keys compromised?
No, SafePal confirmed that seed phrases, private keys, and wallet passwords were not exposed, and there is no evidence wallets or funds were compromised.
What steps is SafePal taking to protect affected customers?
SafePal took down more than 30 phishing websites, reduced data retention to 90 days, notified affected customers, and hired an independent security firm to audit the fix.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

