Data breach at SafePal: compromise affected nearly 40,000 users

Hardware crypto wallet manufacturer SafePal has officially confirmed a data breach incident affecting approximately 39,798 customers. Personal information fell into the hands of third parties: names, shipping addresses, phone numbers, email addresses, and order details. This is a serious signal for the entire industry, as even hardware solutions, considered the gold standard of security, prove vulnerable at the level of associated services.
It is important to emphasize: the incident did not affect critically sensitive data — seed phrases, private keys, passwords, banking details, or card numbers. SafePal does not store such information in principle, which confirms the absence of traces of unauthorized access to wallets or user funds. Nevertheless, the leak of personal data opens a wide field for targeted attacks.
Attack vector and potential risks
Attackers, having obtained contact details, can initiate phishing campaigns: call posing as support, offer fake refunds, demand firmware updates, or redirect to fraudulent resources. The SafePal team is already monitoring phishing sites and actively working to get them blocked, but users should exercise heightened vigilance.
The root of the problem is an authorization flaw in the order tracking plugin integrated with customer data. The plugin incorrectly handled access rights, allowing outsiders to view other users' orders. By the time of the statement's publication, developers had fixed the vulnerability and strengthened protective measures. The incident affected orders placed between March 2, 2025, and April 11, 2026, although the exact timeline of vulnerability exploitation remains undisclosed.
Response and lessons for the industry
SafePal is conducting an investigation together with an independent security company and plans a full audit of the order processing system. In accordance with regulatory requirements, the data retention period has been reduced to 90 days, and logistics partners have been notified of the need to check their systems.
Notably, this is already the second such case in a week: on August 13, a similar leak occurred at Trezor through a breach of logistics partner ShipMonk, affecting nearly 14,000 customers. This trend highlights a systemic problem: the security of hardware wallets directly depends on the entire supply chain and order processing. As an analyst, I recommend that users minimize the amount of personal data provided when purchasing equipment and always verify the authenticity of communications purporting to be from manufacturers.