Data breach at SafePal: compromise affected nearly 40,000 users

On August 16, hardware crypto wallet manufacturer SafePal officially confirmed a data breach affecting approximately 39,798 users. Customer names, shipping addresses, phone numbers, email addresses, and order details fell into the hands of third parties. This is a serious incident that requires close attention from holders of the brand's devices.
It is important to emphasize that critical financial information—seed phrases, private keys, passwords, banking details, and payment card data—was not compromised. SafePal does not store this data on its servers, which is a security standard for the industry. As of now, the project team has found no signs of unauthorized access to users' wallets or funds.
However, the leak of personal data opens a wide field for targeted attacks. Armed with such information, attackers can impersonate support staff, call, message via messengers, offer fake refunds, or demand "firmware updates," redirecting victims to phishing sites. Currently, SafePal is actively monitoring fake resources and working to have them blocked.
Cause of the incident and scope
The root of the problem lies in an authorization error in the order tracking plugin that was linked to customer data. The plugin incorrectly handled access rights, allowing an outsider to view other customers' orders. Developers have already fixed the vulnerability and strengthened protective measures as of the time of the statement's publication.
The incident affected customers who made purchases between March 2, 2025, and April 11, 2026. The exact timeframe of the vulnerability's exploitation and the moment of its discovery have not been disclosed, raising certain questions about the transparency of the process. The company is currently conducting an investigation with independent security experts and plans a full audit of the order processing system.
In accordance with legal requirements, SafePal has reduced the data retention period in this system to 90 days and notified logistics partners, asking them to check their own systems for compromise.
This is already the second such case within a week. Earlier, on August 13, a similar situation occurred with the Trezor project, where a breach of logistics partner ShipMonk led to a data leak for nearly 14,000 customers. This series of incidents points to a systemic problem in the industry: the security of hardware wallets is often higher than the security of associated services, such as logistics and support.
My analysis: This incident is another reminder that even the most reliable hardware wallets are vulnerable through the ecosystem around them. SafePal users should be extremely vigilant: do not click suspicious links in SMS and emails, ignore any calls from "support," and always manually verify website addresses. The storage of funds has not been affected, but your personal information is now in the hands of attackers, creating long-term risks for social engineering.