Crypto news

16.08.2026
14:31

SafePal Data Breach: Personal Information of Nearly 40,000 Users at Risk

hack

On August 16, hardware cryptocurrency wallet manufacturer SafePal officially confirmed a data breach affecting approximately 39,798 users. As a result of the incident, customer names, shipping addresses, phone numbers, email addresses, and order details fell into the hands of third parties. This is a serious signal for the entire market, given the growing activity of phishing schemes in the crypto industry.

It is important to emphasize: the breach did not affect critically sensitive data. Seed phrases, private keys, passwords, banking details, and card data were not compromised, as SafePal does not store this information on its servers. The project team also found no traces of unauthorized access to wallets or user funds. Nevertheless, the risk to customers remains high.

Attackers who obtain personal data can use it for targeted attacks: calling or writing on behalf of support, offering fake refunds, demanding firmware updates, or redirecting to phishing sites. SafePal is already monitoring fake resources and actively working to get them blocked, but users should exercise heightened vigilance.

Cause of the incident and the team's response

The root of the problem is an authorization error in the order tracking plugin that had access to customer data. The plugin incorrectly processed requests, allowing outsiders to view other users' orders. By the time the statement was published, developers had already fixed the vulnerability and strengthened security measures.

The incident affected customers who placed orders between March 2, 2025, and April 11, 2026. The exact timing of when attackers exploited the vulnerability and when the team discovered the issue has not been disclosed. SafePal is currently conducting an investigation with an independent security company and plans a full audit of the order processing system.

In accordance with legal requirements, the company reduced the data retention period in this system to 90 days and notified logistics partners, requesting a review of their systems for potential impact. Notably, this is already the second such case in a week: on August 13, a similar issue was identified at Trezor, where nearly 14,000 customers were affected due to a breach at logistics partner ShipMonk.

My comment: This incident is another reminder that even the most reliable hardware wallets are vulnerable at the level of supporting infrastructure. Users should be cautious with any incoming messages, especially offers of "urgent updates" or "refunds," and always manually verify website addresses.