Crypto news

16.08.2026
14:51

SafePal data breach: nearly 40,000 hardware wallet users affected

hack

On August 16, SafePal, a well-known manufacturer of hardware crypto wallets, officially confirmed the compromise of personal data belonging to a significant portion of its customer base. As a result of the incident, information about 39,798 users, including their names, shipping addresses, phone numbers, email addresses, and order details, ended up in the hands of third parties.

A critical point is that the leak did not affect financial or cryptographic data. Seed phrases, private keys, passwords, banking details, and card numbers were not compromised, as SafePal fundamentally does not store such information on its servers. The project team found no evidence of unauthorized access to user funds or wallets.

However, the risks should not be underestimated. The leak of personal data opens a wide field for targeted phishing attacks. Armed with such information, attackers can impersonate SafePal support, call or write to victims, offering "refunds," "firmware updates," or redirecting them to fake resources to steal seed phrases. Currently, the project team is actively monitoring phishing domains and working to get them blocked.

Cause and Scope of the Incident

The root of the problem lies in an authorization error in the order tracking plugin. This component, which handles customer data, incorrectly processed access requests, allowing an outsider to view other users' orders. By the time the statement was published, the vulnerability had been fixed and protective measures strengthened.

The incident affected customers who placed orders between March 2, 2025, and April 11, 2026. Notably, SafePal has not disclosed the exact timeframe of the vulnerability's exploitation or the moment it was discovered, leaving several questions about the transparency of the process.

As preventive measures, the company has already reduced the data retention period in the order processing system to 90 days in accordance with legal requirements. Additionally, logistics partners have been notified and asked to check their systems for potential impact. The investigation is being conducted jointly with independent security experts, and a full audit of the entire order processing infrastructure is planned.

This is the second such incident in recent days. Earlier, on August 13, Trezor faced a similar problem when its logistics partner ShipMonk allowed a data leak of nearly 14,000 customers. This series of events highlights a systemic issue: even the most secure hardware wallets are vulnerable through their peripheral services, such as logistics and order processing.

My comment: This case is another reminder that security in the crypto industry is not limited to protecting private keys. Attacks on supply chains and auxiliary services are becoming a favored vector for attackers. Users should remain vigilant, especially when receiving suspicious messages purporting to be from wallet manufacturers, and always double-check official website addresses.