Crypto news

16.08.2026
15:11

SafePal data breach: nearly 40,000 hardware wallet users affected

hack

On August 16, hardware crypto wallet manufacturer SafePal officially confirmed the compromise of personal data belonging to a significant portion of its customer base. As a result of the incident, information on approximately 39,798 users, including names, shipping addresses, phone numbers, email addresses, and order details, fell into the hands of third parties.

It is important to emphasize that critical financial information was not affected. Seed phrases, private keys, passwords, banking details, and payment card data were not compromised, as the company fundamentally does not store such information on its servers. Thorough monitoring has not revealed any signs of unauthorized access to users' wallets or funds.

Nevertheless, the threat remains real. The leak opens up a wide field for targeted phishing attacks: attackers may impersonate SafePal support, offer fake refunds, demand firmware updates, or direct victims to fraudulent web resources. At present, the project team is actively tracking fraudulent sites and working to have them blocked.

Anatomy of the Incident

The root of the problem lies in an authorization error in the order tracking plugin integrated with customer data. The plugin incorrectly handled access rights, allowing an unauthorized person to view other users' orders. By the time the statement was published, the vulnerability had been fixed and protective mechanisms strengthened.

The incident affected customers who made purchases between March 2, 2025, and April 11, 2026. The company has not yet disclosed the exact timeframe of vulnerability exploitation or the moment of its discovery. A joint investigation with an independent auditing firm is currently underway, and a comprehensive audit of the entire order processing system is planned.

As part of preventive measures, SafePal has reduced the data retention period in the vulnerable system to 90 days and has notified logistics partners, requesting a review of their systems for potential impact.

Notably, this is already the second similar case in recent days. Earlier, on August 13, SafePal's competitor, the Trezor project, faced a similar issue when its logistics partner ShipMonk allowed a data leak of nearly 14,000 customers.

My comment: This series of incidents in the hardware wallet industry is a worrying signal. Although user funds are protected, the leak of PII (personally identifiable information) creates fertile ground for social engineering, which remains one of the most effective attack vectors in the crypto space. SafePal and Trezor users should be extremely vigilant and ignore any unsolicited communications allegedly coming from wallet manufacturers.