Crypto news

16.08.2026
15:31

Data leak at SafePal: 40,000 users at risk of phishing

hack

The hardware cryptocurrency wallet manufacturer SafePal has disclosed a serious incident affecting nearly 39,798 customers. As a result of the leak, confidential data—names, shipping addresses, phone numbers, email addresses, and order details—ended up in the hands of third parties. This is an alarming signal for the entire sector, given that such attacks are becoming increasingly systemic.

It is important to emphasize: critical information such as seed phrases, private keys, passwords, and banking details was not compromised. SafePal does not store this data on its servers, which is proper architectural practice for hardware wallets. At this time, there is no evidence that attackers gained access to funds or the users' devices themselves.

Attack Mechanism and Risks

The root of the problem is an authorization flaw in the order tracking plugin that was integrated with customer data. The plugin incorrectly handled access rights, allowing unauthorized individuals to view other users' orders. Developers have already fixed the vulnerability and strengthened security measures, but the incident affected orders placed between March 2, 2025, and April 11, 2026.

The main threat now is targeted phishing attacks. With personal data in hand, attackers can impersonate SafePal support, offer fake refunds, demand firmware updates, or redirect users to fraudulent websites. The project team is already monitoring phishing resources and working to have them blocked, as well as conducting a joint investigation with independent security experts.

In response to the incident, SafePal has reduced the data retention period in the order processing system to 90 days and notified logistics partners to check their systems for compromise. This is a reasonable step, given that a similar situation occurred with Trezor just a few days ago—on August 13, a leak through the logistics partner ShipMonk affected nearly 14,000 customers.

My analysis: This case highlights that even the most secure hardware wallets are vulnerable at the ecosystem level—through third-party services and plugins. For the industry, this is a lesson: security must be end-to-end, from code to supply chain. As for users, I recommend being extremely cautious with any messages referencing SafePal and always manually verifying website addresses.