Crypto news

16.08.2026
15:54

SafePal data breach: nearly 40,000 users at risk of targeted attacks

hack

On August 16, hardware crypto wallet manufacturer SafePal officially confirmed a data breach incident affecting approximately 39,798 users. Customer names, shipping addresses, phone numbers, email addresses, and order details fell into the hands of third parties. This is a serious signal for the entire market, given the sensitivity of information about digital asset holders.

It is important to emphasize: the breach did not affect seed phrases, private keys, passwords, banking details, or payment card data. SafePal does not store such information in principle, which rules out direct access by attackers to user funds. The project team found no traces of unauthorized access to customer wallets or assets.

However, the main threat lies elsewhere. The disclosed personal data is an ideal foundation for targeted phishing attacks. Attackers can impersonate SafePal support, offer refunds, demand firmware updates, or lure victims to fake resources. At present, the company is actively monitoring phishing sites and working to get them blocked.

Cause of the incident and its scope

The root of the problem is an authorization flaw in the order tracking plugin integrated with customer data. The plugin incorrectly handled access rights, allowing outsiders to view other users' orders. By the time the statement was published, developers had already fixed the vulnerability and strengthened protective measures.

The incident affected customers who placed orders between March 2, 2025, and April 11, 2026. SafePal has not disclosed the exact time the vulnerability was exploited or when it was discovered. The company is currently conducting an investigation with independent security experts and plans a full audit of the order processing system. In accordance with regulatory requirements, the data retention period has been reduced to 90 days, and logistics partners have been notified of the need to review their systems.

Notably, just three days earlier, on August 13, a similar incident occurred with Trezor: a breach of logistics partner ShipMonk led to a data leak of nearly 14,000 customers. This series of events demonstrates a worrying trend: even hardware wallets, considered the gold standard of security, are vulnerable at the ecosystem level—through third-party services and data processors.

My comment: For crypto asset holders, this is another reminder: protecting funds is only part of the task. Personal data is an equally valuable target for attacks, and after such breaches, one should be especially vigilant about any incoming messages, even if they look official. Never click links from suspicious emails and never disclose confidential information over the phone.