Data breach at SafePal: nearly 40,000 hardware wallet users affected

On August 16, hardware cryptocurrency wallet manufacturer SafePal officially confirmed a personal data breach affecting approximately 39,798 customers. As a result of the incident, third parties obtained user names, shipping addresses, phone numbers, email addresses, as well as details of placed orders.
It is important to emphasize that critical financial information was not compromised. Seed phrases, private keys, passwords, bank details, card numbers, and identification documents remained secure, as SafePal fundamentally does not collect or store such data in its systems. As of now, the project team has not detected any signs of unauthorized access to user wallets or funds.
Nevertheless, the threat remains real. Attackers who gained access to the leaked data may use it to conduct targeted phishing attacks. Attempts of calls and messages on behalf of support services, offers of false refunds, demands to update firmware, or redirects to fake web resources are expected. SafePal is already actively monitoring phishing sites and working to have them forcibly blocked.
Cause and Scope of the Incident
The root of the problem lies in an authorization error within the order tracking plugin integrated with customer data. The plugin incorrectly handled access requests, allowing an unauthorized party to view other customers' orders. By the time the official statement was published, developers had already fixed the vulnerability and strengthened security measures.
The incident affected only those customers who made purchases between March 2, 2025, and April 11, 2026. Notably, SafePal has not disclosed the exact date when the vulnerability was exploited by attackers, nor the moment it was discovered by the team. The company is currently conducting an internal investigation together with independent security experts, and also plans a full audit of the entire order processing system.
In accordance with legal requirements, SafePal has reduced the data retention period for user data in this system to 90 days. Additionally, logistics partners have been notified and asked to check their own systems for potential impact.
This is already the second similar case in recent days. Earlier, on August 13, the Trezor project faced a similar issue, where a breach of logistics partner ShipMonk led to a data leak of nearly 14,000 customers.
My comment: This incident is another reminder that even the most reliable hardware wallets are vulnerable at the level of the ecosystem surrounding them. The key issue here is not the security of the devices themselves, but negligence in handling peripheral services. For users, this is a signal: always use separate email addresses and phone numbers for cryptocurrency-related purchases, and be extremely cautious with any incoming messages, even if they look official.