Crypto news

16.08.2026
16:43

SafePal Data Breach: 40,000 Users at Risk of Phishing Attacks

hack

On August 16, hardware crypto wallet manufacturer SafePal officially confirmed a data breach incident affecting approximately 39,798 users. Customer names, shipping addresses, phone numbers, email addresses, and order details fell into the hands of third parties. This is a serious signal for the entire market, given that such data is a goldmine for scammers.

It is important to emphasize: the incident did not affect critically sensitive information. Seed phrases, private keys, passwords, banking details, and card numbers were not compromised, as SafePal does not store this data on its side. The project team states that it found no traces of unauthorized access to users' wallets or funds. However, this is no reason for complacency.

The main threat now is targeted phishing attacks. With personal data in hand, attackers can impersonate SafePal support: call, write in messengers, offer "refunds," demand "firmware updates," or redirect to fake websites. The company is already monitoring fake resources and working to get them blocked, but users should exercise maximum vigilance.

The root of the problem and the team's response

The cause of the breach was an authorization error in the order tracking plugin integrated with customer data. The plugin incorrectly handled access requests, allowing outsiders to view other customers' orders. By the time the statement was published, developers had already fixed the vulnerability and strengthened protective measures.

The incident affected customers who placed orders from March 2, 2025, to April 11, 2026. The exact dates when attackers exploited the vulnerability and when it was discovered have not been disclosed. SafePal is currently conducting an investigation together with an independent security company and plans a full audit of the order processing system.

In accordance with legal requirements, the company reduced the data retention period in this system to 90 days and notified logistics partners, asking them to check their systems for compromise. Notably, this is already the second such case in a week: on August 13, Trezor faced a data breach of nearly 14,000 customers due to a hack of logistics partner ShipMonk.

My analysis: This series of incidents demonstrates a systemic problem in the hardware wallet industry—the vulnerability lies not in the devices themselves, but in peripheral infrastructure: logistics, plugins, support. Users should remember: even if your coins are safe, your personal data can become a target. Never share seed phrases or click links from suspicious messages, even if they look official.