Crypto news

16.08.2026
17:04

SafePal Data Breach: Compromise Affects Nearly 40,000 Users

hack

On August 16, hardware crypto wallet manufacturer SafePal officially confirmed a data breach incident affecting approximately 39,798 customers. User names, shipping addresses, phone numbers, email addresses, and order details fell into the hands of third parties.

It is important to emphasize: the compromise did not affect critically sensitive data — seed phrases, private keys, passwords, banking details, card numbers, and identification documents. As explained by the project team, such information is not collected or stored on their servers at all. At this time, there are no signs that attackers gained access to users' wallets or funds.

Nevertheless, risks for affected customers remain. The personal data leak opens the door to targeted attacks: attackers may call, write, or send messages posing as support, offering "fund refunds," demanding "firmware updates," or redirecting to phishing sites. SafePal is already monitoring fake resources and actively working to get them blocked.

Cause of the incident

The root of the problem is an authorization flaw in the order tracking plugin integrated with customer data. The plugin incorrectly handled access rights, allowing outsiders to view other users' orders. By the time of the statement's release, developers had already fixed the vulnerability and strengthened security measures.

The incident affected customers who placed orders between March 2, 2025, and April 11, 2026. However, the company did not specify when exactly the vulnerability was exploited or when it was discovered. SafePal is currently conducting an investigation with an independent security firm and plans a full audit of the order processing system.

In accordance with legal requirements, the data retention period in this system has been reduced to 90 days. Logistics partners have also been notified and asked to check whether the issue affected their infrastructure.

This is the second such case within a week: on August 13, a similar situation occurred with the Trezor project, where a breach of logistics partner ShipMonk led to the leak of personal data from nearly 14,000 customers.

My comment: This incident is another reminder that even hardware wallets, considered the gold standard of security, are vulnerable at the level of the infrastructure around them. Users should be extremely cautious with any incoming messages from "support" and always verify website addresses. The industry, meanwhile, needs to rethink its approach to storing and processing personal data, minimizing collection and retention periods.