SafePal data breach: nearly 40,000 hardware wallet users affected

On August 16, hardware crypto wallet manufacturer SafePal officially confirmed a personal data leak incident affecting approximately 39,798 customers. As a result of unauthorized access, user names, delivery addresses, phone numbers, email addresses, and order details fell into the hands of third parties.
It is important to emphasize: critical financial information was not compromised. Seed phrases, private keys, passwords, bank details, and payment card data were not exposed, as SafePal, according to the team's statement, does not store such information on its servers. At this time, there is no evidence that attackers gained access to user funds or wallets.
However, it is too early to relax. The leak creates fertile ground for targeted phishing attacks. Armed with contact details, attackers can impersonate SafePal support, offer fake refunds, demand "firmware updates," or redirect victims to fraudulent websites. The project team is already monitoring phishing domains and actively working to have them blocked.
Cause of the incident and scale of damage
The root of the problem lies in an authorization error in the order tracking plugin integrated with the customer database. Due to improper handling of access rights, an unauthorized user could view other customers' orders. By the time the statement was published, the vulnerability had been fixed and security measures strengthened.
The incident affected customers who made purchases between March 2, 2025, and April 11, 2026. SafePal has not yet disclosed the exact timeframe of the vulnerability's exploitation or the moment it was discovered. A joint investigation with an independent security company is currently underway, and a full audit of the order processing system is planned.
As a preventive measure, the company reduced the data retention period in the vulnerable system to 90 days and notified logistics partners, asking them to check their systems for compromise. Notably, just a few days earlier, on August 13, a similar issue surfaced at SafePal's competitor, Trezor, where a data leak affected nearly 14,000 customers.
My analysis: This incident is another reminder that even the most secure hardware wallets do not guarantee complete anonymity and safety when it comes to ancillary services such as delivery and logistics. Order data is a weak link in the ecosystem, and users should be extremely cautious with any incoming messages, even if they look official. Vigilance is your greatest asset in the face of a growing number of such attacks.