Crypto news

16.08.2026
18:43

Data breach at SafePal: 40,000 users at risk of phishing — my analysis of the incident

hack

On August 16, hardware crypto wallet manufacturer SafePal officially confirmed a data breach affecting approximately 39,798 users. Names, shipping addresses, phone numbers, email addresses, and order details of customers fell into the hands of third parties. This is a serious signal for the entire market, especially given that the incident occurred just a few days after a similar issue at competitor Trezor.

What exactly happened

The key point: the breach did not affect seed phrases, private keys, passwords, or financial data. SafePal does not store this information, which confirms their security architecture. The project team found no traces of unauthorized access to user funds. However, this does not reduce the risks: attackers now have enough data for targeted attacks — fake calls from "support," phishing emails offering refunds or demanding firmware updates.

Cause of the vulnerability

The root of the problem is an authorization error in the order tracking plugin that was linked to customer data. The plugin incorrectly handled access, allowing outsiders to view other users' orders. By the time the statement was published, developers had already fixed the bug and strengthened protective measures. The incident affected orders placed from March 2, 2025, to April 11, 2026, but the exact time the vulnerability was exploited remains unknown.

My conclusions and recommendations

This case is a vivid example that even hardware wallets are vulnerable at the level of peripheral services. While funds are safe, the leak of personal data opens a window for social engineering. I strongly recommend that all SafePal users who placed orders during the specified period be extremely cautious: do not click links from suspicious messages, do not share codes, and do not install updates without verification through official channels.

SafePal has already reduced data retention to 90 days, is conducting an audit of the entire order processing system, and is cooperating with independent security experts. However, the industry must learn a lesson: wallet security is not only about cryptography but also about protecting the entire chain of customer data processing. Otherwise, we risk seeing a wave of targeted attacks that could undermine trust in hardware solutions overall.