Crypto news

16.08.2026
19:04

SafePal discloses data breach: nearly 40,000 hardware wallet users at risk

hack

On August 16, the SafePal team, a well-known manufacturer of hardware crypto wallets, officially confirmed a data breach. The incident affected approximately 39,798 users, whose names, shipping addresses, phone numbers, email addresses, and order details fell into the hands of third parties. This is a serious signal for the entire sector, given the sensitivity of the crypto industry's audience.

It is important to emphasize: the leak did not affect critical assets. Seed phrases, private keys, passwords, and financial information (bank details, card numbers) were not compromised, as SafePal does not store this data on its servers. The project team states that it has found no traces of unauthorized access to user funds or wallets.

However, the main danger lies in the vector of subsequent attacks. With contact details in hand, attackers can launch targeted phishing campaigns: calls pretending to be support, fake refund offers, demands to update firmware, or redirects to fake websites. SafePal is already monitoring such resources and initiating their blocking.

Technical details of the incident

The root of the problem is an authorization flaw in the order tracking plugin integrated with the customer database. The plugin incorrectly handled access rights, allowing outsiders to view other users' orders. By the time the statement was published, the vulnerability had been fixed and protective measures strengthened.

The leak affected customers who made purchases between March 2, 2025, and April 11, 2026. The exact timeframe of vulnerability exploitation and the moment of its discovery have not been disclosed. SafePal is currently conducting an investigation together with an independent security company and is preparing a full audit of the order processing system.

As preventive measures, the company reduced the data retention period in the vulnerable system to 90 days and notified logistics partners, requesting checks of their systems for infection. Notably, this is already the second such case in a week: earlier, on August 13, Trezor faced a data leak of nearly 14,000 customers after its logistics partner ShipMonk was hacked.

My analysis: This situation highlights a systemic problem in the hardware wallet industry—device security does not guarantee the security of the entire supply chain and customer service. Users should be extremely vigilant: any message referencing your order or requiring action on behalf of SafePal should be verified through official channels. I strongly recommend enabling two-factor authentication wherever possible and ignoring any requests to "update firmware" via links from emails or SMS.