SafePal Data Breach: Nearly 40,000 Users at Risk of Phishing Attacks

On August 16, hardware cryptocurrency wallet manufacturer SafePal officially confirmed a personal data breach incident affecting 39,798 customers. User names, shipping addresses, phone numbers, email addresses, and order details fell into the hands of third parties. This is a serious signal for the entire market, given that such data is a goldmine for social engineers.
It is important to emphasize: critical financial information was not compromised. Seed phrases, private keys, passwords, banking details, and card data were not exposed, as SafePal does not store this information on its servers. The project team found no traces of unauthorized access to wallets or user funds, which reduces the risk of direct financial losses.
Nevertheless, the threat remains high. Attackers could use the leaked contacts for targeted attacks: calls impersonating support, fake refund offers, demands to update firmware, or redirects to phishing websites. Currently, SafePal is actively monitoring fake resources and working to get them blocked, but users should exercise maximum vigilance.
Cause of the incident and response measures
The root of the problem is an authorization flaw in the order tracking plugin integrated with customer data. The plugin incorrectly handled access, allowing outsiders to view other users' orders. By the time the statement was published, the vulnerability had been fixed and security measures strengthened.
The incident affected customers who made purchases between March 2, 2025, and April 11, 2026. The exact timeframe of vulnerability exploitation and the moment of its discovery remain undisclosed, raising questions about the transparency of the investigation process. Currently, SafePal is cooperating with an independent security company and plans to conduct a full audit of the order processing system.
In accordance with regulatory requirements, the company reduced the data retention period in this system to 90 days and notified logistics partners of the need to review their infrastructure. This is a reasonable step, but it highlights a systemic issue: even hardware wallets, considered the gold standard of security, are vulnerable through adjacent services.
Notably, this case is not isolated. Just a few days earlier, on August 13, a similar situation occurred with SafePal's competitor, the Trezor project, where a breach of logistics partner ShipMonk led to a data leak of nearly 14,000 customers. This points to a worrying trend: attackers are increasingly targeting the ecosystem around crypto asset storage rather than the wallets themselves.
My analysis: The hardware wallet market is facing a new wave of risks, where order processing workflows and third-party integrations become the weak link. Users should treat any incoming messages from "support" as potentially malicious and always verify official website addresses. For SafePal, this incident is a test of trust, and how the company conducts its investigation and communication will determine its reputation in the long term.