Crypto news

16.08.2026
19:44

SafePal Data Breach: 40,000 Users at Risk of Targeted Phishing Attacks

hack

The hardware cryptocurrency wallet manufacturer SafePal has disclosed a serious security incident affecting nearly 39,798 customers. During the breach, personal data—names, delivery addresses, phone numbers, email addresses, and order details—fell into the hands of third parties. This is an alarming signal for the entire industry, given that such information is a goldmine for scammers.

It is important to emphasize: the incident did not affect critical data such as seed phrases, private keys, passwords, or banking details. SafePal does not store this information in principle, which rules out direct access by attackers to users' funds. The project team found no traces of unauthorized access to wallets, which somewhat softens the picture but does not diminish the risks for affected customers.

The main threat now is targeted attacks. The leak opens the door to phishing: attackers may call, write, or send messages on behalf of SafePal support, offering "refunds," "firmware updates," or redirecting to fake resources. The team is already monitoring phishing sites and working to have them blocked, but users should exercise maximum vigilance.

Cause of the incident

The root of the problem is an authorization error in the order tracking plugin linked to customer data. The plugin incorrectly handled access, allowing outsiders to view other users' orders. By the time the official statement was published, the vulnerability had been fixed and protective measures strengthened.

The incident affected customers who placed orders between March 2, 2025, and April 11, 2026. The exact timeline of the vulnerability's exploitation and the moment of its discovery have not been disclosed, raising questions about the transparency of the process. Currently, SafePal is conducting an investigation together with an independent security company and plans a full audit of the order processing system.

As part of legal requirements, the company has reduced data retention to 90 days and notified logistics partners, requesting checks of their systems for compromise. This is a reasonable step, given that a similar incident occurred at Trezor just a few days earlier—on August 13, through a breach of logistics partner ShipMonk.

My analysis: This leak is another reminder that even hardware wallets, considered the gold standard of security, are vulnerable at the level of peripheral services. For users, this is a lesson: personal data linked to crypto assets requires the same protection as the keys themselves. I recommend that all SafePal customers within the risk period change their passwords and be extremely cautious with any incoming requests, especially offers of "help" or "updates."