Crypto news

16.08.2026
20:23

Data breach at SafePal: compromise affected nearly 40,000 users

hack

On August 16, hardware crypto wallet manufacturer SafePal officially confirmed a data breach incident affecting 39,798 users. Customer names, delivery addresses, phone numbers, email addresses, and order details fell into the hands of third parties. This is a serious signal for the entire market, given that such data often becomes the foundation for targeted phishing attacks.

It is important to emphasize: the incident did not affect critically important security elements — seed phrases, private keys, passwords, banking details, card numbers, or document numbers. As the project team explains, such data is not collected or stored on their servers at all. At this time, there is no evidence that attackers gained access to users' wallets or funds.

However, it is too early to relax. The personal data leak creates fertile ground for social engineering. Attackers may already be using the obtained information for calls, sending messages on behalf of SafePal support, offering "fund refunds," demanding firmware updates, or directing users to phishing sites. Developers are currently actively monitoring fake resources and working to get them blocked.

Cause of the incident and the team's response

The root of the problem is an authorization error in the order tracking plugin that was linked to customer data. The plugin incorrectly handled access, allowing outsiders to see other users' orders. By the time the statement was published, the vulnerability had already been fixed and security measures strengthened.

The incident affected customers who placed orders between March 2, 2025, and April 11, 2026. The company has not disclosed the exact dates when attackers exploited the vulnerability or when it was discovered. SafePal is currently conducting an investigation together with an independent security company and plans a full audit of the order processing system.

In accordance with legal requirements, the data retention period in this system has been reduced to 90 days. Logistics partners have also been notified and asked to check their systems for potential impact.

Notably, this is already the second such case within a week. Earlier, on August 13, the Trezor project faced a similar issue when a breach at logistics partner ShipMonk led to a data leak affecting nearly 14,000 customers. This trend highlights the systemic vulnerability of the hardware wallet ecosystem: even with flawless protection of the devices themselves, peripheral services often turn out to be the weak link.

My comment: Users of SafePal and other hardware wallets should exercise heightened vigilance in the coming months. Any unexpected messages about "account issues" or "firmware updates" are a red flag. Always check website addresses manually and never enter your seed phrase on third-party resources. The leak itself is not critical, but its consequences in the form of targeted attacks can be quite significant.