Crypto news

16.08.2026
20:43

SafePal data breach: compromise affected nearly 40,000 hardware wallet users

hack

On August 16, hardware crypto wallet manufacturer SafePal officially confirmed a data breach affecting approximately 39,798 users. As a result of the incident, third parties obtained customers' personal data: names, shipping addresses, phone numbers, email addresses, as well as details of placed orders.

It is important to emphasize: the compromise did not affect critically sensitive information. Seed phrases, private keys, passwords, banking details, and payment card data were not impacted — SafePal does not store this information in principle. The project team found no signs of unauthorized access to users' funds or wallets, which somewhat mitigates the severity of the incident but does not eliminate the risks.

The main threat now is targeted phishing attacks. Armed with contact details, attackers can impersonate SafePal support: call, write, offer "refunds," demand firmware updates, or lure victims to fake websites. Developers are already monitoring phishing resources and working to get them blocked, but users should exercise heightened vigilance.

Cause of the incident

The root of the problem is an authorization flaw in the order tracking plugin integrated with customer data. The plugin incorrectly handled access to information, allowing an unauthorized person to view other users' orders. By the time the statement was published, the vulnerability had been fixed and security measures strengthened.

The incident affected customers who placed orders between March 2, 2025, and April 11, 2026. The exact timeframe of vulnerability exploitation and the moment of its discovery have not been disclosed. Currently, SafePal is conducting an investigation together with an independent security company and plans a comprehensive audit of the entire order processing system.

In compliance with legislation, the company reduced data retention to 90 days and notified logistics partners, requesting checks of their systems for potential impact.

This is already the second such case within a week: on August 13, a similar breach occurred at competitor Trezor, where nearly 14,000 customers were affected due to a hack of logistics partner ShipMonk. The trend is alarming: the hardware wallet industry is facing a rise in attacks on peripheral services rather than on the devices themselves.

My comment: This incident is another reminder that the security of crypto assets depends not only on the reliability of the device but also on the entire data processing chain. SafePal users in the risk zone are strongly advised to ignore any incoming requests for "updates" or "checks" and to always initiate contact with support only through official channels.