Data leak at SafePal: nearly 40,000 users at risk of targeted attacks

On August 16, hardware crypto wallet manufacturer SafePal officially confirmed a large-scale data breach incident. As a result of a vulnerability in a third-party order tracking plugin, attackers gained access to personal information of approximately 39,798 customers. Names, shipping addresses, phone numbers, email addresses, and order details fell into the hands of third parties.
It is important to emphasize: the incident did not affect critical data. Seed phrases, private keys, passwords, banking details, and card numbers remained secure — SafePal fundamentally does not store such information. The project team also found no traces of unauthorized access to user wallets or funds.
Threat Analysis and Attack Vectors
However, it is too early to relax. The personal data leak opens a wide field for targeted phishing campaigns. Attackers may use the obtained information for calls and messages impersonating SafePal support, offering "refunds" or demanding "firmware updates." Particularly dangerous are attempts to redirect users to fake resources to steal seed phrases. Currently, the project team is actively monitoring phishing sites and working to get them blocked.
Technical Details and Response Measures
The root of the problem is an authorization flaw in the order tracking plugin, which was integrated with customer data. Incorrect handling of access rights allowed outsiders to view other users' orders. By the time of the statement's release, developers had already fixed the defect and strengthened protective measures.
The incident affected customers who made purchases between March 2, 2025, and April 11, 2026. Notably, SafePal has not yet disclosed the exact timeline of the vulnerability's exploitation or the moment of its discovery. A joint investigation with an independent security company is currently underway, along with plans for a full audit of the entire order processing system.
In accordance with regulatory requirements, the company reduced the data retention period in this system to 90 days and notified logistics partners, requesting checks of their systems for compromise.
This is already the second major incident in the industry in recent days. On August 13, a similar situation occurred with Trezor, where a breach at logistics partner ShipMonk led to a data leak of nearly 14,000 customers. This series of events highlights a systemic problem: even hardware wallet manufacturers, renowned for their security, remain vulnerable through the perimeter of third-party services and logistics chains.
My comment: This leak is another reminder that crypto asset security is not limited to protecting private keys. The entire ecosystem around the wallet, including the marketplace and delivery services, is an attack vector. SafePal users affected by the period of the compromised orders should be extremely vigilant and ignore any incoming requests for "updates" or "verification" — official communications can always be verified through channels listed on the manufacturer's website.