Crypto news

16.08.2026
22:44

SafePal data breach: nearly 40,000 hardware wallet users affected

hack

On August 16, hardware crypto wallet manufacturer SafePal officially confirmed a serious security incident: personal data of approximately 39,798 customers fell into the hands of third parties. The compromised information includes names, shipping addresses, phone numbers, email addresses, and order details.

A critical point: the leak did not affect seed phrases, private keys, passwords, banking details, or payment card data. SafePal does not store such sensitive information, which significantly reduces the risk of direct theft of funds. As of now, the project team has found no signs of unauthorized access to user wallets or assets.

However, the developers warn of a high likelihood of targeted phishing attacks. Armed with personal data, attackers may impersonate SafePal support, offer fake refunds, demand firmware updates, or redirect victims to fraudulent websites. The company is currently actively monitoring phishing resources and working to get them blocked.

Cause of the incident and its scope

The root of the problem is an authorization flaw in the order tracking plugin that was linked to customer data. The plugin incorrectly handled access requests, allowing outsiders to view other users' orders. By the time the statement was published, the vulnerability had already been fixed, and security measures were strengthened.

The incident affected customers who placed orders between March 2, 2025, and April 11, 2026. Notably, SafePal has not disclosed the exact date the vulnerability was exploited, leaving questions about when the issue was discovered.

The company is currently conducting an investigation together with an independent cybersecurity firm and plans a comprehensive audit of the entire order processing system. Additionally, in compliance with legal requirements, the data retention period in this system has been reduced to 90 days, and logistics partners have been notified of the need to review their systems.

This is already the second such case within a week. Earlier, on August 13, the Trezor project faced a data leak of nearly 14,000 customers due to a breach at logistics partner ShipMonk. This series of incidents highlights a systemic security problem in the hardware wallet ecosystem, where the weak link is often not the devices themselves, but auxiliary services and supply chains.

My analysis: Although user funds are safe, the leak of personal data creates fertile ground for social engineering. In the coming weeks, expect a wave of phishing emails and calls. I strongly recommend SafePal users ignore any messages demanding "urgent action" and always manually verify official website addresses.