Crypto news

16.08.2026
23:04

SafePal data breach: nearly 40,000 hardware wallet users affected

hack

Hardware crypto wallet manufacturer SafePal has confirmed a serious security incident: on August 16, the company disclosed a data breach affecting approximately 39,798 users. Customer names, shipping addresses, phone numbers, email addresses, and order details fell into the hands of third parties. This is a classic personal data compromise scenario that opens a wide field for social engineering.

It is important to emphasize that the incident did not affect critically sensitive information: seed phrases, private keys, passwords, banking details, and payment card data remained secure. SafePal does not store such information on its servers, which is a sound architectural decision. At present, there is no evidence that attackers gained access to the wallets themselves or to user funds.

However, a personal data leak is not just a leak. It is a tool for targeted attacks. Attackers can now use the obtained information for phishing campaigns: calling victims while posing as SafePal support, offering "refund assistance," demanding "firmware updates," or redirecting to fake websites. The project team is already monitoring phishing resources and working to get them blocked, but users should exercise maximum vigilance.

Cause of the incident

The root of the problem is an authorization flaw in the order tracking plugin that was linked to customer data. The plugin incorrectly handled access rights, allowing outsiders to view other customers' orders. By the time the statement was published, developers had already fixed the vulnerability and strengthened protective measures.

The incident affected customers who placed orders between March 2, 2025, and April 11, 2026. Notably, SafePal has not disclosed the exact time the vulnerability was exploited or when it was discovered, leaving questions about the duration of the impact. The company is currently conducting an investigation together with an independent audit firm and plans to carry out a full audit of the entire order processing system.

In accordance with legal requirements, SafePal has reduced the data retention period in this system to 90 days and has notified logistics partners, asking them to check their systems for compromise.

This is already the second similar case within a week: on August 13, a similar leak occurred at the Trezor project, where nearly 14,000 customers were affected due to a breach at logistics partner ShipMonk. This trend clearly demonstrates that even the most secure hardware wallets are vulnerable at the infrastructure and order processing level.

My comment: This incident is another reminder that security in the crypto industry is not limited to protecting keys. Any data collection point, even a secondary one, becomes a target for attacks. Hardware wallet users should be prepared for a wave of phishing and always check website addresses, as well as ignore any "urgent" requests to update firmware or provide data. Storing funds is only part of the task; protecting personal information is an equally critical aspect.