SafePal data breach: nearly 40,000 hardware wallet users affected

On August 16, hardware crypto wallet manufacturer SafePal officially confirmed a personal data breach affecting approximately 39,798 customers. User names, shipping addresses, phone numbers, email addresses, and order details fell into the hands of third parties. This is a serious incident that requires close attention from crypto asset holders, even though financial funds were not directly affected.
It is important to emphasize: the breach did not affect seed phrases, private keys, passwords, or banking details. The company does not store such sensitive information, and no traces of unauthorized access to user wallets or assets were found. Nevertheless, the personal data breach creates fertile ground for targeted phishing attacks.
Having obtained contact details, attackers may impersonate SafePal support staff. Typical scenarios include calls and emails offering "fund recovery," requests to update device firmware, or redirecting to fake websites. The company has already stated that it is monitoring phishing resources and working to have them blocked.
Cause and Scope of the Incident
The root of the problem is an authorization flaw in the order tracking plugin that was linked to customer data. Due to incorrect handling of access rights, an unauthorized user could view other customers' orders. Developers claim the vulnerability has already been fixed and security measures have been strengthened.
The incident affected only those customers who placed orders between March 2, 2025, and April 11, 2026. The company has not disclosed the exact date the vulnerability was exploited or when it was discovered. An investigation is currently underway with the involvement of independent security experts, and an audit of the entire order processing system is planned.
In accordance with legal requirements, SafePal has reduced the data retention period in this system to 90 days and has notified logistics partners, asking them to check their own systems for compromise.
This is already the second major incident in the industry in recent days. Recall that on August 13, a similar breach occurred at competitor Trezor, whose logistics partner ShipMonk allowed the exposure of data from nearly 14,000 customers.
My comment: The fact that such cases occur with leading hardware wallet manufacturers highlights the ecosystem's main vulnerability—not the devices themselves, but peripheral services and supply chains. Users should be extremely vigilant: if someone calls or writes "from support" asking you to do something urgently, it is almost certainly fraudsters. Official representatives never request seed phrases or demand "updates" via links in emails. Always verify website addresses manually and ignore any incoming requests to transfer funds.