Data breach at SafePal: compromise affected nearly 40,000 users

On August 16, hardware crypto wallet manufacturer SafePal officially confirmed a data breach incident affecting 39,798 customers. As a result of unauthorized access, user names, shipping addresses, phone numbers, email addresses, and order details fell into the hands of third parties. This is a serious signal for the entire industry, given that such data often becomes the foundation for subsequent phishing attacks.
It is important to emphasize: critical financial information was not compromised. Seed phrases, private keys, passwords, banking details, and payment card data remained secure, as SafePal does not store this information on its servers. The project team found no signs of attempts to access users' wallets or funds, which somewhat lowers the level of alarm but does not eliminate the risks.
The main threat now is targeted attacks. With personal data at their disposal, attackers can impersonate SafePal support: call, write in messengers, offer "refunds," demand "firmware updates," or direct users to phishing websites. The company is already monitoring fake resources and actively working to get them blocked, but users should exercise maximum vigilance.
Cause of the incident and the team's response
The root of the problem is an authorization flaw in the order tracking plugin that was linked to customer data. The plugin incorrectly handled access rights, allowing an outsider to view other customers' orders. By the time the statement was published, the vulnerability had been fixed and protective measures strengthened.
The incident affected orders placed between March 2, 2025, and April 11, 2026. Notably, SafePal has not disclosed the exact time the vulnerability was exploited or when it was discovered, leaving a number of questions. The company is currently conducting an investigation together with independent security experts and plans a full audit of the order processing system.
As part of preventive measures, SafePal reduced the data retention period in this system to 90 days in accordance with legal requirements, and also notified logistics partners, asking them to check their systems for potential impact.
This is already the second such case within a week: on August 13, a similar issue was identified at Trezor, where nearly 14,000 customers were affected due to a hack of logistics partner ShipMonk. This series of incidents points to a systemic vulnerability in the data processing chains of crypto companies, where a focus on blockchain security often leaves the protection of peripheral services in the shadows.
My analytical conclusion: Personal data leaks in hardware wallets are not a code problem but an operational security problem. Users should immediately ignore any incoming requests for "software updates" or "verification" that do not come from official channels. The industry, in turn, needs to reconsider its approach to storing customer data, moving toward minimalist "zero-knowledge" models where even the company itself does not have access to sensitive information.