Crypto news

17.08.2026
00:23

Data breach at SafePal: nearly 40,000 users at risk of phishing

hack

On August 16, hardware cryptocurrency wallet manufacturer SafePal officially confirmed a data breach incident affecting approximately 39,798 customers. As a result of unauthorized access, user names, delivery addresses, phone numbers, email addresses, and order details fell into the hands of third parties. This is a serious signal for the entire market, given the sensitivity of the information handled by such services.

It is important to emphasize that the incident did not affect seed phrases, private keys, passwords, banking details, card numbers, or document numbers. SafePal does not collect or store such data in its infrastructure, which is a key security factor for hardware wallets. At this time, the project team has found no signs that attackers gained access to user funds or wallets, which reduces the level of immediate financial threat.

However, risks for affected customers remain high. The personal data leak opens up a wide field for targeted attacks: attackers can use the obtained information for calls, sending messages on behalf of support, offering refunds, demanding firmware updates, or redirecting to phishing resources. SafePal has already stated that it is monitoring fake websites and working to have them blocked.

Cause of the incident

The root of the problem lies in an authorization error in the order tracking plugin that was linked to customer data. The plugin incorrectly handled access to information, allowing outsiders to view other customers' orders. By the time the statement was published, developers had already fixed the vulnerability and strengthened protective measures.

The incident affected customers who placed orders between March 2, 2025, and April 11, 2026. Notably, SafePal has not disclosed the exact timeframe when the vulnerability was exploited and when it was discovered. The company is currently conducting an investigation together with an independent security organization, and also plans a full audit of the entire order processing system.

In accordance with legal requirements, SafePal has reduced the data retention period in this system to 90 days and notified logistics partners, requesting a review of their systems for potential impact. This is a reasonable step that minimizes consequences in the future.

Notably, this is already the second similar case within a week: on August 13, the Trezor project faced a similar issue, where a breach of logistics partner ShipMonk led to a data leak of nearly 14,000 customers. This trend is alarming: the hardware wallet industry, which positions itself as a benchmark of security, turns out to be vulnerable through its peripheral services—logistics and order processing. This is a reminder that security is a comprehensive system, and the weak link can be found where it is least expected.