Crypto news

17.08.2026
00:44

Data breach at SafePal: compromise affected nearly 40,000 hardware wallet users

hack

On August 16, hardware crypto wallet manufacturer SafePal officially confirmed a data breach incident affecting approximately 39,798 users. As a result of unauthorized access, customer names, shipping addresses, phone numbers, email addresses, and order details fell into the hands of third parties. This is a serious signal for the entire market, given the sensitivity of such information in the context of the crypto industry.

It is important to emphasize that critical financial information was not compromised. Seed phrases, private keys, passwords, banking details, and payment card data remain safe—SafePal architecturally does not store this data on its servers. The project team found no signs that attackers gained access to users' wallets or funds.

However, the main threat lies in the vector of further attacks. The personal data leak opens a wide field for targeted phishing: attackers may call victims, posing as SafePal support, offering "fund recovery," demanding firmware updates, or redirecting to fake resources. Currently, the company is actively monitoring phishing domains and working to have them blocked.

Cause and Scope of the Incident

The root of the problem is an authorization flaw in the order tracking plugin that was linked to customer data. The plugin incorrectly handled access requests, allowing an unauthorized person to view other users' orders. By the time the statement was published, developers had already fixed the vulnerability and strengthened protective measures.

The incident affected customers who placed orders between March 2, 2025, and April 11, 2026. Notably, SafePal has not disclosed the exact timing of when attackers exploited the vulnerability or when it was discovered. This raises questions about the transparency of the response process.

Currently, the company is conducting an investigation together with an independent security audit firm and plans a full audit of the entire order processing system. In accordance with regulatory requirements, the data retention period in this system has been reduced to 90 days. Logistics partners have also been notified and are checking their systems for compromise.

Notably, this is already the second similar case within a week: on August 13, a similar leak occurred at the Trezor project, where nearly 14,000 customers were affected due to a breach of logistics partner ShipMonk. This series of incidents demonstrates a systemic problem: even the most secure wallets are vulnerable through peripheral services—logistics, CRM, and plugins. I recommend that hardware wallet users be especially vigilant about any incoming communications allegedly from manufacturers and always verify website addresses manually.