Crypto news

17.08.2026
01:13

SafePal data breach: nearly 40,000 users affected, but keys remain secure

hack

On August 16, hardware crypto wallet manufacturer SafePal officially confirmed a personal data leak incident. As a result of unauthorized access, information on approximately 39,798 customers fell into the hands of third parties. This includes names, shipping addresses, phone numbers, email addresses, and order details.

It is important to emphasize: the incident did not affect critically sensitive data. Seed phrases, private keys, passwords, banking details, and card numbers were not compromised, as SafePal fundamentally does not store this information on its servers. The project team found no signs that attackers gained access to users' wallets or funds.

Nevertheless, risks for affected customers remain high. The personal data leak opens a wide field for targeted phishing attacks. Attackers may use the obtained information for calls and emails impersonating SafePal support, offering "refund processing" or demanding "firmware updates." Fake websites mimicking the official SafePal portal pose a particular danger. The company is already monitoring such resources and actively working to get them blocked.

Cause of the incident and response measures

The root of the problem lies in an authorization error in the order tracking plugin that was integrated with the customer database. Incorrect handling of access rights allowed an unauthorized person to view other users' orders. As of the statement's publication, developers had already fixed the vulnerability and strengthened protective measures.

The incident affected customers who placed orders between March 2, 2025, and April 11, 2026. The exact timeframe when attackers exploited the vulnerability has not been disclosed. Currently, SafePal is conducting an internal investigation together with an independent security company, as well as preparing a full audit of the entire order processing system.

In accordance with legal requirements, the company has reduced the data retention period in this system to 90 days. Additionally, logistics partners have been notified and asked to check their systems for potential impact.

Notably, this is already the second major incident in the industry in recent days. Earlier, on August 13, the Trezor project faced a similar issue, where a breach at logistics partner ShipMonk led to a data leak of nearly 14,000 customers. This trend points to a systemic problem in the hardware wallet ecosystem, where the weak link is not the devices themselves, but auxiliary services and supply chains.

My comment: This case is yet another reminder that user security is determined not only by cryptographic protection of keys, but also by data hygiene on the periphery. The industry has long needed to reconsider its approach to storing personal information, minimizing its collection and using decentralized solutions for delivery. As for users, they should now be extremely vigilant about any incoming messages supposedly from SafePal and check website addresses before entering any data.