Crypto news

17.08.2026
01:34

SafePal data breach: compromise affected nearly 40,000 users

hack

On August 16, SafePal, a company specializing in the production of hardware cryptocurrency wallets, officially confirmed a data breach affecting approximately 39,798 customers. As a result of the incident, user names, delivery addresses, phone numbers, email addresses, and order details fell into the hands of third parties.

It is important to emphasize that this incident did not affect data critical to security: seed phrases, private keys, passwords, banking details, card numbers, and document numbers. This is because SafePal fundamentally does not collect or store such sensitive information. Moreover, the project team found no evidence that attackers gained access to users' wallets or funds.

Nevertheless, the developers warn of a high risk of targeted attacks. The personal data leak opens a wide field for fraudulent activities: attackers may call or write to victims, posing as support staff, offering refunds, demanding firmware updates, or redirecting to phishing sites. Currently, the SafePal team is actively monitoring fake resources and working to have them blocked.

Cause and scope of the incident

The root of the problem lies in an authorization error in the order tracking plugin that was integrated with customer data. The plugin incorrectly handled requests for information access, allowing outsiders to view other customers' orders. By the time the official statement was published, the developers had already fixed the vulnerability and strengthened security measures.

The incident affected customers who placed orders between March 2, 2025, and April 11, 2026. SafePal has not disclosed the exact timing of when attackers exploited the vulnerability or when it was discovered. Currently, the company is conducting an internal investigation together with an independent security firm and plans a full audit of the order processing system.

In accordance with legal requirements, SafePal has reduced the data retention period in this system to 90 days and notified logistics partners, asking them to check whether the issue affected their own systems.

Notably, just a few days earlier, on August 13, a similar situation occurred with the Trezor project. A breach of their logistics partner ShipMonk led to the leak of personal information from nearly 14,000 customers. This trend is alarming: the hardware wallet industry, which positions itself as a benchmark of security, is becoming increasingly vulnerable at the level of related services and contractors.

My comment: Incidents like these are a wake-up call for the entire industry. Even if the wallets themselves remain impenetrable, attacks on the perimeter—logistics, plugins, partner systems—are becoming the main threat vector. Users should be extremely vigilant: any messages from "SafePal support" asking for data or directing to a link are almost certainly fraud. Keeping funds safe does not negate the need to protect your personal information.