SafePal Data Breach: Nearly 40,000 Users at Risk of Targeted Attacks

On August 16, hardware crypto wallet manufacturer SafePal officially confirmed an incident affecting the personal data of approximately 39,798 customers. Names, delivery addresses, phone numbers, email addresses, and order details fell into the hands of third parties. This is a serious signal for the entire sector, given the sensitivity of the hardware wallet audience.
It is important to emphasize: the leak did not affect seed phrases, private keys, passwords, or banking information. SafePal does not store this data in principle, which rules out direct financial harm to users. The project team found no traces of unauthorized access to customer funds or wallets.
However, the main threat lies elsewhere. Attackers now possess a sufficient volume of data to conduct targeted phishing attacks. They can impersonate SafePal support, offer "refunds," demand "firmware updates," or direct users to fake websites. The company is currently actively monitoring fraudulent resources and working to have them blocked.
Cause of the incident
The root of the problem is an authorization flaw in the order tracking plugin integrated with the customer database. The plugin incorrectly processed requests, allowing an unauthorized party to view other users' orders. By the time the statement was published, the vulnerability had been fixed and protective measures strengthened.
The incident affected customers who placed orders between March 2, 2025, and April 11, 2026. The exact dates of the vulnerability's exploitation and its discovery have not been disclosed. SafePal is currently conducting an investigation together with an independent security company and plans a full audit of the order processing system.
In accordance with regulatory requirements, the data retention period has been reduced to 90 days, and logistics partners have been notified of the need to check their systems. This is a sensible step, but it does not negate the fact that the leak has already occurred.
Notably, just three days earlier, on August 13, a similar incident occurred with Trezor — nearly 14,000 customers were affected due to a breach at logistics partner ShipMonk. Two major players in the hardware wallet market faced leaks within one week — this is an alarming trend indicating systemic weaknesses in data handling.
My analysis: Although user funds are safe, the main lesson here is distrust of any incoming messages. In an era when even hardware wallet manufacturers become victims of leaks, two-factor authentication and cold storage are only part of the protection. It is critically important to double-check any requests for "updates" or "verification" through official channels, bypassing links from emails and SMS.