Crypto news

17.08.2026
03:53

SafePal data breach: incident affects nearly 40,000 hardware wallet users

hack

On August 16, hardware crypto wallet manufacturer SafePal officially confirmed a personal data breach affecting approximately 39,798 customers. As a result of the incident, third parties obtained user names, shipping addresses, phone numbers, email addresses, and details of placed orders. This is a serious signal for the entire industry, as even hardware wallets, considered the gold standard of security, prove vulnerable at the level of ancillary services.

It is important to emphasize: the breach did not affect critically sensitive data. Seed phrases, private keys, passwords, banking details, card numbers, and document numbers were not compromised — SafePal fundamentally does not store this information on its servers. The project team stated that it found no signs of unauthorized access to user funds or wallets. Nevertheless, the risks for affected customers remain high.

Attackers who gained access to personal data may use it for targeted phishing attacks. This includes calls and messages impersonating support services, offers of "refunds," demands to update firmware, or redirects to fake websites. SafePal is already monitoring phishing resources and actively working to get them blocked, but users should exercise heightened vigilance.

Cause of the incident and the team's response

The root of the problem lies in an authorization error in the order tracking plugin integrated with the customer database. The plugin incorrectly handled access rights, allowing an outsider to view other users' orders. By the time the statement was published, developers had already fixed the vulnerability and strengthened protective measures. The incident affected orders placed between March 2, 2025, and April 11, 2026, although the exact time of vulnerability exploitation has not yet been disclosed.

SafePal is currently conducting an investigation together with an independent security company and plans a full audit of the order processing system. In accordance with legislation, the data retention period in this system has been reduced to 90 days, and logistics partners have been notified of the need to check their systems for compromise. Notably, just three days earlier, on August 13, a similar incident occurred with Trezor — a breach of logistics partner ShipMonk led to a data leak of nearly 14,000 customers.

My analysis: This wave of incidents in the hardware wallet industry is a wake-up call. Hackers have shifted from attacking the devices themselves to attacking the perimeter: logistics, plugins, support. Users should remember that security is not only about storing a seed phrase in a metal casing, but also about protecting personal information that could become a bridge to your assets. Be prepared for phishing and never disclose confidential data over the phone or in messengers.