Crypto news

17.08.2026
04:13

Data breach at SafePal: nearly 40,000 users at risk of targeted attacks

hack

On August 16, hardware crypto wallet manufacturer SafePal officially confirmed an incident involving the compromise of personal data of approximately 39,798 customers. Names, delivery addresses, phone numbers, emails, and order details fell into the hands of third parties. This is a serious signal for the entire market, given the sensitivity of the crypto industry's audience.

It is important to emphasize: the leak did not affect critically important data — seed phrases, private keys, passwords, banking details, and card numbers. The company does not store such information, which rules out direct access by attackers to user funds. However, this does not reduce the risks: the leaked data is an ideal foundation for social engineering and phishing attacks.

The developers warn that attackers may use the obtained information for targeted attacks: calling or writing on behalf of support, offering "refunds," demanding firmware updates, or redirecting to fake websites. Currently, the SafePal team is actively monitoring phishing resources and working to get them blocked.

Cause of the Incident

The root of the problem is an authorization error in the order tracking plugin that was linked to customer data. The plugin incorrectly handled access, allowing outsiders to view other users' orders. By the time the statement was published, the vulnerability had already been fixed, and protective measures were strengthened.

The incident affected customers who placed orders between March 2, 2025, and April 11, 2026. The company has not disclosed the exact timeline of the vulnerability's exploitation or the moment of its discovery, which raises questions about the transparency of the process.

Currently, SafePal is conducting an investigation together with an independent security company and plans a full audit of the order processing system. In accordance with legislation, the data retention period has been reduced to 90 days, and logistics partners have been notified of the need to check their systems.

This is the second major incident in the industry in recent days: on August 13, a similar leak occurred at Trezor through the breach of logistics partner ShipMonk, affecting nearly 14,000 customers. The trend is alarming — attackers are increasingly targeting not the wallets themselves, but peripheral services.

My comment: In conditions where hardware wallets are considered the gold standard of security, leaks at the logistics and order tracking level are becoming the "weak link." Users should be extremely vigilant: any calls or emails "from support" asking to update firmware or enter a seed phrase are almost certainly phishing. Never trust unverified communication channels.