Data breach at SafePal: data of 40,000 users at risk

On August 16, hardware crypto wallet manufacturer SafePal officially confirmed a personal data leak incident affecting approximately 39,798 users. Customer names, shipping addresses, phone numbers, email addresses, and order details fell into the hands of third parties. This is a serious signal for the entire industry, given that such data is an ideal foundation for targeted phishing attacks.
It is important to emphasize: critical financial information has not been compromised. Seed phrases, private keys, passwords, banking details, and card data are not stored on SafePal's servers, so attackers did not gain access to users' wallets or funds. The project team found no traces of unauthorized access to client assets.
However, the leak creates fertile ground for social engineering. Attackers may impersonate support services, offer "refunds," demand firmware updates, or lure victims to phishing websites. SafePal is already monitoring fake resources and actively working to have them blocked, but users should remain extremely vigilant.
Cause and Scope of the Incident
The root of the problem is an authorization flaw in the order tracking plugin integrated with client data. The plugin incorrectly handled access permissions, allowing unauthorized individuals to view other users' orders. By the time the statement was published, the vulnerability had already been fixed, and protective measures were strengthened.
The incident affected customers who placed orders between March 2, 2025, and April 11, 2026. The exact dates of the vulnerability's exploitation and discovery have not been disclosed. SafePal is currently conducting an investigation together with an independent security company and plans a full audit of the order processing system.
In accordance with legislation, the data retention period has been reduced to 90 days, and logistics partners have been notified of the need to check their systems for compromise. Notably, this is the second such case within a week: on August 13, the Trezor project reported a similar leak affecting nearly 14,000 customers, whose logistics partner ShipMonk was hacked.
My analysis: This situation is yet another reminder that even hardware wallets, which protect keys from digital threats, are vulnerable at the infrastructure level. Users should treat any messages from "support" as potential phishing and always double-check website addresses. The industry, in turn, needs to consider standardizing the security of personal data processing, otherwise such leaks will become a systemic problem.