Crypto news

17.08.2026
04:54

SafePal Data Breach: 40,000 Users at Risk of Phishing

hack

On August 16, hardware crypto wallet manufacturer SafePal officially confirmed a personal data breach affecting approximately 39,798 customers. Names, shipping addresses, phone numbers, email addresses, and order details of users fell into the hands of third parties.

It is important to emphasize: the incident did not affect critically sensitive information. Seed phrases, private keys, passwords, banking details, and document data remained secure — SafePal fundamentally does not store such information on its servers. The project team found no signs of unauthorized access to wallets or user funds.

However, the main threat lies elsewhere. The personal data breach opens a wide field for targeted attacks: attackers can impersonate support staff, call, write in messengers, offer "fund refunds," or demand "firmware updates." All of these are classic phishing scenarios aimed at stealing funds. Currently, SafePal is actively monitoring fake resources and working to have them blocked.

Cause of the incident

The root of the problem is an authorization error in the order tracking plugin integrated with the customer database. The plugin incorrectly handled access requests, allowing an outsider to view orders of other users. By the time of the statement's publication, developers had already fixed the vulnerability and strengthened protective measures.

The incident affected customers who placed orders between March 2, 2025, and April 11, 2026. The exact timeframe of the vulnerability's exploitation and the moment of its discovery have not yet been disclosed. Currently, SafePal is conducting a joint investigation with an independent security company and plans a full audit of the order processing system.

In accordance with legislation, the company reduced the data retention period in this system to 90 days and notified logistics partners, requesting a review of their systems for compromise.

This is already the second such case within a week. Earlier, on August 13, the Trezor project faced a similar breach: a hack of logistics partner ShipMonk led to the exposure of data from nearly 14,000 customers. The situation clearly demonstrates that even the most secure crypto wallets are vulnerable through third-party services that handle personal data.

My comment: The SafePal and Trezor incidents are a wake-up call for the entire industry. Hardware wallets remain the gold standard for fund security, but their users face the main risk — social engineering. If you receive such a notification, remember: official support will never ask for your seed phrase or private key. Verify any contacts through the project's official channels.