Data breach at SafePal: compromise affected nearly 40,000 users

On August 16, hardware crypto wallet manufacturer SafePal officially confirmed a data breach affecting approximately 39,798 customers. As a result of the incident, personal information ended up in the hands of third parties: user names, delivery addresses, phone numbers, email addresses, and order details.
It is important to emphasize: the incident did not affect critically sensitive information. Seed phrases, private keys, passwords, banking details, card numbers, and document numbers were not compromised — SafePal does not store this data on its side. The project team found no signs of unauthorized access to wallets or user funds, which somewhat mitigates the severity of what happened.
Nevertheless, risks for those affected remain high. Attackers could use the leaked data for targeted phishing attacks: calls impersonating support, messages offering refunds, demands to update firmware, or redirects to fake websites. SafePal is already monitoring phishing resources and actively working to get them blocked.
Cause of the incident
The root of the problem is an authorization flaw in the order tracking plugin integrated with customer data. The plugin incorrectly handled access rights, allowing outsiders to view other users' orders. By the time the statement was published, the vulnerability had been fixed and security measures strengthened.
The incident affected customers who placed orders between March 2, 2025, and April 11, 2026. The exact timeframe of vulnerability exploitation and the moment of its discovery have not been disclosed. SafePal is currently conducting an investigation together with an independent security company and plans a full audit of the order processing system.
In accordance with regulatory requirements, the company reduced the data retention period in this system to 90 days and notified logistics partners, requesting checks of their systems for potential impact.
Notably, this is the second such case within a week. Earlier, on August 13, Trezor faced a similar issue: a breach at logistics partner ShipMonk led to the leak of personal data from nearly 14,000 customers. This series of incidents in the hardware wallet industry raises questions about security standards in supply chains and user data processing.
My comment: Although SafePal emphasizes that user funds were not affected, the leak of personal data is a serious signal for the entire industry. Hardware wallets are positioned as the most secure solution, and any failure in peripheral systems undermines trust in the brand. I recommend affected users be extremely vigilant about any incoming messages, especially those requesting data or asking to follow links.