Hardware cryptocurrency wallet manufacturer SafePal has officially confirmed a personal data breach affecting approximately 39,798 customers. During the incident, disclosed on August 16, user names, shipping addresses, phone numbers, email addresses, and order details fell into the hands of third parties. This is a classic dataset for building targeted phishing campaigns.
It is important to emphasize: critical financial information has not been compromised. Seed phrases, private keys, passwords, bank details, and card data were not stored on the affected servers, so there is no direct threat to user funds. At this time, the project team has found no traces of unauthorized access to wallets or attempts to withdraw assets.
However, the main risk lies in social engineering. With personal data in hand, attackers can impersonate SafePal support, offer "refunds," demand "firmware updates," or direct victims to phishing resources. The project team is currently actively monitoring fake websites and domains, working to have them blocked.
Cause of the incident and scope
The root of the problem is an authorization error in the order tracking plugin integrated with the customer database. The plugin incorrectly handled access rights, allowing an outsider to view other users' orders. Developers stated that the vulnerability has already been fixed and protective measures have been strengthened.
The incident affected customers who made purchases between March 2, 2025, and April 11, 2026. Notably, SafePal has not disclosed the exact dates of vulnerability exploitation or the moment of its discovery, leaving questions about how long the data was in the hands of attackers. As part of the investigation, conducted jointly with an independent security company, a full audit of the order processing system is planned.
As preventive measures, the company has reduced the data retention period in this system to 90 days in accordance with regulatory requirements, and has also notified logistics partners, asking them to check their own systems for compromise.
This is the second such case within a week: previously, the Trezor project faced a similar issue, where a data breach of nearly 14,000 customers occurred through a hack of logistics partner ShipMonk.
My comment: This incident once again highlights that hardware wallet security is useless if the attack targets the human factor and the data processing perimeter. Users of SafePal and Trezor who placed orders during the specified periods should be extremely vigilant about any incoming messages, even if they look official. Always manually check website addresses and ignore any requests for "urgent updates" or "verification" — official support never asks for your seed phrase or private keys.