Crypto news

17.08.2026
05:59

Data breach at SafePal: 40,000 users at risk of phishing

hack

Hardware crypto wallet manufacturer SafePal has disclosed a large-scale incident affecting approximately 39,798 customers. Personal data fell into the hands of third parties: names, shipping addresses, phone numbers, email addresses, and order details. This is a serious blow to privacy, but critically, attackers did not gain access to seed phrases, private keys, or financial information. The company does not store this data, and no signs of wallet compromise have been detected.

Nevertheless, the leak creates fertile ground for targeted attacks. Scammers can now call, write, or send phishing messages on behalf of SafePal support, offering "refunds" or demanding firmware updates. The project team is already monitoring fake resources and working to block them.

Root of the problem

The cause of the leak was an authorization flaw in the order tracking plugin. The system incorrectly handled access rights, allowing an outsider to view other customers' orders. As of the statement's publication, developers had already fixed the vulnerability and strengthened security. The incident affected orders placed between March 2, 2025, and April 11, 2026, though the exact timing of the attack and its discovery has not been disclosed.

SafePal is currently conducting an investigation with an independent security company and preparing an audit of the entire order processing system. In accordance with legislation, the data retention period has been reduced to 90 days, and logistics partners have been notified of the need to review their systems.

This is already the second such case within a week. Earlier, on August 13, the Trezor project faced a data leak of nearly 14,000 customers due to a breach at logistics partner ShipMonk. The trend is alarming: even hardware wallets that protect crypto assets are vulnerable at the level of personal data processing.

My conclusion: The incident highlights that security in the crypto industry is not limited to protecting keys. Phishing through leaked data is a silent threat that can lead to loss of funds if the user does not remain vigilant. Always check website addresses and do not trust messages, even if they look official. Security is a comprehensive process, and it should only be entrusted to those who treat it with the utmost seriousness.