SafePal data breach: nearly 40,000 users at risk of targeted phishing attacks

On August 16, hardware crypto wallet manufacturer SafePal officially confirmed a data breach affecting a significant portion of its customer base. As a result of the incident, information about 39,798 users fell into the hands of third parties, including names, physical shipping addresses, phone numbers, email addresses, and order details.
It is important to emphasize that this incident is limited in scope and did not affect critically important financial data. Seed phrases, private keys, passwords, banking details, card numbers, and identification documents remain secure, as SafePal by design does not collect or store such information. At this time, there is no indication that attackers gained access to client funds or wallets.
However, the risks associated with the personal data leak should not be underestimated. The obtained information provides an ideal foundation for targeted phishing attacks. Armed with order and contact data, attackers can impersonate SafePal support, offer fake refunds, demand firmware updates, or direct users to fraudulent web resources. The project team is already monitoring phishing sites and taking measures to block them.
Technical Details of the Incident
The root of the problem lies in an authorization flaw in the order tracking plugin integrated with customer data. This plugin incorrectly handled requests for information access, allowing an unauthorized party to view other users' orders. By the time the official statement was published, developers had already fixed the vulnerability and strengthened protective measures.
The incident affected customers who made purchases between March 2, 2025, and April 11, 2026. The company has not yet disclosed the exact timeline of when the vulnerability was exploited and when it was discovered. Currently, SafePal is conducting an internal investigation in collaboration with an independent security firm and plans to carry out a full audit of the entire order processing system.
As preventive measures, the company reduced the data retention period in the vulnerable system to 90 days in accordance with legal requirements, and also notified logistics partners, asking them to check their systems for potential impact.
This is already the second such case in recent days. Earlier, on August 13, the Trezor project faced a similar issue, where a data leak through logistics partner ShipMonk affected nearly 14,000 customers.
My comment: This situation once again demonstrates that even the most reliable hardware wallets are vulnerable at the level of the ecosystem around them. Investors must understand: security is not only about protecting private keys but also about vigilance regarding any communications, especially after data leaks. Targeted phishing using real order data is one of the most dangerous attack vectors, so SafePal users should exercise extreme caution and ignore any suspicious requests to transfer funds or disclose confidential information.