Crypto news

17.08.2026
06:41

SafePal data breach: nearly 40,000 hardware wallet users affected

hack

Hardware cryptocurrency wallet manufacturer SafePal has disclosed a large-scale incident affecting approximately 39,798 customers. Personal data fell into the hands of third parties: names, shipping addresses, phone numbers, email addresses, and order details. This is a serious blow to user privacy, but there is also encouraging news.

Critically important information, such as seed phrases, private keys, passwords, and banking details, remains secure. SafePal does not store this data on its servers, which is the standard for hardware wallets. The project team has found no signs of fund compromise or wallet access.

Nevertheless, the leak opens the door to targeted phishing attacks. Armed with personal data, attackers can call, write, or send messages posing as support staff, offering "refunds," demanding "firmware updates," or redirecting to fake websites. SafePal is already monitoring phishing resources and working to have them blocked.

Cause of the incident

The root of the problem is an authorization flaw in the order tracking plugin. This component incorrectly handled access rights, allowing outsiders to view other customers' orders. By the time the statement was published, developers had already fixed the vulnerability and strengthened security measures.

The incident affected customers who placed orders between March 2, 2025, and April 11, 2026. The exact timeframe of vulnerability exploitation and the moment of its discovery have not been disclosed. SafePal is currently conducting an investigation together with an independent security company and plans a full audit of the order processing system.

In accordance with legal requirements, the company has reduced the data retention period in this system to 90 days and has notified logistics partners, asking them to check their systems for potential impact.

This is already the second similar case in recent days. Earlier, on August 13, the Trezor project faced a similar issue: a breach of logistics partner ShipMonk led to the leak of personal data from nearly 14,000 customers.

My analysis: This leak is another reminder that even hardware wallets do not protect against the compromise of personal data associated with shipping. Attackers are increasingly using social engineering rather than technical hacking. Users should exercise maximum vigilance and ignore any requests coming from "support"—especially those demanding urgent action or the entry of seed phrases.