SafePal discloses data breach: 40,000 users at risk of targeted attacks

On August 16, hardware crypto wallet manufacturer SafePal officially confirmed an incident involving unauthorized access to its customer database. As a result of a vulnerability in the order processing system, personal information of approximately 39,798 users fell into the hands of third parties. The compromised data includes names, shipping addresses, phone numbers, email addresses, and order details.
It is important to emphasize: the incident did not affect security-critical assets — seed phrases, private keys, passwords, banking details, or payment card data. SafePal does not store this information on its servers, which significantly reduces the risk of direct theft of digital assets. According to the investigation conducted, no signs of unauthorized access to wallets or user funds were detected.
Nevertheless, the risks remain high. The personal data leak opens a wide field for targeted phishing attacks. Armed with such information, attackers can impersonate SafePal support staff, call, write in messengers, offer "refunds," demand "firmware updates," or redirect victims to fake websites. Currently, the project team is actively monitoring fraudulent resources and working to get them blocked.
Technical details of the incident
The root of the problem is an authorization flaw in the order tracking plugin. This component, linked to customer data, incorrectly handled access rights, allowing an outsider to view other users' orders. By the time the statement was published, the vulnerability had been fixed and protective measures strengthened.
The incident affected customers who placed orders between March 2, 2025, and April 11, 2026. The company has not yet disclosed the exact timeframe of the vulnerability's exploitation or the moment it was discovered. SafePal is currently conducting a joint investigation with an independent security company and plans a full audit of the order processing system. As a preventive measure, the data retention period in this system has been reduced to 90 days, and logistics partners have been notified and are checking their systems for compromise.
This incident is the second serious leak case in the hardware wallet industry in recent days. Earlier, on August 13, it became known that Trezor's logistics partner was hacked, leading to a data leak of nearly 14,000 customers. An alarming trend is evident: attackers are increasingly targeting not the wallets themselves, but more vulnerable links — processing and logistics systems. This highlights that even the most secure hardware solutions are vulnerable at the ecosystem level, and users need to remain vigilant, especially regarding any incoming messages allegedly originating from manufacturers.