Crypto news

17.08.2026
07:20

SafePal data breach: nearly 40,000 hardware wallet users at risk of phishing

hack

On August 16, hardware crypto wallet manufacturer SafePal officially confirmed a data breach incident affecting approximately 39,798 users. Names, shipping addresses, phone numbers, email addresses, and order details of customers fell into the hands of third parties.

It is important to emphasize: critical financial information has not been compromised. Seed phrases, private keys, passwords, bank details, and payment card data are not stored on SafePal's servers, so attackers did not gain access to users' funds. At this time, there are no signs of unauthorized transactions or wallet breaches.

Nevertheless, the threat remains serious. The leak of personal data opens a wide field for targeted phishing attacks. Attackers may contact victims posing as support staff, offer "refunds," demand "firmware updates," or redirect them to fake websites. The SafePal team is already monitoring phishing resources and actively working to get them blocked.

Cause of the Incident

The root of the problem is an authorization flaw in the order tracking plugin. This component, which handles customer data, incorrectly processed access rights, allowing outsiders to view other users' orders. By the time the statement was published, the vulnerability had been fixed and protective measures strengthened.

The incident affected customers who placed orders between March 2, 2025, and April 11, 2026. The company has not disclosed the exact time the vulnerability was exploited or when it was discovered. SafePal is currently conducting an investigation together with independent security experts and plans a full audit of the order processing system.

As a preventive measure, the company reduced the data retention period in this system to 90 days and notified logistics partners, asking them to check their own systems for compromise.

This is the second such case within a week. Earlier, on August 13, the project Trezor reported a similar leak—a breach at logistics partner ShipMonk led to the disclosure of data from nearly 14,000 customers.

My comment: This series of incidents is a warning sign for the entire industry. Hardware wallets remain one of the safest ways to store crypto assets, but their manufacturers are also companies with customer bases that process personal data. Attacks are shifting from the devices themselves to infrastructure and supply chains. Users should be extremely vigilant: any messages about "wallet issues" or "firmware updates" should only be verified through official channels. Your seed phrase is the only thing attackers cannot steal unless you reveal it yourself.