grid
Abstract circular gradient with concentric rings in blue, green, yellow, and red fading into black background.
5 min read

SafePal Data Breach Exposes 39,798 Crypto Wallet Owners' Details

SafePal Data Breach
Published on
August 17, 2026

SafePal confirmed a data breach on August 16 that exposed order records for roughly 39,798 buyers of its cryptocurrency hardware wallets.The company traced the incident to an authorization flaw in an order-tracking plug-in. Under certain conditions, that flaw let one request retrieve another customer's order details.

The data breach that SafePal disclosed covers orders placed between March 2, 2025 and April 11, 2026. Exposed fields include names, email addresses, shipping addresses, phone numbers, and purchase details. A threat actor has since advertised the stolen records on a cybercrime forum, though no one has independently verified that the seller holds the data.

What the Breach Did and Did Not Expose

The stolen information sits entirely on the e-commerce side of the business. Order histories and delivery details lived in the order-processing environment. None of it touches the wallet software or the devices themselves.

SafePal stated that the data breach did not expose seed phrases, private keys, wallet passwords, bank details, payment card numbers, or identification documents. The company does not collect those categories at all. Investigators found no evidence that the intrusion reached customer wallets or funds.

That distinction matters, but it does not make the exposure harmless. The data breach handed attackers a precise picture of who buys SafePal hardware, where those people live, and which model they own. For a criminal building a target list, that combination beats a generic marketing database.

How SafePal Uncovered the Data Breach

SafePal received its first warning about the data breach in early May 2026, when a customer reported behaviour consistent with the flaw. Staff treated it as an isolated case. They escalated it into a formal investigation and added protections. The order-processing stack spans internal components, external integrations, and logistics partners, so several explanations stayed plausible.

In July, the team began a full review and rebuild of the order-processing system. That work surfaced the authorization flaw in the plug-in's order-tracking function. Engineers patched it and layered on further controls, and an independent security firm is now validating the fix and auditing the wider system.

SafePal also found that the data breach reached further back than it should have. A configuration error had quietly broken a scheduled data-cleanup process between September 2025 and April 2026. Records that should have aged out stayed live, stretching exposure as far back as March 2025.

A Threat Actor Claims to Be Selling the Records

A seller on a cybercrime forum now claims to hold the stolen order data. The listing cites the same order window and roughly the same customer count that SafePal published about the data breach. That overlap lends the claim some weight without confirming it.

The seller also offers prospective buyers order IDs and shipping countries pulled from the trove. Those samples can go through the company's own exposure-checking page, which turns a customer safety tool into a proof-of-authenticity service for the sale. If the claims hold up, buyers can validate the goods before paying.

No one outside the forum has confirmed that the seller possesses the full dataset. Criminal marketplaces carry a steady volume of recycled and fabricated listings. Until someone independently examines a sample, the sale sits as an allegation.

Why Order Data Puts Wallet Owners at Risk

Phishing built on this material does not need to guess. An attacker can cite a real order number, the correct device model, and a genuine delivery address. Those details strip away most of the cues people rely on to spot a fake. Customers began reporting emails and calls impersonating SafePal in May, months before the data breach became public.

One reported message claimed the X1 hardware wallet carried a newly discovered vulnerability and demanded an urgent firmware update. The link to this incident remains unconfirmed, though the pretext fits the pattern closely. Any approach that ends with a user typing a seed phrase into a webpage achieves what the intrusion could not.

The physical dimension deserves attention too. Confirmed home addresses tied to confirmed crypto ownership support mail-based scams and counterfeit replacement devices arriving unannounced. In rare cases, they support direct coercion. The company has already taken down more than 30 fraudulent websites and phishing links.

What Affected Customers Should Do

SafePal published a verification page where customers can check their orders against the data breach, using an order number and a shipping country. The company also emailed every affected person on August 16. Anyone unsure about a message should verify it through that page rather than replying.

An affected order does not force a hardware replacement or a transfer of funds. The devices remain secure and the keys never left them. Anyone who entered a seed phrase after a suspicious call or website should treat that wallet as compromised. Move the assets to a new wallet on a trusted device.

Legitimate support staff never ask for recovery phrases. Typing the official web address manually beats following any link. An unexpected hardware delivery referencing a past purchase warrants suspicion.

Final Thoughts

Two failures compounded here. One authorization flaw in a plug-in opened the door. A broken retention job then kept fourteen months of order records sitting behind it. The company has closed both gaps, cut its retention window to 90 days, and purged affected personal data from active servers.

For customers, the exposure does not fade with the patch. Order details do not expire, and the people buying them can afford to be patient. SafePal has fixed the flaw, but the data breach will keep feeding phishing attempts for months. The only durable defence is a flat refusal to share wallet credentials with anyone who asks.

Subscribe to newsletter

Subscribe to receive the latest blog posts to your inbox every week.

By subscribing you agree to with our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.