
On August 16, hardware crypto wallet manufacturer SafePal disclosed a data breach affecting approximately 39,798 users. Names, delivery addresses, phone numbers, emails, and order details were exposed to third parties.
The incident did not compromise seed phrases, private keys, passwords, bank details, card numbers, or documents, as SafePal does not collect or store such information. The team found no evidence of unauthorized access to user wallets or funds.
Developers warned that the leaked information could be used for targeted attacks, such as calls, messages, or emails impersonating support, offering refunds, requesting firmware updates, or redirecting to phishing sites. SafePal is currently monitoring fake resources and working to have them blocked.
Cause of the Breach
The vulnerability arose from an authorization error in an order tracking plugin linked to customer data. It improperly handled access, allowing unauthorized parties to view other customers’ orders.
Developers reported that the issue was resolved and security measures were enhanced by the time of the announcement.
The breach affected customers who placed orders between March 2, 2025, and April 11, 2026. SafePal did not specify when the vulnerability was exploited or when it was discovered by the team.
The hardware wallet manufacturer is investigating the incident with an independent security company and plans to audit the entire order processing system.
In compliance with regulations, the company has reduced the data retention period in this system to 90 days and has notified logistics partners, asking them to check if their systems were affected.
Earlier, on August 13, a similar situation occurred with the Trezor project. A breach of its logistics partner ShipMonk led to the leak of personal information of nearly 14,000 customers.
