Hardware wallet manufacturer SafePal has reported a security incident that resulted in unauthorized access to order data for approximately 39,798 customers by third parties. The cause was an authorization error in the order tracking function associated with a related plugin. The incident could pose a risk of targeted phishing and fraud attacks against cryptocurrency wallet owners.
"We recently identified a flaw in the order tracking plugin that led to unauthorized access to information for a portion of customers," the company stated.
The incident affects users who placed orders between March 2, 2025, and April 11, 2026. Information that may have fallen into the hands of third parties includes name, email address, shipping address, phone number, as well as purchase and order details.
SafePal emphasized that seed phrases, private keys, passwords, and other wallet credentials were not compromised. The leak also did not involve bank account numbers, payment card numbers, or government-issued identity documents.
"This incident did not involve your seed phrase, private keys, wallet password, or other wallet credentials, bank account information, payment card numbers, or government-issued documents," SafePal stated.
SafePal Fears Phishing Attacks
The company has already addressed the identified vulnerability and implemented additional security measures. Affected customers were notified by individual emails from security@safepal.com on August 16.
The primary risk following the leak is not the direct theft of cryptocurrency, but the potential use of the obtained information to carry out more convincing attacks.
Malicious actors may attempt to impersonate SafePal and contact users via:
- email, phone calls, or SMS;
- fake refund offers;
- messages claiming firmware updates are needed;
- fake customer support;
- fraudulent websites and QR codes;
- letters or physical parcels related to SafePal orders.
The company urged users never to share their seed phrase, private key, or password, even if the request appears to come from someone claiming to be a SafePal employee.
SafePal also reported that it has already taken down over 30 fraudulent websites and phishing links related to such activity and continues to monitor for new domains.
To check if a specific order was affected by the incident, the company published a separate page where users can enter their order number and shipping country.
Company Tightens Control Over Customer Data
SafePal stated that it is engaging an independent third-party cybersecurity firm to verify the fix and conduct a broader audit of its order processing systems.
Furthermore, the company has:
- reduced the retention period for personal data in the relevant environment to 90 days, unless otherwise required by law;
- created a dedicated support channel for affected customers;
- initiated checks on third-party logistics and fulfillment partners' systems;
- continued collecting user reports on fraudulent activity.
SafePal specifically noted that users do not need to move their crypto assets solely because their order data was exposed to third parties.
At the same time, if a wallet owner has already shared their seed phrase or private key in response to a suspicious message or via a fraudulent website, the company recommends considering that wallet compromised and moving the remaining assets to a new wallet created using a trusted device or the official SafePal app.
The incident comes amid a series of recent leaks affecting hardware crypto wallet users. In particular, following the hack of Trezor's logistics partner, 13,689 customers were put at risk of targeted phishing attacks, although the manufacturer's own systems and devices were also not compromised.
Previously, a large-scale attack on Coldcard also sparked significant reaction among Bitcoin holders: following the $100M+ incident, long-term holders moved approximately 210,000 BTC, marking one of the largest coin movements in this category in 2026.






