SafePal Leaks Data of Nearly 40,000 Hardware Wallet Buyers: Private Keys Intact, Yet Danger Moves Closer to the Physical
Hardware wallet manufacturer SafePal has disclosed a data breach affecting approximately 39,798 customers who placed orders between March 2025 and April 2026. The leak exposed personal information including names, email addresses, phone numbers, physical delivery addresses, and purchase records. The company confirmed that private keys, recovery phrases, wallet passwords, and financial details were not compromised, as the cold storage systems operate in an isolated environment separate from the e-commerce servers.
However, the breach poses significant risks beyond digital theft. Attackers now possess a high-value list of confirmed hardware wallet owners, effectively marking them as likely holders of substantial cryptocurrency. This enables highly targeted social engineering attacks, such as phishing emails referencing real order details, fake hardware deliveries, or phone scams impersonating SafePal support. The company has already identified and taken down over 30 related phishing sites.
A critical aspect of the incident is the delayed disclosure timeline. SafePal acknowledged receiving initial user reports of phishing attempts in May but treated them as isolated. A full investigation began in July, with a public announcement not made until August, leaving users exposed for approximately three months. Furthermore, a configuration error prevented a data-purge routine from deleting old order information as intended, potentially increasing the scope of the leaked data.
The incident highlights a structural paradox in the hardware wallet industry: while the devices are designed to secure private keys offline, the necessary e-commerce process collects sensitive personal data that, if leaked, makes the user a target. This mirrors a similar breach suffered by Ledger in 2020.
Affected users are advised to be extremely vigilant. They should verify if they are impacted via SafePal's dedicated page, treat all unsolicited communications (emails, calls, physical mail) referencing SafePal as suspicious, and never share recovery phrases. Users who may have entered sensitive information on a phishing site must create a new wallet immediately. The breach underscores that in cryptocurrency security, the most vulnerable link is often the human user, not the cryptographic technology.
marsbit1 h fa