Data of Almost 40,000 SafePal Hardware Wallet Users Exposed to Third Parties

cryptonews.ruPublished on 2026-08-17Last updated on 2026-08-17

Abstract

Hardware crypto wallet manufacturer SafePal has disclosed a data breach affecting approximately 39,798 users. On August 16, the company announced that leaked information includes customer names, delivery addresses, phone numbers, email addresses, and order details. However, sensitive data such as seed phrases, private keys, passwords, bank details, and card numbers were not compromised, as SafePal states it does not collect or store this information. An internal investigation found no evidence that attackers accessed user wallets or funds. The primary risk for affected customers is targeted social engineering attacks. Scammers may use the leaked order details to pose as customer support, offering fake refunds, urging firmware updates, or sending phishing links. SafePal is monitoring and taking down such fraudulent sites and warns users to be cautious of any communication referencing their order information. The breach originated from an authorization vulnerability in a third-party order-tracking plugin, which allowed unauthorized access to other customers' order data. The issue affected orders placed between March 2, 2025, and April 11, 2026. The company has since patched the vulnerability and strengthened its system protections. In response, SafePal is conducting a joint investigation with an independent security firm and auditing its entire order processing system. Additional measures include reducing data retention in the affected system to 90 days and notifying logisti...

The manufacturer of SafePal hardware crypto wallets has reported a data leak affecting approximately 39,798 users. The company disclosed the incident on August 16, clarifying that third parties gained access to customer names, delivery addresses, phone numbers, email addresses, and order information.

However, seed phrases, private keys, passwords, bank details, card numbers, and document numbers were not affected by the leak—SafePal initially does not collect or store such information. The project team has inspected its systems and found no signs that malicious actors gained access to user wallets or funds.

The Danger of the Leak for Customers

The developers warned: even without access to cryptocurrency assets, the leaked data provides grounds for targeted attacks. Scammers may call or write to customers posing as support staff, offer "refunds," persuade them to update device firmware, or send links to phishing resources impersonating the SafePal website.

The company is already tracking the appearance of such fake resources and working to get them blocked. Customers should be cautious of any communications that mention details of their orders—precisely this information may now be used to make messages appear credible.

Error in Order Tracking Plugin

According to SafePal, the leak occurred due to a vulnerability in the order tracking plugin linked to customer data. An authorization flaw in it allowed an unauthorized user to access orders of other customers—meaning they could see someone else's information where only their own should have been displayed.

By the time of the statement's publication, the developers had already fixed the issue and strengthened system protection measures. The incident affected those who placed orders between March 2, 2025, and April 11, 2026. When exactly the malicious actors exploited the vulnerability and when the project team discovered it was not specified by the company.

What SafePal is Doing Next

The manufacturer is currently investigating the incident in collaboration with an independent security company and preparing an audit of the entire order processing system. Among the measures taken are reducing the data retention period in the affected system to 90 days, notifying logistics partners with a request to check if the issue impacted their own systems, fixing the vulnerability in the plugin, and strengthening access controls to customer data.

Thus, the leak did not jeopardize the cryptocurrency assets of SafePal users, but it exposed enough personal data to organize fraudulent schemes through social engineering. The company states that it will continue to monitor the situation and investigate together with external security experts.

AI Opinion

Analysis reveals a clear industry pattern: the SafePal incident is already the third case of customer contact data leakage from hardware wallet manufacturers in recent years, and each time malicious actors use the same scheme—phishing emails sent impersonating support. A similar story happened with Ledger in 2020 when data of a million customers leaked, and victims were then pursued by fraudulent mailings for months, including fake devices by mail. Trezor faced the same problem very recently.

A technical aspect left outside the article's scope: the vulnerability arose not in the hardware wallet itself, but in a third-party order tracking plugin—this points to a weak link not in the devices' cryptography, but in auxiliary web services that companies connect to their platforms. Moreover, the leak's timeframe—over a year—raises questions: how many more such vulnerabilities in manufacturers' adjacent systems remain unnoticed until the data starts being used against the customers themselves?

Trending Cryptos

Related Questions

QAccording to the article, what type of user data was leaked in the SafePal incident?

AThe leaked data included customer names, delivery addresses, phone numbers, email addresses, and order details. However, sensitive information like seed phrases, private keys, passwords, bank details, card numbers, and identification documents was not compromised, as SafePal does not collect or store such data.

QWhat is the primary security risk for SafePal customers following this data leak, as mentioned in the article?

AThe primary risk is targeted attacks using social engineering. Scammers can use the leaked personal and order information to impersonate SafePal support, call or message customers, offer 'refunds,' convince them to update device firmware, or send phishing links to fake websites, making their schemes appear more legitimate.

QWhat was identified as the specific cause of the data breach at SafePal?

AThe breach was caused by a vulnerability in an order tracking plugin. An authorization error in this plugin allowed unauthorized users to access the orders and personal information of other customers, seeing data that should only have been visible to the account owner.

QWhat period of time did the SafePal data breach affect, and what key actions did the company take in response?

AThe breach affected customers who placed orders between March 2, 2025, and April 11, 2026. In response, SafePal fixed the vulnerability, strengthened system protections, reduced data retention in the affected system to 90 days, notified logistics partners, initiated a full order system audit with an independent security firm, and is continuing its investigation with external experts.

QHow does the article's 'AI Opinion' section contextualize the SafePal incident within the hardware wallet industry?

AThe 'AI Opinion' notes this is the third such leak of customer contact data from hardware wallet companies in recent years, following similar incidents at Ledger (2020) and Trezor. It highlights a pattern where attackers use the data for phishing campaigns impersonating support. It also points out that the vulnerability was not in the cryptographic security of the hardware wallet itself, but in a third-party web service plugin, suggesting auxiliary systems are a weak link.

Related Reads

U.S. Bancorp Stablecoin USBDC: U.S. Bancorp Conducts Pilot Transfer via Stellar

U.S. Bancorp has successfully conducted a pilot transaction using its USBDC stablecoin on the Stellar blockchain. The test involved a cross-border transfer between the bank's divisions in North America and Europe, utilizing its internal digital asset platform to evaluate the real-world performance of the dollar-pegged digital currency. The pilot tested key functions, including token issuance and redemption, fund freezing, and transaction clawbacks. This demonstrates the bank's focus on combining transaction speed with risk control and compliance in payment infrastructure. U.S. Bancorp's move into stablecoins reflects the broader financial sector's interest in blockchain-based payments. These assets are seen as a way to modernize wire transfers, accelerate international settlements, and integrate new financial technology into existing processes. The article highlights the established USDC stablecoin as a benchmark, noting its emphasis on transparent reserves and regulatory compliance. This pilot is part of a larger trend where traditional financial institutions, including other major banks reportedly planning a joint stablecoin project, are exploring cryptocurrency not just as an investment but as a settlement technology. The key challenge for widespread adoption will be achieving interoperability between these new digital payment systems and the existing banking infrastructure. While not an immediate mass launch, U.S. Bancorp's test signals that major banks are actively investigating how digital currencies can operate alongside traditional finance.

cryptonews.ru5m ago

U.S. Bancorp Stablecoin USBDC: U.S. Bancorp Conducts Pilot Transfer via Stellar

cryptonews.ru5m ago

Vitalik Buterin Announces Good News About New Ethereum Update

Vitalik Buterin, co-founder of Ethereum, has proposed EIP-8288, aimed at drastically reducing the cost of transactions that are resistant to quantum attacks. Named the recursive STARK mempool, this proposal is intended for inclusion in the planned I-star upgrade following the Hegota update. The goal of EIP-8288 is to move signatures and cryptographic proofs outside Ethereum's main execution process, bundling them with recursive STARK proofs within the transaction pool. This is designed to significantly reduce both the computational load on the blockchain and data costs. According to Buterin, the system offers major advantages, particularly for quantum-secure signatures and privacy-focused protocols. Currently, the cost of a privacy-preserving, quantum-secure transaction can reach around 10 million gas, but with EIP-8288, it is projected to fall to tens of thousands of gas. The proposal can also support next-generation signature systems or proofs of work, such as Falcon and ML-DSA, without requiring changes to the Ethereum Virtual Machine (EVM). It may pave the way for privacy-enhancing applications in account abstraction. In the proposed system, Ethereum nodes would periodically bundle transaction dependencies to generate recursive STARK proofs. Block builders would then generate the necessary proofs for including transactions in a block. The system's overhead is estimated at roughly 100–300 KB of STARK proofs per block and 96 bytes of extra data per verified claim. Buterin added that this approach could help establish a RISC-V architecture as a standard instruction set for recursive STARK transactions within the Ethereum ecosystem. If included in the I-star upgrade, EIP-8288 would represent a significant advance for Ethereum's long-term quantum resilience and privacy infrastructure.

cryptonews.ru50m ago

Vitalik Buterin Announces Good News About New Ethereum Update

cryptonews.ru50m ago

Trading

Spot

Hot Articles

How to Buy DATA

Welcome to HTX.com! We've made purchasing DATA Network (DATA) simple and convenient. Follow our step-by-step guide to embark on your crypto journey.Step 1: Create Your HTX AccountUse your email or phone number to sign up for a free account on HTX. Experience a hassle-free registration journey and unlock all features.Get My AccountStep 2: Go to Buy Crypto and Choose Your Payment MethodCredit/Debit Card: Use your Visa or Mastercard to buy DATA Network (DATA) instantly.Balance: Use funds from your HTX account balance to trade seamlessly.Third Parties: We've added popular payment methods such as Google Pay and Apple Pay to enhance convenience.P2P: Trade directly with other users on HTX.Over-the-Counter (OTC): We offer tailor-made services and competitive exchange rates for traders.Step 3: Store Your DATA Network (DATA)After purchasing your DATA Network (DATA), store it in your HTX account. Alternatively, you can send it elsewhere via blockchain transfer or use it to trade other cryptocurrencies.Step 4: Trade DATA Network (DATA)Easily trade DATA Network (DATA) on HTX's spot market. Simply access your account, select your trading pair, execute your trades, and monitor in real-time. We offer a user-friendly experience for both beginners and seasoned traders.

2.3k Total ViewsPublished 2026.07.01Updated 2026.07.01

How to Buy DATA

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of DATA (DATA) are presented below.

活动图片