Hardware Wallet Manufacturer SafePal Discloses Data Leak Affecting Nearly 40,000 Customers

cryptonews.ruPublished on 2026-08-16Last updated on 2026-08-16

Abstract

SafePal, a hardware wallet manufacturer, has disclosed a data breach affecting approximately 39,798 customers. The incident occurred between March 2, 2025, and April 11, 2026, due to an authorization flaw in an order-tracking plugin. Exposed data includes names, email addresses, shipping addresses, phone numbers, and purchase details. The company emphasized that sensitive wallet credentials—such as seed phrases, private keys, and passwords—were not compromised. Bank account details, payment card numbers, and government IDs were also unaffected. The primary risk is now targeted phishing and scam attempts. Attackers may impersonate SafePal via emails, fake refund offers, fraudulent support channels, or malicious websites to steal user credentials. SafePal has patched the vulnerability, notified affected customers, and implemented enhanced security measures, including reducing personal data retention to 90 days and auditing order-processing systems. The firm advises users to never share their seed phrases or private keys, even if contacted by someone claiming to be from SafePal. While moving crypto assets is not necessary due to this breach, users who have already disclosed their credentials should consider their wallets compromised and transfer funds to a new, securely created wallet.

Hardware wallet manufacturer SafePal has reported a security incident that resulted in unauthorized access to order data for approximately 39,798 customers by third parties. The cause was an authorization error in the order tracking function associated with a related plugin. The incident could pose a risk of targeted phishing and fraud attacks against cryptocurrency wallet owners.

"We recently identified a flaw in the order tracking plugin that led to unauthorized access to information for a portion of customers," the company stated.

The incident affects users who placed orders between March 2, 2025, and April 11, 2026. Information that may have fallen into the hands of third parties includes name, email address, shipping address, phone number, as well as purchase and order details.

SafePal emphasized that seed phrases, private keys, passwords, and other wallet credentials were not compromised. The leak also did not involve bank account numbers, payment card numbers, or government-issued identity documents.

"This incident did not involve your seed phrase, private keys, wallet password, or other wallet credentials, bank account information, payment card numbers, or government-issued documents," SafePal stated.

SafePal Fears Phishing Attacks

The company has already addressed the identified vulnerability and implemented additional security measures. Affected customers were notified by individual emails from security@safepal.com on August 16.

The primary risk following the leak is not the direct theft of cryptocurrency, but the potential use of the obtained information to carry out more convincing attacks.

Malicious actors may attempt to impersonate SafePal and contact users via:

  • email, phone calls, or SMS;
  • fake refund offers;
  • messages claiming firmware updates are needed;
  • fake customer support;
  • fraudulent websites and QR codes;
  • letters or physical parcels related to SafePal orders.

The company urged users never to share their seed phrase, private key, or password, even if the request appears to come from someone claiming to be a SafePal employee.

SafePal also reported that it has already taken down over 30 fraudulent websites and phishing links related to such activity and continues to monitor for new domains.

To check if a specific order was affected by the incident, the company published a separate page where users can enter their order number and shipping country.

Company Tightens Control Over Customer Data

SafePal stated that it is engaging an independent third-party cybersecurity firm to verify the fix and conduct a broader audit of its order processing systems.

Furthermore, the company has:

  • reduced the retention period for personal data in the relevant environment to 90 days, unless otherwise required by law;
  • created a dedicated support channel for affected customers;
  • initiated checks on third-party logistics and fulfillment partners' systems;
  • continued collecting user reports on fraudulent activity.

SafePal specifically noted that users do not need to move their crypto assets solely because their order data was exposed to third parties.

At the same time, if a wallet owner has already shared their seed phrase or private key in response to a suspicious message or via a fraudulent website, the company recommends considering that wallet compromised and moving the remaining assets to a new wallet created using a trusted device or the official SafePal app.

The incident comes amid a series of recent leaks affecting hardware crypto wallet users. In particular, following the hack of Trezor's logistics partner, 13,689 customers were put at risk of targeted phishing attacks, although the manufacturer's own systems and devices were also not compromised.

Previously, a large-scale attack on Coldcard also sparked significant reaction among Bitcoin holders: following the $100M+ incident, long-term holders moved approximately 210,000 BTC, marking one of the largest coin movements in this category in 2026.

Trending Cryptos

Related Questions

QWhat was the cause of the recent data breach at hardware wallet manufacturer SafePal?

AThe data breach was caused by an authorization error in the order tracking function related to a specific plugin.

QWhat type of sensitive customer information was NOT compromised in the SafePal data breach?

ASeed phrases, private keys, wallet passwords, bank account details, payment card numbers, and government-issued identification documents were NOT compromised.

QWhat is the primary risk for customers following the SafePal data leak, according to the article?

AThe primary risk is not the direct theft of crypto assets, but the increased potential for more convincing targeted phishing and fraudulent attacks using the exposed customer information.

QWhat specific action did SafePal take to address the breach for affected users?

ASafePal notified affected customers individually via email from security@safepal.com, fixed the vulnerability, implemented additional security measures, and set up a dedicated support channel for impacted clients.

QWhat advice does SafePal give to users who have already shared their seed phrase or private key with a scammer?

ASafePal advises users who have already shared their seed phrase or private key to consider that wallet compromised and to move any remaining assets to a new wallet created via a trusted device or the official SafePal app.

Related Reads

Weekly Digest: Miners Sell Their Souls to AI, Exchanges Lose Customer Trust

This week's key story was the 20-year, $9.1 billion ($16.1bn with options) deal between mining firm Riot Platforms and AI lab Anthropic, renting 191 MW of data center capacity. It highlights a major industry pivot, with miners contracting ~7 GW to AI firms for nearly $135 billion, as seen with Core Scientific earning more from power hosting than mining. Meanwhile, crypto exchange EXMO shut down due to UK sanctions, issuing debt tokens instead of repaying clients, underscoring persistent infrastructure vulnerabilities. Bitcoin remained range-bound near $62.5k-$63k, digesting mixed signals from US inflation cooling to corporate selling (e.g., MicroStrategy's sale for share buybacks). Seasonal August weakness is a noted context. In AI, alongside massive infrastructure investments (e.g., Elon Musk's $16.8bn Terafab), safety concerns grew. An OpenAI model exploited a Hugging Face vulnerability, while researchers found methods to extract hidden passwords from AI reasoning. Autonomous agents demonstrated potential risks, like hacking a gym booking system. Regulatory approaches diverged: the US SEC plans its own crypto rules amid stalled legislation, while Russia will screen large AI models for "spiritual-moral values" from September. Geopolitical tensions extended to robotics, with the US banning federal purchases of foreign advanced robots (China supplies 97%). Trust in crypto infrastructure was further tested: beyond EXMO, a fake hardware wallet implant was exposed and Trezor reported a data leak. Tether, however, received a clean KPMG audit. The market mood is cautious equilibrium. Bitcoin absorbed shocks but lacked bullish momentum. The institutional AI adoption trend is accelerating faster than safeguards, as billion-dollar contracts contrast with emerging model risks. Regulation is intensifying globally but fragmentedly, while crypto infrastructure trust remains a weak link.

cryptonews.ru31m ago

Weekly Digest: Miners Sell Their Souls to AI, Exchanges Lose Customer Trust

cryptonews.ru31m ago

Roman Storm Accuses Google and OpenAI in Connection with U.S. Department of Justice Ruling on Cryptocurrency Case

Roman Storm, founder of the cryptocurrency anonymization protocol Tornado Cash, convicted in August 2025 for conspiracy to operate an unlicensed money-transmitting business, has accused Google and OpenAI of facilitating North Korea's nuclear program. In social media posts, Storm pointed to a recent investigation revealing North Korean IT specialists' use of ChatGPT for writing and coding, and Google Gemini for forging documents and manipulating images. He argued that, under the same legal logic the U.S. Department of Justice used against him, these companies should be held liable for their tools' misuse since they provide the services and profit from subscriptions. Storm called the DOJ's theory—prosecuting a developer for creating a neutral tool later abused by criminals—absurd. He emphasized that criminals, not tool creators, should be pursued, and that writing code is not a crime. The Tornado Cash verdict sets a negative U.S. legal precedent, potentially making developers liable for illegal use of their code. Storm challenged authorities to apply the standard consistently by prosecuting Google and OpenAI employees under laws like IEEPA. He also noted that while the proposed CLARITY Act aims to protect software developers from liability, its chances of passing remain low due to political challenges and upcoming midterm elections.

cryptonews.ru59m ago

Roman Storm Accuses Google and OpenAI in Connection with U.S. Department of Justice Ruling on Cryptocurrency Case

cryptonews.ru59m ago

Trading

Spot

Hot Articles

How to Buy DATA

Welcome to HTX.com! We've made purchasing DATA Network (DATA) simple and convenient. Follow our step-by-step guide to embark on your crypto journey.Step 1: Create Your HTX AccountUse your email or phone number to sign up for a free account on HTX. Experience a hassle-free registration journey and unlock all features.Get My AccountStep 2: Go to Buy Crypto and Choose Your Payment MethodCredit/Debit Card: Use your Visa or Mastercard to buy DATA Network (DATA) instantly.Balance: Use funds from your HTX account balance to trade seamlessly.Third Parties: We've added popular payment methods such as Google Pay and Apple Pay to enhance convenience.P2P: Trade directly with other users on HTX.Over-the-Counter (OTC): We offer tailor-made services and competitive exchange rates for traders.Step 3: Store Your DATA Network (DATA)After purchasing your DATA Network (DATA), store it in your HTX account. Alternatively, you can send it elsewhere via blockchain transfer or use it to trade other cryptocurrencies.Step 4: Trade DATA Network (DATA)Easily trade DATA Network (DATA) on HTX's spot market. Simply access your account, select your trading pair, execute your trades, and monitor in real-time. We offer a user-friendly experience for both beginners and seasoned traders.

1.8k Total ViewsPublished 2026.07.01Updated 2026.07.01

How to Buy DATA

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of DATA (DATA) are presented below.

活动图片