At a Glance
| Organization | SafePal (crypto hardware wallet maker) |
| Data exposed | Names, emails, shipping addresses, phone numbers, purchase details |
| Affected | About 39,798 customers (company figure) |
| Cause | Authorization flaw in an order-tracking plug-in |
| Disclosure status | Confirmed and disclosed by SafePal; customers notified |
| Source | SafePal security advisory |
TL;DR
SafePal disclosed a data breach affecting about 39,798 customers. An authorization flaw in an order-tracking plug-in let outsiders view other customers’ order information. No seed phrases, private keys, or wallet funds were exposed. A threat actor now claims to be selling the stolen data.
What Was Exposed
The SafePal data breach exposed order and contact information. That includes names, email addresses, shipping addresses, phone numbers, and purchase details. The data covers orders placed between March 2, 2025, and April 11, 2026.
Wallet credentials stayed safe. In its official security update, SafePal stressed that seed phrases, private keys, and wallet passwords were not part of the affected order data. Bank details, card numbers, and government IDs were also not involved.
How It Happened
The root cause was an authorization flaw, not malware. SafePal traced it to the order-tracking function of a plug-in. Under certain conditions, one customer could reach another customer’s order record.
SafePal fixed the flaw upon discovery and added new controls. The company first received a report consistent with the issue in early May 2026. It treated that as an isolated case before escalating to a full investigation.
Who Is Affected
The breach affects roughly 39,798 customers, per SafePal’s own count. This is a company-confirmed figure, not an external estimate. Affected buyers placed orders during the 13-month window named above.
SafePal emailed all affected customers on August 16. The email came from security@safepal.com. Its subject line flagged that the recipient’s order information had been affected.
Unverified Resale Claims
In its August 18 update, SafePal said individuals now claim to own the dataset and are offering it for sale. The company cannot verify those claims but takes them seriously. It says wider circulation of order data could raise the risk of targeted phishing and impersonation.
What Affected People Should Do
Stay alert for phishing that references your SafePal purchase. Treat unexpected calls, emails, letters, or hardware deliveries as suspect. Never share your seed phrase or private key with anyone, including someone claiming to be support.
Type the SafePal web address manually rather than clicking links in messages. Report suspicious activity through SafePal’s dedicated scam-protection page. You do not need to move assets solely because your order data was exposed.
The Company Response
SafePal has fixed the flaw and added security measures. It engaged an independent third-party firm to validate the fix and review its order systems. The company also cut its data-retention period for order data to 90 days.
SafePal says it has taken down more than 30 fraudulent websites and phishing links tied to the scam activity. It continues to monitor public networks for signs the affected data has been shared.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.