Skip to content

SafePal Data Breach Exposes Order Data of 39,798 Customers

SafePal Data Breach Exposes Order Data of 39,798 Customers

Short answer: On August 16, 2026, crypto wallet maker SafePal disclosed a data breach that exposed the names, emails, phone numbers, shipping addresses and purchase details of 39,798 customers who ordered between March 2, 2025 and April 11, 2026. No funds, seed phrases or private keys were exposed, but the leaked list is reportedly for sale and makes buyers prime targets for phishing.

What happened

SafePal, a self-custody wallet provider best known for its hardware wallets and mobile app, notified affected customers on Sunday, August 16, 2026. The cause was an authorization flaw in a plug-in that tracks customer orders: under certain conditions, one customer could view another customer's order record, and an attacker used that weakness to collect order data at scale.

  • Who is affected: 39,798 customers whose orders were placed between March 2, 2025 and April 11, 2026.
  • What leaked: full names, email addresses, phone numbers, shipping addresses and what was bought.
  • What did not leak: seed phrases, private keys, wallet passwords, bank details, payment card numbers and government ID numbers.
  • How it surfaced: SafePal received a first report in early May, initially treated it as an isolated case, and confirmed the wider problem during a rebuild of its order system that began in July. A separate configuration error had also stopped old order data from being purged between September 2025 and April 2026.

The company says it has fixed the flaw, hired an outside security firm to audit the fix, cut retention of order data to 90 days, launched a tool that lets customers check whether an order was affected, and taken down more than 30 phishing sites and links tied to the incident. Security outlets reported that a seller on a cybercrime forum is already offering a dataset matching the same date range and customer count.

Why a wallet data breach matters if your keys are safe

A leaked order record cannot move a single coin. What it does is tell a criminal that a specific person, at a specific home address, almost certainly holds crypto in self-custody. That turns generic spam into targeted fraud: fake "urgent firmware update" emails, calls from a supposed support agent, SMS messages with lookalike links, and even printed letters or tampered devices sent by post. One SafePal customer had already reported an impersonation attempt by email, letter and phone in May, although no link to the breach has been confirmed.

Every one of these scams ends the same way: the victim is persuaded to type the recovery phrase into a website, an app or a "replacement" device. Once that happens, the funds are gone, and no hardware security chip can help.

Third crypto customer data leak in a week

The SafePal disclosure landed in the middle of a run of incidents in which the weak point was not wallet cryptography but the e-commerce and analytics systems around it.

CompanyDisclosedPeople affectedWeak point
Trezor (via fulfillment partner ShipMonk)August 13, 2026about 13,700Logistics partner's analytics platform
SafePalAugust 16, 202639,798Order-tracking plug-in
Bits of Gold (Israeli crypto broker)August 16, 2026about 200,000Third-party data analytics provider

Bits of Gold's leak is potentially more sensitive, since it reportedly included national ID numbers and bank account details alongside public wallet addresses. The pattern echoes the Ledger incident of 2020, when a marketing database breach later led to a dump of more than 270,000 customer names and home addresses and years of phishing that followed.

What it means for you

If you bought a SafePal device in the affected window, or any hardware wallet online, assume your name and address may be on a list and act accordingly:

  1. Never share or type your recovery phrase in response to any email, call, SMS or letter. No legitimate wallet company will ask for it.
  2. Update firmware only through the official app or website you already use, never through a link in a message.
  3. Treat unexpected devices as hostile. A "free replacement" wallet that arrives unannounced should be discarded, not set up.
  4. Use a separate email address for crypto purchases and consider a pickup point instead of your home address for future orders.
  5. Consider moving funds to a fresh wallet with a new seed only if you ever entered your phrase somewhere questionable; otherwise the leak alone does not require it.

More habits that protect against this kind of targeted attack are collected in our crypto wallet security guide. Keeping less personal data in circulation also helps: a non-custodial swap service that does not require registration never holds a profile that could leak in the first place.

Key takeaways

  • SafePal's data breach exposed order data of 39,798 customers from March 2, 2025 to April 11, 2026.
  • No funds, seed phrases, private keys or payment card data were compromised, according to the company.
  • The dataset is reportedly being offered on a cybercrime forum, so targeted phishing is the main risk.
  • It was one of three crypto customer data leaks disclosed within a week, alongside Trezor and Bits of Gold.

If a message about your wallet looks urgent, pause and check it against our guide on how to avoid crypto scams before clicking anything.

Sources: CoinDesk, BleepingComputer, Help Net Security, CoinDesk (Bits of Gold)

Frequently asked questions

Were SafePal wallet funds or seed phrases stolen in the breach?

No. SafePal says the leak was limited to order data such as names, emails, phone numbers, shipping addresses and purchase details, and that seed phrases, private keys, wallet passwords, card numbers and ID documents were not exposed.

How do I know if my SafePal order was affected?

SafePal emailed affected customers from its security address and published a verification tool on its website. Orders placed between March 2, 2025 and April 11, 2026 fall within the exposed window.

What should I do if my hardware wallet order data leaked?

Your coins stay safe as long as your recovery phrase stays secret. Expect targeted phishing by email, SMS, phone and even post, never enter your seed phrase anywhere a message sends you, and install firmware only through the official app.

← Blog

Read next