SafePal Data Breach Exposes Nearly 40,000 Customers’ Order Information
SafePal, a cryptocurrency hardware wallet provider, has disclosed a data breach affecting 39,798 customers after a flaw in its order-tracking system was exploited to steal personal information. The incident impacts users who placed orders between March 2, 2025, and April 11, 2026, exposing names, email addresses, shipping details, phone numbers, and purchase information.
The breach did not compromise wallet seed phrases, private keys, passwords, payment details, or government-issued IDs. SafePal confirmed that no evidence suggests unauthorized access to customer funds or wallets. Impacted users were notified via email on August 16, 2026, and the company released an online verification tool to check if order data was exposed.
A threat actor is now selling the stolen data on a cybercrime forum, matching SafePal’s disclosed timeline and customer count. The seller offered to verify order details using SafePal’s tool to prove legitimacy. While the data’s authenticity has not been independently confirmed, customers reported phishing attempts including fake firmware update emails and fraudulent calls as early as May 2026.
SafePal first detected suspicious activity in early May 2026 but initially treated it as an isolated case. A full investigation in July 2026 uncovered an authorization flaw in a third-party order-tracking plugin, which allowed unauthorized access to customer data. The company patched the vulnerability and implemented additional security measures, later discovering a separate configuration error that caused order data to be retained longer than intended back to March 2025.
SafePal has since purged exposed personal data from active servers, retaining an encrypted offline copy for potential law enforcement use. The company also took down over 30 fraudulent websites and phishing links tied to the breach. While customers do not need to replace hardware wallets or move funds, those who shared seed phrases or private keys in response to phishing attempts should transfer assets to a new wallet.
SafePal is working with a third-party security firm to validate fixes and review its order-processing systems. The incident highlights risks of targeted phishing and social engineering attacks using stolen order data.
SafePal cybersecurity rating report: https://www.rankiteo.com/company/safepal
"id": "SAF1786926220",
"linkid": "safepal",
"type": "Breach",
"date": "3/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '39,798',
'industry': 'Cryptocurrency, Cybersecurity, FinTech',
'name': 'SafePal',
'type': 'Cryptocurrency hardware wallet provider'}],
'attack_vector': 'Authorization flaw in third-party order-tracking plugin',
'customer_advisories': 'Email notifications sent on August 16, 2026; online '
'verification tool released; warnings about phishing '
'attempts and fraudulent websites',
'data_breach': {'data_encryption': 'Encrypted offline copy retained for law '
'enforcement',
'data_exfiltration': 'Yes (data sold on cybercrime forum)',
'number_of_records_exposed': '39,798',
'personally_identifiable_information': 'Yes (names, email '
'addresses, phone '
'numbers, shipping '
'details)',
'sensitivity_of_data': 'Moderate (PII, but no financial or '
'highly sensitive data like seed '
'phrases/private keys)',
'type_of_data_compromised': ['Names',
'Email addresses',
'Shipping details',
'Phone numbers',
'Purchase information']},
'date_detected': '2026-05-01',
'date_publicly_disclosed': '2026-08-16',
'description': 'SafePal, a cryptocurrency hardware wallet provider, disclosed '
'a data breach affecting 39,798 customers after a flaw in its '
'order-tracking system was exploited to steal personal '
'information. The breach exposed names, email addresses, '
'shipping details, phone numbers, and purchase information but '
'did not compromise wallet seed phrases, private keys, '
'passwords, payment details, or government-issued IDs. The '
'threat actor is selling the stolen data on a cybercrime '
'forum, and customers reported phishing attempts following the '
'breach.',
'impact': {'brand_reputation_impact': 'Yes (public disclosure, phishing '
'attacks, fraudulent websites)',
'customer_complaints': 'Phishing attempts reported (fake firmware '
'update emails, fraudulent calls)',
'data_compromised': 'Names, email addresses, shipping details, '
'phone numbers, purchase information',
'identity_theft_risk': 'Moderate (PII exposed, but no '
'government-issued IDs or payment details)',
'operational_impact': 'Purged exposed data, took down fraudulent '
'websites/phishing links, implemented '
'additional security measures',
'payment_information_risk': 'None (payment details not '
'compromised)',
'systems_affected': 'Order-tracking system, third-party plugin'},
'initial_access_broker': {'data_sold_on_dark_web': 'Yes (data sold on '
'cybercrime forum)',
'entry_point': 'Authorization flaw in third-party '
'order-tracking plugin'},
'investigation_status': 'Ongoing (third-party security firm reviewing '
'order-processing systems)',
'lessons_learned': 'Risks of third-party plugins in order-tracking systems, '
'importance of timely detection and investigation, need '
'for proactive phishing/social engineering defenses, risks '
'of prolonged data retention',
'motivation': 'Financial gain (data sold on dark web), potential for '
'phishing/social engineering',
'post_incident_analysis': {'corrective_actions': ['Patched vulnerability',
'Purged exposed data from '
'active servers',
'Retained encrypted offline '
'copy for law enforcement',
'Took down fraudulent '
'websites/phishing links',
'Engaged third-party '
'security firm to validate '
'fixes'],
'root_causes': ['Authorization flaw in third-party '
'order-tracking plugin',
'Configuration error causing '
'prolonged data retention (back to '
'March 2025)']},
'recommendations': ['Customers should remain vigilant against phishing '
'attempts',
'Customers who shared seed phrases/private keys in '
'response to phishing should transfer assets to a new '
'wallet',
'Companies should audit third-party integrations for '
'security flaws',
'Implement stricter data retention policies',
'Enhance monitoring for unauthorized access to customer '
'data'],
'references': [{'source': 'SafePal Public Disclosure'}],
'response': {'communication_strategy': 'Email notifications to affected '
'customers on August 16, 2026, public '
'disclosure',
'containment_measures': 'Patched vulnerability, purged exposed '
'data from active servers, retained '
'encrypted offline copy for law '
'enforcement',
'incident_response_plan_activated': 'Yes',
'recovery_measures': 'Took down over 30 fraudulent '
'websites/phishing links, released online '
'verification tool for customers',
'remediation_measures': 'Fixed authorization flaw, addressed '
'configuration error, implemented '
'additional security measures',
'third_party_assistance': 'Yes (third-party security firm '
'validating fixes)'},
'threat_actor': 'Unknown threat actor selling data on cybercrime forum',
'title': 'SafePal Data Breach Exposes Nearly 40,000 Customers’ Order '
'Information',
'type': 'Data Breach',
'vulnerability_exploited': 'Authorization flaw, configuration error leading '
'to prolonged data retention'}