SafePal Faces Scrutiny Over Alleged Customer Data Exposure Amid Broader Hardware Wallet Security Concerns
SafePal, a provider of hardware wallets, is under scrutiny following reports that scammers may have accessed customer order details though no public confirmation of a 39,798-user breach has been verified. The incident highlights a growing risk in the crypto hardware space: while non-custodial wallets protect private keys, purchase data including names, addresses, and payment information remains vulnerable to exploitation.
In May, a SafePal customer reported receiving phishing attempts from scammers who possessed precise order details, such as the buyer’s name, shipping address, and device model. SafePal’s privacy policy acknowledges that such data is collected during purchases, with a stated retention period of six months post-delivery. However, the company has not issued a public breach notification matching the alleged 39,798 affected users, a March 2025–April 2026 exposure window, or an August 2026 confirmation date cited in unverified claims.
The incident underscores a critical distinction: while hardware wallets like SafePal’s S1 are designed to secure private keys offline, the logistics of shipping and order processing create separate attack surfaces. Criminals can leverage leaked purchase data for phishing, fake firmware updates, or even physical targeting risks that Ledger customers faced in past breaches.
SafePal is not alone in this challenge. The Financial Times recently reported that nearly 14,000 Trezor customers were exposed after a breach at a third-party shipping provider, compromising names, addresses, and contact details. Though Trezor stated no fraud or physical threats had been confirmed, the incident reinforces how supply chain vulnerabilities can undermine trust in hardware wallets.
A separate but equally severe issue emerged with Coldcard in July, where a firmware bug in affected devices reduced seed-generation randomness, leading to estimated losses exceeding 1,000 BTC (approximately $70.2 million). Galaxy Research identified 1,196 drained addresses, with total suspected thefts nearing $88.6 million. Unlike SafePal and Trezor, Coldcard’s flaw directly impacted wallet security, demonstrating how hardware wallet risks can stem from both technical flaws and operational exposures.
For SafePal, the path forward hinges on transparency. Without a clear accounting of stored customer data, retention policies, and vendor access, trust remains fragile regardless of the wallet’s technical security. The incidents across SafePal, Trezor, and Coldcard reveal a broader truth: hardware wallet users must trust more than just the device’s chip.
Source: https://startupfortune.com/safepal-confirms-data-breach-exposed-order-details-of-nearly-40000-users/
SafePal cybersecurity rating report: https://www.rankiteo.com/company/safepal
"id": "SAF1786971462",
"linkid": "safepal",
"type": "Breach",
"date": "5/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '39,798 (alleged, unverified)',
'industry': 'Cryptocurrency / Blockchain',
'name': 'SafePal',
'type': 'Hardware Wallet Provider'},
{'customers_affected': '14,000 (third-party shipping '
'provider breach)',
'industry': 'Cryptocurrency / Blockchain',
'name': 'Trezor',
'type': 'Hardware Wallet Provider'},
{'customers_affected': '1,196 drained addresses '
'(firmware bug)',
'industry': 'Cryptocurrency / Blockchain',
'name': 'Coldcard',
'type': 'Hardware Wallet Provider'}],
'attack_vector': 'Supply Chain / Third-Party Vendor',
'customer_advisories': 'SafePal customers should be cautious of unsolicited '
'communications, especially those referencing order '
'details. Enable multi-factor authentication and '
'monitor accounts for suspicious activity.',
'data_breach': {'number_of_records_exposed': '39,798 (alleged, unverified)',
'personally_identifiable_information': ['Names',
'Addresses',
'Shipping Details'],
'sensitivity_of_data': 'High (PII and payment data)',
'type_of_data_compromised': ['Personally Identifiable '
'Information (PII)',
'Payment Information',
'Order Details']},
'date_detected': '2025-05',
'date_publicly_disclosed': '2026-08',
'description': 'SafePal, a provider of hardware wallets, is under scrutiny '
'following reports that scammers may have accessed customer '
'order details though no public confirmation of a 39,798-user '
'breach has been verified. The incident highlights a growing '
'risk in the crypto hardware space: while non-custodial '
'wallets protect private keys, purchase data including names, '
'addresses, and payment information remains vulnerable to '
'exploitation.',
'impact': {'brand_reputation_impact': 'High (undermined trust in hardware '
'wallet security)',
'customer_complaints': 'Phishing attempts reported by customers',
'data_compromised': 'Customer order details (names, addresses, '
'payment information, device models)',
'identity_theft_risk': 'High (PII exposure)',
'operational_impact': 'Potential reputational damage and loss of '
'customer trust',
'payment_information_risk': 'High (payment details potentially '
'exposed)',
'systems_affected': "SafePal's order processing/logistics systems"},
'investigation_status': 'Ongoing (unverified allegations)',
'lessons_learned': 'Hardware wallet security extends beyond private key '
'protection; supply chain and operational exposures (e.g., '
'order processing, third-party vendors) create significant '
'risks. Transparency in data retention policies and breach '
'notifications is critical for maintaining trust.',
'motivation': 'Financial Gain (Phishing, Fraud)',
'post_incident_analysis': {'corrective_actions': ['Review and enforce data '
'retention policies',
'Audit third-party vendor '
'access to customer data',
'Improve breach '
'notification processes'],
'root_causes': ['Inadequate data retention '
'policies for customer order '
'details',
'Potential third-party vendor '
'access to sensitive data',
'Lack of transparency in breach '
'notifications']},
'recommendations': ['Conduct a thorough audit of data retention policies and '
'third-party vendor access controls.',
'Implement stricter access controls for customer order '
'data and reduce retention periods where possible.',
'Enhance monitoring for phishing attempts leveraging '
'exposed customer data.',
'Issue clear public communications regarding breach '
'allegations to maintain transparency.',
'Collaborate with industry peers to address supply chain '
'vulnerabilities in hardware wallet logistics.'],
'references': [{'source': 'Financial Times'}, {'source': 'Galaxy Research'}],
'response': {'communication_strategy': 'Limited (no public breach '
'notification confirmed)'},
'stakeholder_advisories': 'Hardware wallet users should remain vigilant '
'against phishing attempts and verify firmware '
'updates directly from official sources. Consider '
'physical security risks associated with leaked '
'shipping data.',
'threat_actor': 'Scammers / Cybercriminals',
'title': 'SafePal Faces Scrutiny Over Alleged Customer Data Exposure',
'type': 'Data Exposure',
'vulnerability_exploited': 'Inadequate data retention and access controls for '
'customer order details'}