
Crypto hardware wallet provider SafePal has disclosed a security incident that exposed personal information of thousands of customers. According to reports from SafePal, the breach affected 39,798 customers who placed orders between March 2, 2025, and April 11, 2026. The company identified an authorization flaw in a plug-in used to track customer orders, which likely allowed attackers to view other customers' order details by changing order numbers. The incident was first reported to SafePal in early May 2025 as a phishing case, but the company initially treated it as an isolated incident before escalating it into a formal security investigation.
The exposed data included names, email addresses, shipping addresses, phone numbers, and purchase details of the affected customers. As reported by SafePal, the breach did not compromise any cryptocurrency funds, seed phrases, private keys, wallet passwords, payment card numbers, bank account information, or government-issued identification numbers. However, the company warned that users who have shared their private keys or seed phrases via phishing emails, phone calls, or letters should treat their wallets as compromised and transfer their assets to new wallets using a trusted SafePal device or official application. The company stressed that it never asks customers for seed phrases, private keys or passwords.
According to SafePal's announcement, the company has patched the vulnerability and introduced additional security measures. The company notified all affected customers by email from security@safepal.com on August 16th with the email subject [Important] Your SafePal Order Information Has Been Affected. The company has engaged an independent third-party security firm to validate its fix and conduct a broader review of its order-processing systems. SafePal also identified and removed more than 30 fraudulent websites and phishing links associated with the breach and opened a dedicated support channel for affected customers. The company has contacted logistics and fulfillment partners and found no evidence so far that the incident extended into their systems.
The breach has significantly increased phishing risks for affected customers despite their wallet credentials remaining secure. As reported by AMBCrypto, the exposed customer data provides attackers with verifiable information on hardware wallet owners, enabling them to create more socially engineered attacks. SafePal confirmed that seed phrases, private keys, wallet passwords, payment information, identification documents, and customer funds remained secure during the breach. However, the company noted that rising support tickets and targeted impersonation reports among the 39,798 affected customers would provide clearer evidence that attackers are actively exploiting the leaked data. There were reports of scammers referencing specific customer details prior to public disclosure, suggesting some information had been circulating before the breach was disclosed.
Separately, SafePal disclosed that a scheduled data-cleanup process stopped working correctly between September 2025 and April 2026 due to a configuration error. According to the company, this failure did not cause the unauthorized access but left older order records stored longer than intended, helping extend the affected range back to March 2025. The company has now reduced personal-data retention in the relevant order-processing environment to 90 days, subject to legal requirements. Affected customers' personal information has been removed from active e-commerce servers, while an encrypted offline copy is being retained to support potential investigations.