Skip to main content
boxmining
Menu

SafePal Data Breach Exposes 39,798 Hardware Wallet Buyers: What Leaked and What to Do

Michael GuMichael Gu
8 min read
News
SafePal-style hardware wallet and cryptographic key protected inside a vault while customer shipping data flows toward phishing calls, email and a fake QR code
Contents

Bottom line: SafePal says a flaw in an e-commerce order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers and purchase details of approximately 39,798 customers. The company says seed phrases, private keys, wallet passwords, payment cards and funds were not compromised. That distinction matters—but it does not make the incident harmless. The leaked records tell scammers who bought a hardware wallet, what they bought and where they live.

SafePal disclosed the incident on August 16, 2026, after months of reports consistent with targeted phishing. The affected records belong to customers who placed orders between March 2, 2025 and April 11, 2026.

This is not evidence that SafePal hardware wallets have been remotely cracked. It is a breach of the customer identity layer surrounding self-custody, and that can still put crypto owners in danger.

What SafePal says was exposed

According to SafePal’s incident report, the exposed order records included:

  • customer names;
  • email addresses;
  • shipping addresses;
  • phone numbers; and
  • purchase and order details.

SafePal says the incident did not involve seed phrases, private keys, wallet passwords, other wallet credentials, bank-account information, payment-card numbers or government-issued identification numbers. The company also says it found no evidence that the breach itself gave anyone access to customer wallets or funds.

That means a customer who only had order information exposed does not need to replace the device, rotate the seed or move funds solely because of this disclosure.

The risk changes immediately if that customer later enters a recovery phrase or private key into a fake firmware page, shares it with a caller, scans a malicious QR code or follows instructions in a scam letter. At that point, the wallet secret—not just the order record—has been compromised.

How the breach happened

SafePal says it found an authorization flaw in the order-tracking function of a plug-in connected to customer order information. Under certain conditions, an unauthorized person could access another customer’s order details.

The company says it first received a report consistent with the problem in early May 2026. It initially treated that report as an isolated case, then escalated it into a formal investigation. Because SafePal’s e-commerce stack included multiple components, external integrations and logistics partners, the company says it could not immediately isolate the source.

In July, SafePal began a wider review and rebuild of its order-processing pipeline. That work identified the order-tracking flaw. The investigation also found a separate configuration error: a scheduled deletion process had stopped working correctly between September 2025 and April 2026. That error did not create the unauthorized access, but it left older order records online longer than intended and expanded the affected window back to March 2025.

SafePal says it has now:

  • fixed the access-control flaw and added further security controls;
  • reduced sensitive order-data retention in the relevant system to 90 days, subject to legal requirements;
  • purged affected personal data from active e-commerce servers while keeping an encrypted offline copy for possible investigations;
  • asked logistics and fulfilment partners to check their own systems;
  • opened a dedicated incident support channel; and
  • taken down more than 30 fraudulent websites and phishing links connected to the scam activity.

An independent security firm is being engaged to validate the fix and review the wider order-processing system. That work was still ongoing when the disclosure was published.

The stolen-data sale is a claim, not a confirmed fact

BleepingComputer reported that a threat actor was advertising the dataset on a cybercrime forum. The seller cited the same customer count and affected order period disclosed by SafePal, and reportedly offered order IDs and shipping countries as samples that prospective buyers could test against SafePal’s verification tool.

BleepingComputer explicitly said it had not independently verified that the seller possessed the stolen data. The sale should therefore be treated as a credible but unconfirmed threat-actor claim, not as an established transaction.

The confirmed part is serious enough: SafePal itself says customer order information was accessed without authorization, and phishing linked to the exposed information was already being reported.

Why this leak is dangerous even if the wallet stayed secure

Generic phishing is noisy. This data can make it personal.

A scammer may know the victim’s full name, phone number, delivery address, exact SafePal product and approximate purchase date. That information can make a fake support call or firmware notice feel like proof of legitimacy. SafePal warns that attackers may use phone calls, emails, text messages, letters, fake refunds, product-return requests, fake legal investigations, malicious sites and even unexpected hardware deliveries.

The most dangerous message may not ask for a seed phrase immediately. It may first confirm real order details, create urgency and move the victim to a convincing second step.

There is also a physical-security dimension. A shipping address linked to a hardware-wallet purchase identifies a household that may hold crypto. It does not reveal the size of the holdings—or prove that the purchaser still owns any—but it can still enable intimidation, burglary attempts or other targeted crime.

This is the key difference from the recent Coldcard RNG incident. Coldcard’s failure weakened wallet seeds and was linked to on-chain theft. SafePal’s disclosed flaw was in the e-commerce layer. The device secrets may remain intact while the human owner becomes a much easier target.

How to check whether your SafePal order was affected

SafePal says it emailed affected customers on August 16 from [email protected] with the subject [Important] Your SafePal Order Information Has Been Affected.

Do not trust an email merely because the sender name and subject look correct. Those details are easy to copy.

Instead:

  1. Open a fresh browser window.
  2. Type www.safepal.com into the address bar yourself.
  3. Navigate to SafePal’s incident or scam-protection page from the official site.
  4. Use the official checker with your order number and shipping country.
  5. If you need help, open a support ticket through the official site—not through a phone number, social-media reply or link sent to you.

SafePal specifically warns about lookalike domains that replace the lowercase “l” in its name with a capital “I”. A search ad, QR code or almost-correct domain is not a safe shortcut.

What affected customers should do now

If you have not shared a seed phrase or private key

  • Do not move funds just because the order record was exposed. A rushed migration creates its own risk.
  • Treat every unexpected SafePal call, email, text, letter, refund, return request and firmware warning as hostile until independently verified.
  • Do not click links or scan QR codes from those messages.
  • Never confirm your wallet balance, holdings or storage arrangements to a caller.
  • Secure the email account tied to the order with a unique password and app- or hardware-key-based two-factor authentication.
  • Add a strong account PIN with your mobile carrier to make SIM-swap attempts harder.
  • If an unexpected package or visitor references the purchase, do not engage. Preserve evidence and contact local authorities if you feel physically threatened.

SafePal says its employees do not initiate phone calls to customers and it does not send physical letters. Genuine support will never ask for a recovery phrase, private key, PIN or wallet password.

If you entered or shared a seed phrase or private key

Treat the wallet as compromised—even if no theft is visible yet.

  1. Use a trusted device and an official wallet application to create a completely new wallet with a new seed.
  2. Verify the new receive address on the trusted device itself.
  3. Send a small test transaction.
  4. After it confirms, move the remaining assets as quickly and carefully as conditions allow.
  5. Stop using the exposed seed everywhere it was restored, including other apps and devices.
  6. Preserve the phishing message, URL, phone number and transaction records, then report the case through SafePal’s official incident channel and to relevant local authorities.

Do not accept help from strangers who contact you after a public post. “Recovery specialists” asking for credentials or upfront crypto payments are often running a second scam against the same victim.

What this incident says about hardware-wallet privacy

Buying a hardware wallet creates a centralized data trail even when the wallet itself is non-custodial. A merchant may need a name, email, address, phone number, payment record and logistics data to complete the sale. The buyer’s seed can remain offline while that commercial record sits in web applications, plug-ins, fulfilment systems and backups.

That is why “not your keys, not your coins” is only part of the security model. Self-custody removes one financial intermediary from the signing path. It does not remove e-commerce software, shipping partners, email accounts, mobile carriers or the human susceptibility to a well-researched lie.

SafePal’s shorter retention window is a useful response, but the incident raises the harder industry question: why should a hardware-wallet seller keep identity-rich order records online any longer than operationally necessary? Encryption, access control, deletion testing and strict retention limits are part of wallet security because they protect the person holding the wallet.

SafePal data breach FAQ

How many SafePal customers were affected?

SafePal says approximately 39,798 customers had order information accessed without authorization. The affected orders were placed between March 2, 2025 and April 11, 2026.

Were SafePal seed phrases or private keys leaked?

SafePal says the incident did not expose seed phrases, private keys, wallet passwords or other wallet credentials, and that it found no evidence the breach itself compromised wallets or funds.

What personal information was exposed?

The affected order records included names, email addresses, shipping addresses, phone numbers and purchase details.

Do affected customers need to replace their SafePal wallet?

No, not solely because their order information was exposed. SafePal says the hardware and wallet data were unaffected. A customer who shared a seed phrase or private key with a scammer should create a new wallet and move remaining assets.

How can I safely check whether my order was affected?

Type safepal.com into a fresh browser window, navigate to the official incident page, and use SafePal's checker with the order number and shipping country. Do not reach the checker through an unsolicited email, message, QR code or search ad.

Is the stolen SafePal database being sold?

A threat actor has advertised what they claim is the stolen dataset on a cybercrime forum. BleepingComputer reported the listing but said it had not independently verified that the seller possessed the data.

This article is security news and general information, not financial, legal or incident-response advice. If you believe wallet credentials were exposed, prioritize safe migration through verified software and contact the relevant official support and authorities.

Share

Found this useful?

Share it with someone who'd want to read it.

Related