SafePal, a provider of cryptocurrency hardware wallets, has disclosed a data breach affecting approximately 39,798 customers. The incident, which exposed customer order information, stems from an exploited authorization flaw within an order-tracking plugin.
The breach impacts customers who placed orders between March 2, 2025, and April 11, 2026. The compromised data includes names, email addresses, shipping addresses, phone numbers, and purchase details. SafePal has confirmed that sensitive information such as wallet seed phrases, private keys, passwords, bank account details, payment card numbers, or government-issued identification numbers were not exposed. The company stated that there is no evidence the incident compromised access to SafePal wallets or funds.
SafePal began notifying affected customers via email on August 16, using the subject line "[Important] Your SafePal Order Information Has Been Affected." The company has also launched an online verification tool, allowing customers to check if their order details were stolen by entering their order number and shipping country.
A threat actor is reportedly selling the stolen SafePal customer data on a cybercrime forum. The seller's claims align with SafePal's disclosed affected order period and customer count. As proof of legitimacy, the threat actor is offering to share order IDs and shipping country information for verification against SafePal's online tool.
The company first received a report consistent with the issue in early May 2026, which was initially treated as an isolated case. During that period, a customer reported receiving a phishing email and a phone call from someone impersonating a SafePal employee. The phishing email falsely claimed a security vulnerability in the SafePal X1 hardware wallet required a firmware update.
In July, SafePal initiated a comprehensive review and rebuild of its order-processing system. This investigation uncovered an authorization flaw in the order-tracking function of a plugin, which permitted unauthorized access to other customers' order information. SafePal has since patched the vulnerability and implemented additional security measures, and is working with a third-party security firm to validate the fix and conduct a broader review.
During the investigation, SafePal also identified a separate configuration error that caused a data-cleanup process to malfunction between September 2025 and April 2026. This error resulted in order data being retained from as far back as March 2025. For affected orders, SafePal has purged personal data from active e-commerce servers, while retaining an encrypted offline copy for potential law enforcement investigations.
SafePal is urging customers to be vigilant against targeted phishing emails and phone calls related to firmware upgrades, product returns, refunds, or legal investigations. The company has already taken down over 30 fraudulent websites and phishing links associated with the incident.
Customers whose order information was exposed are not advised to replace their hardware wallets or move cryptocurrency solely due to this breach. However, SafePal advises that if a customer has already shared their seed phrases or private key in response to a phishing attempt, they should consider their wallet compromised and transfer any assets to a new wallet using a trusted SafePal device or official application.






