Cryptocurrency hardware wallet provider SafePal has confirmed a data breach affecting approximately 39,798 customers after an authorization flaw in an order-tracking plug-in exposed customer order information to unauthorized access.
The disclosure came as a cybercrime forum listing appeared offering what the seller claims is data from the same incident. The listing references SafePal’s own security advisory and claims to contain information belonging to customers who placed orders between March 2, 2025 and April 11, 2026, matching the timeframe disclosed by the company.
SafePal confirmed that names, email addresses, shipping addresses, phone numbers, and purchase information were accessed externally without authorization. The company said seed phrases, private keys, wallet passwords, payment card numbers, bank account information, and government-issued identification numbers were not exposed.
Authorization flaw exposed order information
In an August 16 security advisory, SafePal said it recently identified an authorization flaw affecting the order-tracking function of a plug-in associated with customer order information.
Under certain conditions, the flaw allowed one customer’s order information to be accessed without authorization by another party. SafePal said it remediated the issue after discovery and introduced additional security controls.
The affected information relates to customers who placed orders between March 2, 2025 and April 11, 2026. Approximately 39,798 customers were impacted.
The exposed data includes:
- Names
- Email addresses
- Shipping addresses
- Phone numbers
- Purchase and order information
SafePal said there is no evidence that the incident itself resulted in unauthorized access to customer wallets or cryptocurrency funds.
Alleged dataset appears on cybercrime forum
A separate cybercrime forum post published around the time of SafePal’s disclosure claims to offer the affected order data for sale.
The seller describes the material as originating from a SafePal “order plugin” breach and cites the same approximately 39,798-customer figure, exposure timeframe, and categories of personal information subsequently confirmed by SafePal.
The listing also claims prospective buyers can verify individual order records against SafePal’s own incident-checking page using an order number and shipping country.
BreachNews has not independently verified the dataset being offered for sale or established that the seller was responsible for exploiting the vulnerability. SafePal’s advisory confirms the underlying unauthorized access and affected data types, but does not identify who accessed the information.
SafePal warns of targeted phishing and impersonation
The combination of shipping information and cryptocurrency purchase history creates a particularly sensitive phishing risk because attackers could potentially identify individuals known to have purchased SafePal products.
SafePal warned that affected customers may receive fraudulent emails, text messages, phone calls, physical letters, refund offers, firmware-update requests, fake customer-support communications, or links to malicious websites.
The incident follows another recent hardware wallet customer data exposure involving Trezor, which confirmed a third-party shipping provider breach affecting nearly 14,000 customers. In both cases, the companies said wallet credentials and cryptographic secrets were not exposed, but warned that the stolen customer information could be used in highly targeted phishing and impersonation campaigns.
The company specifically warned customers never to disclose their seed phrase, private key, or wallet password, regardless of whether a request appears to come from SafePal support.
SafePal also cautioned customers to treat unexpected physical deliveries referencing their SafePal purchase as suspicious. Hardware wallet owners have previously been targeted through highly personalized scams that use legitimate customer information to make fraudulent communications or devices appear credible.
More than 30 phishing sites taken down
SafePal said it has already identified and taken down more than 30 fraudulent websites and phishing links associated with scam activity, while continuing to monitor for additional malicious infrastructure.
The company has also opened a dedicated support channel for affected customers and notified impacted users individually by email on August 16.
Customers can independently check whether an order was affected using SafePal’s incident verification page, which requires the order number and shipping country.
SafePal said an independent third-party security firm is being engaged to validate the remediation and conduct a broader review of its order-processing systems.
Retention period tightened to 90 days
Following the incident, SafePal said it tightened the retention period for personal information in the affected order-processing environment to 90 days, subject to applicable legal requirements.
The company also contacted logistics and fulfillment partners to determine whether the incident had spread beyond the affected plug-in environment.
SafePal said it will continue publishing updates as the external review progresses and as additional phishing infrastructure is identified.
Customers whose order information was exposed do not need to move cryptocurrency solely because of the breach, according to SafePal. However, anyone who has already entered or shared a seed phrase or private key in response to a suspicious message, website, phone call, or letter should treat the wallet as compromised and move remaining assets to a newly created wallet using a trusted device or official application.











