A SafePal data breach has exposed order information belonging to approximately 39,798 customers. The cryptocurrency hardware wallet provider says attackers exploited a flaw in its order-tracking system and stole personal data linked to purchases made between March 2025 and April 2026.
A threat actor now claims to be selling the stolen data on a cybercrime forum. However, the claim has not been independently verified.
SafePal says the incident did not expose wallet seed phrases, private keys, passwords, payment card numbers, bank details or government-issued identification documents. The company also says it found no evidence that attackers gained access to customer wallets or funds.
Order-tracking flaw exposed personal data
The SafePal data breach exposed customer names, email addresses, shipping addresses, phone numbers and purchase information.
SafePal began investigating after receiving a report consistent with the issue in early May 2026. The company initially treated the report as an isolated case. It later expanded the investigation and added extra protections as more concerns emerged.
In July, SafePal launched a full review and rebuild of its order-processing system. That work uncovered an authorisation flaw in an order-tracking plug-in. The flaw allowed unauthorised users to access another customer’s order information.
SafePal says it has fixed the vulnerability and introduced additional security controls. The company is also working with an external security firm to validate the fix and review its wider order-processing environment.
Data retention error increased the affected period
During its investigation, SafePal found a separate configuration problem involving its data-cleanup process. The issue stopped the process from working correctly between September 2025 and April 2026.
As a result, the company retained some order data as far back as March 2025. The affected purchase period runs from March 2, 2025, to April 11, 2026.
SafePal says it has removed the affected personal data from active e-commerce servers. It will retain an encrypted offline copy for potential law-enforcement purposes.
The company emailed affected customers on August 16. It also launched an online tool that lets customers check whether a specific order was involved by entering the order number and shipping country.
Criminals claim to sell stolen SafePal data
A seller on a cybercrime forum claims to offer the stolen SafePal customer data for sale. The seller cited the same affected order period and roughly the same number of customers disclosed by SafePal.
The threat actor reportedly offered to provide order IDs and shipping countries as proof. Those details could be checked through SafePal’s verification tool.
Customers had already reported suspicious SafePal-themed phishing emails and phone calls in May. One reported scam claimed that a firmware flaw affected the SafePal X1 wallet and urged the recipient to install an update.
Customers should watch for targeted scams
SafePal warns that criminals may use the exposed information in phishing and social engineering attacks. Customers should be cautious of unexpected messages or calls about firmware upgrades, refunds, returns or legal investigations.
The company says it has removed more than 30 fraudulent websites and phishing links connected to the incident.
Affected customers do not need to replace their hardware wallet or move cryptocurrency solely because of the breach. However, anyone who shared a seed phrase or private key with a scammer should treat the wallet as compromised and transfer funds to a newly created wallet through an official SafePal device or app.
Conclusion
The SafePal data breach exposed sensitive customer order details, but not the credentials needed to access wallets or funds. Customers should remain alert for convincing phishing attempts that use their purchase information to appear legitimate.


0 responses to “SafePal data breach affects 39,798 hardware wallet customers”