On August 16, SafePal, a manufacturer of hardware cryptocurrency wallets, disclosed a data breach impacting approximately 39,798 users. The leaked information includes names, shipping addresses, phone numbers, email addresses, and order details.
Importantly, the breach did not compromise seed phrases, private keys, passwords, banking details, or document numbers, as SafePal does not collect or store such sensitive information. The project's team found no evidence that attackers gained access to users' wallets or funds.
However, developers warned that the leaked data could be exploited for targeted attacks, such as phishing calls, emails, or messages impersonating support staff, offering refunds, requesting firmware updates, or redirecting users to fraudulent sites. SafePal is currently monitoring for counterfeit sites and is working to have them blocked.
Details of the Breach
The vulnerability arose due to an authorization flaw in an order tracking plugin linked to customer data, which improperly allowed unauthorized access to other clients' orders.
Developers stated that they fixed the issue by the time of the announcement and have enhanced security measures.
This incident affected customers who placed orders between March 2, 2025, and April 11, 2026. SafePal did not specify when the attackers exploited the vulnerability or when the issue was discovered by the team.
Currently, the hardware wallet manufacturer is investigating the incident in collaboration with an independent security firm and plans to conduct a full audit of their order processing system.
In compliance with legal requirements, the company has reduced the data retention period in this system to 90 days and has informed logistics partners, urging them to check if their systems were impacted.
It is worth noting that on August 13, the Trezor project faced a similar situation, where a breach at its logistics partner ShipMonk resulted in the leakage of personal information of nearly 14,000 clients.
