
Cryptocurrency hardware wallet maker SafePal is notifying customers of a data breach after an authorization flaw in its order-tracking system allowed a threat actor to access order records belonging to 39,798 customers. The breach exposed names, email addresses, shipping addresses, phone numbers, and purchase details for orders placed between March 2, 2025 and April 11, 2026. Wallet seed phrases, private keys, passwords, and payment card numbers were not affected.
SafePal says it first received a suspicious report in early May 2026 but initially treated it as an isolated case. A full investigation launched in July uncovered the root cause: a bug in a third-party order-tracking plugin that let unauthenticated requests retrieve another customer’s order record. A separate configuration error had also caused order data to accumulate further back than intended, extending the exposure window. The company fixed the flaw, purged the exposed records from active servers, and has since taken down over 30 phishing sites linked to the incident. A threat actor is now advertising the stolen dataset for sale on a cybercrime forum, and customers have reported receiving phishing calls and emails about fake firmware updates since May.
How to check if you’re affected
Affected products include all SafePal hardware wallet orders placed between March 2, 2025 and April 11, 2026. SafePal has published a verification tool at safepal.com where customers can enter their order number and shipping country to confirm whether their order was among the stolen records. If you receive any contact — email or phone — about a firmware update, product return, refund, or legal matter from someone claiming to be SafePal, treat it as a phishing attempt. Do not share your seed phrase or private key in response to any unsolicited message. If you already shared those credentials, move your assets to a new wallet immediately on a trusted SafePal device or official app.
