- SafePal says an authorization flaw exposed order data belonging to 39,798 customers.
- Names, email addresses, phone numbers, shipping addresses and purchase details were accessed.
- Seed phrases, private keys, wallet passwords and payment data were not compromised.
SafePal has disclosed a data breach affecting 39,798 customers, but the most consequential part of the incident sits outside the wallet software itself. An authorization flaw in an order-tracking plugin exposed names, emails, phone numbers, shipping addresses and purchase information belonging to customers who ordered between March 2, 2025 and April 11, 2026.
SafePal said it found no evidence that wallet access or customer funds were compromised, and seed phrases, private keys and passwords were not exposed. The breach instead highlights a different problem for hardware-wallet providers: a device can protect cryptographic keys while the commerce systems used to sell it still expose the identity and location of its owner.
The wallet stayed secure while the customer identity layer failed
SafePal traced the incident to an authorization flaw in a plugin used for order tracking. Under certain conditions, one customer’s order information could be accessed without authorization. The company said it fixed the issue after discovering it and introduced additional security measures.
The exposed information included:
- Full names
- Email addresses
- Phone numbers
- Shipping addresses
- Purchase details
SafePal stressed that the incident did not involve seed phrases, private keys, wallet passwords, bank account details, payment card numbers or government-issued identification. It also said it found no evidence that the breach itself enabled access to customer wallets or funds.
Dear community,
While your SafePal wallet, seed phrase, and private keys are secure; we identified a flaw in the order-tracking plug-in that led to unauthorized access to information of a subset of customers.
The issue has been fixed with additional security measures…
— SafePal – Crypto Wallet (@SafePal) August 16, 2026
That distinction matters because this was not a compromise of SafePal’s self-custody architecture. It was a breach of the infrastructure surrounding the purchase of a self-custody device.
For affected customers, however, that does not make the incident harmless.
Shipping data can be more dangerous than it looks
A database containing an address and purchase history can reveal something that attackers would otherwise have to discover separately: this person likely owns a hardware wallet and where that person receives deliveries.
That creates a threat model very different from a conventional password breach.
An attacker does not necessarily need a seed phrase immediately. Genuine purchase information can make phishing substantially more convincing. A scammer can reference the device model, order history, delivery details or customer name while impersonating SafePal support and asking the victim to “verify” or “restore” a wallet.
SafePal itself warned that affected customers could face fraudulent calls, text messages, emails, letters, fake refund offers, malicious websites and bogus firmware-update requests.
The physical address creates another concern. Hardware-wallet buyers are self-selecting as people with some level of crypto ownership, making an e-commerce database more sensitive than a generic retail mailing list.
This does not mean the SafePal breach has resulted in physical attacks. No such link has been established. But the incident increases the amount of personal information available for targeting.
A retention failure made the breach larger than it needed to be
One of the more important findings came from SafePal’s incident review rather than the plugin flaw itself.
The company said a scheduled data-cleanup process stopped functioning correctly between September 2025 and
April 2026 because of a configuration error. The failure did not cause the unauthorized access, but it meant older customer records remained available for longer than intended, helping extend the affected period back to March 2025.
That is a meaningful security lesson.
Organizations usually focus on preventing attackers from reaching stored data. Data minimization addresses the problem from the opposite direction: information that has already been deleted cannot later be stolen from the compromised system.
SafePal has now reduced personal-data retention in the relevant order-processing environment to 90 days, subject to legal obligations, and said affected information has been removed from active e-commerce servers. An encrypted offline copy is being retained for investigative purposes.
For hardware-wallet companies, this could become one of the more effective ways of reducing the consequences of future commerce-layer breaches. Shipping information is operationally necessary while an order is being fulfilled. Its security value becomes increasingly questionable once that purpose has ended.
The breach was detected after phishing activity had already appeared
The timeline also raises questions about how quickly retail-security incidents can be recognized.
According to SafePal’s incident FAQ, the company received a phishing report consistent with the problem in early May. It initially appeared to be an isolated case. The issue later escalated into a wider security investigation, and SafePal began rebuilding its order-processing pipeline in July before confirming the plugin vulnerability.
By the August 16 disclosure, SafePal said it had notified affected customers individually from [email protected]. It also said it had taken down more than 30 phishing websites and malicious links associated with scam activity.
That sequence illustrates the difficulty of identifying customer-data abuse. The first visible symptom may not be an obvious server compromise. It can be a customer receiving an unusually convincing scam.
Hardware-wallet security now extends beyond the hardware
The incident exposes a structural problem for the hardware-wallet industry.
Manufacturers invest heavily in secure elements, offline key generation and protection against device tampering.
Yet selling those devices still depends on conventional web infrastructure: online stores, fulfillment systems, analytics services, shipping partners and customer-support software.
Every additional system that stores names, addresses and product information expands the security perimeter.
SafePal’s case is particularly useful because the core wallet protections apparently worked. There is no indication that attackers penetrated devices or obtained credentials required to move crypto.
The weakness appeared in a mundane order-tracking function.
That makes supply-chain and commerce security increasingly relevant to self-custody providers. The strongest cryptography on the device cannot prevent a customer from being identified through a vulnerable plugin sitting somewhere else in the purchasing process.
What affected SafePal customers should actually watch
The highest-probability near-term threat is targeted impersonation rather than immediate wallet compromise.
SafePal customers affected by the breach should treat messages referencing real order information as untrusted unless independently verified through official channels. In particular, legitimate support staff should not need a seed phrase or private key to investigate an order-related issue.
The other metric worth watching is whether SafePal’s 90-day retention policy becomes a permanent part of its operational model and whether other hardware-wallet companies adopt similar limits.
For this sector, that may matter more than another firmware feature. The security problem is increasingly about minimizing how long a company knows who bought a self-custody device and where that person lives.
Credit: Source link
