SafePal Says Order Data of Nearly 40,000 Customers Was Exposed in Plug-In Flaw
SafePal disclosed an authorization flaw in an order-tracking plug-in exposed the names, addresses and purchase details of 39,798 customers, the third wallet-industry security incident in two weeks.
Crypto hardware-wallet maker SafePal disclosed a data breach affecting roughly 39,798 customers. Order details were exposed. Crypto assets, seed phrases, and private keys were not. The company made the announcement Sunday.
The unauthorized access pulled names, email addresses, shipping addresses, phone numbers, and purchase records. Anyone who placed an order between 2 March 2025 and 11 April 2026 was potentially affected. SafePal detailed the leak in an official statement posted 16 August. The cause was an authorization flaw in a plug-in used to track customer orders.
“The incident itself did not expose seed phrases, private keys, or wallet passwords,” SafePal said. “You should not need to move your assets solely because your order information was affected.”
This is the third wallet-industry security incident to surface this month. On 5 August, an apparent Coldcard exploit reportedly drained at least $120 million in bitcoin. Then on 13 August, a Trezor warning went out to 14,000 customers after a fulfilment partner suffered its own data exposure. None of the three incidents involved direct compromise of wallet cryptography. All three touched the edges of the hardware-wallet supply chain: fulfilment, order tracking, and device-level exploit respectively.
SafePal said it patched the plug-in flaw on discovery and added further security measures. An independent third-party security firm is reviewing the fix and auditing the company’s order-processing systems. The firm was not named.
Personal-data retention in the order-processing environment has been cut to 90 days from the point of collection, subject to legal requirements. The company also said it removed more than 30 fraudulent websites and phishing links tied to scam activity. Monitoring for new ones continues.
Affected customers were notified by email from [email protected] on Sunday with the subject line “[Important] Your SafePal Order Information Has Been Affected.” A verification page at safepal.com/scam-protection lets customers check whether their order was exposed using an order ID and shipping country.
SafePal warned that any customer who shared a seed phrase or private key in response to a phishing email, call, or letter should treat that wallet as compromised, create a new wallet, and move assets.
The company draws a clear line between the data leak and direct wallet compromise. That line holds, as far as the disclosed facts go. The exposed fields are customer-contact and purchase data, not the cryptographic material that controls funds.
Here is what the framing does not address. A persistent attacker now has 39,798 confirmed hardware-wallet-buyer records. Name, address, phone, and proof of a hardware purchase. That is a targeting list. The 30+ phishing sites SafePal says it took down suggests the company knows it.
Unknowns remain. The identity of the attacker or attackers. The exact date SafePal discovered the flaw (the company said only “recently identified”). How long the authorization flaw existed before discovery. SafePal did not say whether the flaw was actively exploited or merely capable of exploitation. No ransom or extortion demand has been reported. Regulatory notification status, including GDPR or state breach filings, was not addressed in either the company statement or CoinDesk’s reporting.
The third-party security firm conducting the audit was not named. SafePal did not respond to a request for additional comment beyond the published statement, according to CoinDesk.
The string of incidents has prompted renewed discussion about concentration risk in hardware-wallet custody. Traders, as ever, disagree on whether the answer is diversifying across vendors or spreading holdings across cold storage, exchange, and self-custody. The data does not settle it.