SafePal Data Breach: 39,798 Customers Exposed

Ledger
Changelly


Hardware wallet maker SafePal acknowledged a data breach on August 16, 2026: the names, email addresses, delivery addresses, phone numbers and order details of 39,798 customers were exposed. Seed phrases, private keys and payment data were not affected, according to the company. Anyone who ordered a device between March 2, 2025 and April 11, 2026 should check now, because the combination of a home address and the knowledge that someone there “owns a hardware wallet” is precisely what makes targeted fraud possible.

The company has notified affected customers by email and published a lookup tool that establishes, from the order number, whether a given order sits in the leak. It is the second incident of its kind in the industry within two weeks.

What Exactly Happened in the SafePal Data Breach

The cause, according to SafePal, was an authorization flaw in a plugin used for order tracking. An authorization flaw means an application checks whether someone is logged in, but not whether that person is entitled to see the data being requested. Under certain conditions, another customer’s order could be viewed through it.

A second, unrelated fault compounded the problem. According to research by BleepingComputer, a misconfiguration prevented old order records from being deleted on schedule between September 2025 and April 2026. Far more historical data therefore sat in the system than should have been there. Only that interplay explains why the order window reaches back into March 2025.

itrust

The sequence matters more to the assessment than the headline number. A first indication of the problem reached SafePal in early May 2026. In July the company began a full review and rebuild of its order processing and came across the vulnerability in the process. The public statement followed on August 16. A good three months therefore separate the first indication from the notification of those affected.

Which Data Leaked in the SafePal Breach and Which Did Not

SafePal sets out both sides explicitly in its security notice. Affected are names, email addresses, shipping addresses, phone numbers and purchase details. Not affected, the company says, are seed phrases, private keys, wallet passwords and other wallet credentials, along with bank details, card numbers and official identity numbers.

The seed phrase is the sequence of twelve or twenty-four words from which every key in a wallet can be restored. Anyone who knows it has full access to the balance, regardless of where the device happens to be. Its absence from the leak is the good news in this incident: the leaked data alone cannot move funds.

That is only half the picture. An attacker who knows a name, home address, phone number and order date does not need to steal the seed phrase. They can try to have it handed over. That is what separates an ordinary address leak from an address leak at a wallet manufacturer.

One further point belongs in an honest account. According to reports by BleepingComputer and the specialist service Help Net Security, an actor on a cybercrime forum is offering a data set that cites the same customer count and the same order window. Whether that offer is genuine remains unconfirmed. For your own caution it makes no difference, because the safe way to handle unexpected contact is the same either way.

Am I Affected by the SafePal Data Breach? How to Check Your Order

There are three routes, and they complement one another to give a reliable picture.

Order Window, Notification and the Lookup Tool

The first route is the calendar. Only orders placed between March 2, 2025 and April 11, 2026 are affected. Anyone who ordered earlier or later falls outside the leak, on the company’s account of it. The second route is the inbox: SafePal notified affected customers by email on August 16 from the sender address security@safepal.com. The third route is the lookup tool, into which an order number and shipping country can be entered.

One detail about that tool is easy to miss and decisive. Open the site only through the address www.safepal.com typed in directly, and follow no link from an email. SafePal says it has already had more than 30 fake websites and phishing links taken down. Imitations of that kind live on appearing at the right moment, and the right moment is now.

Black desk telephone with the receiver off the hook next to a slit-open empty envelope on dark wood, with a coin bearing the Bitcoin symbol beside it
Contact does not necessarily arrive by email: a name, address and phone number are enough to construct a convincing call or letter.

Why a Delivery Address Is More Dangerous Than a Leaked Password

A leaked password can be changed in two minutes. A home address and a phone number cannot be changed, and the fact that someone living at that address holds crypto assets in self-custody does not go stale. That is the core of the problem and the reason address leaks at wallet makers form a category of their own.

Two risk paths follow from it. The first is targeted phishing. Phishing describes the attempt to obtain credentials behind a faked identity. An attacker who cites your name, your purchase date and your device model clears the usual hurdle: the contact does not read like a bulk mailing, but like a callback about a transaction that genuinely took place.

The second path is the more unpleasant one. The industry has adopted the term wrench attack for the physical assault on wallet owners: instead of breaking encryption, the owner is pressured into handing over their keys. A solid address list is the prerequisite. Cryptoticker described this connection on April 25, 2026 in the context of the series of kidnappings in France; that chain likewise began with exposed data.

Anyone who draws the conclusion that their custody setup needs a rethink will find the common devices and their purchase routes in the hardware wallet comparison. That is no substitute for responding to the leak; it only narrows the attack surface for the next one.

Hardware Wallets ComparedHardware Wallets Compared

Phishing Calls Since May: the Data Has Been in Use for Months

The finding that sets this incident apart from a routine disclosure notice sits in the reports by BleepingComputer and Help Net Security. As early as May 2026, months before the official statement, customers reported phishing emails and phone calls concerning supposed firmware updates and security problems with their hardware wallet. One customer additionally reported a letter.

SafePal has not confirmed any direct link between those approaches and the leak, on Help Net Security’s account. The timing and the callers’ knowledge nonetheless point to an overlap in the specialist service’s assessment. For you as a customer the practical meaning is clear: the assumption that the risk begins with publication does not hold. The attacks were already running.

A firmware update is an update to the device software of a hardware wallet. The user always initiates such an update themselves through the manufacturer’s official application, and it is never announced by telephone. A call pressing for an update is therefore a warning sign independently of any data breach.

The Fake Replacement Device: the Scam SafePal Warns About Itself

One phrase the company has written into its recommendations is worth noting. Customers should treat every unexpected approach and every unexpected hardware delivery relating to their SafePal purchase as suspicious, whether it comes by phone, by post or in person.

There is a reason a manufacturer explicitly warns about parcels that appear to come from itself. A tampered device shipped with prepared instructions and a recovery phrase already supplied hands control of every holding later stored on it to the sender. The recipient notices nothing at first, because the device works to all appearances.

The rule against it is unspectacular and effective. A device you did not order yourself does not get set up. A recovery phrase that comes with a device is never genuine, because it is generated on the device and nowhere else. And a seed phrase is under no circumstances entered on a website, into a form or over the phone. How to store it instead is set out in our guide to storing your seed phrase.

Two outwardly identical black electronic devices on a metal plate, one with its torn security seal hanging loose, with a coin bearing the Bitcoin symbol beside them
Tampered devices are rarely distinguishable from the outside. What counts is whether you triggered the delivery yourself.

Second Case in Two Weeks: What Trezor and SafePal Have in Common

On August 13, 2026, Cryptoticker reported a data breach at Trezor in which, on the information available then, 13,689 customers were affected with names, phone numbers and home addresses; there the data escaped through the logistics provider ShipMonk. The details are in our report on the Trezor data breach.

The technical causes of the two cases have nothing to do with each other. One lay with an external shipping provider, the other in a self-operated plugin. What they share is the location: in neither case was the device the target, nor the cryptography behind it, but the ordering process.

That is the real lesson of the pairing. The security architecture of a hardware wallet is built so that the private key never leaves the device, and it serves that purpose. The purchase that precedes it is an ordinary online shop with an address database, shipping workflow and third-party plugins, and it is run to the standards of an online shop. Two incidents in fourteen days are too small a number for a statistic, but they are enough to make that asymmetry visible.

In practice one question follows, and it can be asked before any purchase: which data does the merchant actually need, and how long does it keep them? SafePal has announced in response that it will delete purchase records after 90 days in future, where legal requirements do not demand otherwise. Shorter retention periods are the most effective remedy against precisely this kind of leak, because leaked data can only be as old as the records still held.

Regulated Crypto Exchanges ComparedRegulated Crypto Exchanges Compared

What SafePal Customers Should Do in the Next Few Days

Responding to an address leak differs fundamentally from responding to a password leak. There is nothing to reset. What remains is preparing for the approaches that will come.

Five Points for the Coming Weeks

Check first, through the manufacturer’s address typed in directly, whether your order sits in the leak, and look in your inbox for a notification. Then treat every incoming approach relating to your purchase, whatever the channel, as unverified until you have confirmed it yourself through an official route. Do not set up hardware you did not order. Do not enter your seed phrase under any circumstances, not even into a form that looks genuine. And reconsider the delivery address for future orders, for instance a parcel locker or an alternative delivery point.

What you do not have to do: replace the device or set the wallet up again. Since no wallet credentials are affected on the company’s account, there is no reason for it. Anyone who nevertheless wants to move out of caution should do so through a self-controlled fresh setup with a newly generated seed phrase, and not through a device sent to them.

GDPR and Data Breaches: What Rights Customers in Germany Have

Even though SafePal is not based in the EU, the General Data Protection Regulation applies as soon as goods are delivered to people in the EU. Two practical claims follow for you. Under Article 15 GDPR you can request information about which data are stored about you. Under Article 34 GDPR a controller is obliged to notify data subjects without undue delay where a personal data breach is likely to result in a high risk to them.

Whether the notification in this case meets the standard of undue delay is an assessment for supervisory authorities, not for us. All that can be recorded is the chronology: first indication in early May, notification in mid-August. Anyone wanting to pursue the matter can turn to the data protection authority responsible for the provider; in Germany the relevant state data protection authority is the right place for a complaint.

Independently of that, documentation is worthwhile. Keep the notification email and the result of your check. Should damage arise later, evidence of when you knew what is the starting point for anything that follows.

Checking the SafePal Data Breach: What to Take Away

The incident affects a manageable group, but for that group it is serious, because the exposed details remain valid indefinitely. Three steps put you on solid ground within minutes.

  1. Check the order and classify the contacts. See whether your purchase falls between March 2, 2025 and April 11, 2026, and verify the result through the manufacturer’s address typed in yourself. Treat every call and every message about your purchase as unverified until you have checked it. If you then rethink custody, the hardware wallet comparison is the sober place to start.
  2. Do not set up a device you did not order. That single rule covers the most dangerous variant of the scam in full. For amounts where postal delivery does not pay off anyway, the software wallet comparison is the obvious alternative.
  3. Make data economy a habit. Shorter retention periods and fewer details on file limit the damage of the next leak before it happens. That applies to merchants as much as to trading venues; which providers operate under European supervision is shown in the overview of regulated crypto exchanges.

(As of August 20, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)



Source link

Blockonomics

Be the first to comment

Leave a Reply

Your email address will not be published.


*