SafePal is notifying nearly 40,000 customers after attackers exploited a vulnerability in an order-tracking component and gained access to personal information associated with purchases of the company’s cryptocurrency hardware wallets.
The incident affected 39,798 customers who placed orders between March 2, 2025, and April 11, 2026. The compromised information includes names, postal addresses, email addresses, telephone numbers and order details. SafePal disclosed the breach on August 16, the same day a threat actor began advertising the stolen dataset on a cybercrime forum.
The incident is particularly sensitive because SafePal operates in the cryptocurrency sector. While the stolen database does not appear to contain the cryptographic secrets necessary to directly access wallets, customer information can provide attackers with something extremely valuable: a list of identifiable cryptocurrency users who can be targeted with convincing social-engineering attacks.
A vulnerability in the order systemAccording to SafePal, the attackers exploited a flaw in the order-tracking functionality of a customer order information plugin. The vulnerability provided access to information associated with customers who had purchased SafePal products.
The company began investigating after receiving a report in May, initially treating the situation as an isolated case. A broader review later revealed a problem in SafePal’s systems that caused order information to remain stored significantly longer than intended. SafePal began rebuilding its order-processing pipeline in July and eventually confirmed the underlying cause of the incident.
The breach therefore raises two separate security questions. The first concerns the vulnerability that allowed unauthorized access. The second concerns data retention: information that might no longer have been operationally necessary remained available long enough to be stolen.
This is an important distinction. Security teams often concentrate on preventing unauthorized access, but reducing the amount of historical information retained can substantially limit the consequences when prevention fails.
Wallet credentials were not compromisedSafePal stressed that the incident did not expose seed phrases, private keys, wallet passwords or other wallet credentials. Bank account information, payment card numbers and government identification numbers were also not affected.
That significantly limits the immediate financial impact. An attacker cannot simply take the leaked customer database and use it to reconstruct victims’ cryptocurrency wallets.
However, the absence of private keys does not make the breach harmless.
A dataset combining names, contact information and confirmed SafePal purchases provides attackers with highly useful targeting intelligence. Instead of sending generic cryptocurrency phishing messages to millions of random addresses, criminals can contact people they know have purchased a specific hardware wallet.
That allows considerably more convincing scams.
An attacker could impersonate SafePal and claim that a customer’s wallet needs to be “verified” following the breach, for example, before directing the victim toward a fraudulent website designed to capture their seed phrase. Telephone numbers and postal addresses provide additional channels for impersonation.
The breach can therefore become the starting point for attacks rather than the mechanism that directly steals cryptocurrency.
SafePal is already fighting phishing infrastructureThat secondary threat is not theoretical. SafePal says it has already identified and removed more than 30 fraudulent websites and phishing links associated with scam activity and continues monitoring for additional malicious infrastructure.
The company is warning affected customers to be particularly suspicious of emails, websites, telephone calls or letters requesting seed phrases or private keys.
Anyone who has already entered a seed phrase or private key into a suspicious website or provided it through another questionable communication should consider the wallet compromised. SafePal recommends creating a new wallet using a trusted device or its official application and transferring remaining assets to the new wallet.
This illustrates why cryptocurrency breaches create a distinctive type of follow-on risk. Traditional account credentials can often be reset after phishing. A cryptocurrency seed phrase is fundamentally different: whoever possesses it can potentially control the wallet.
Once exposed, it cannot simply be “changed” while keeping the same wallet. Assets need to be moved to a newly generated wallet whose private keys remain secret.
Physical information creates another concernThe inclusion of postal addresses deserves particular attention in the context of cryptocurrency.
A leaked email address reveals that someone may be interested in crypto. An order record showing that a specific individual purchased a hardware wallet and providing their physical address establishes a considerably stronger connection.
Hardware wallets are generally purchased by users who want to secure cryptocurrency assets themselves rather than leave them entirely under the control of an exchange. That does not reveal how much cryptocurrency an individual owns—or whether they currently own any—but it can still make those individuals attractive targets for highly focused scams.
For this reason, cryptocurrency companies should treat customer shipping information as particularly sensitive even when it contains no financial credentials.
The SafePal incident reinforces a difficult privacy problem for hardware-wallet manufacturers: physical products need to be delivered somewhere, creating customer records that can remain valuable to attackers long after the transaction itself has been completed.
The attacker claims the same number of victimsSafePal’s disclosure coincided with a threat actor advertising stolen company data on a cybercrime forum. The attacker claimed information belonging to 39,798 individuals—the same figure subsequently provided by SafePal.
SafePal says it has fixed the exploited vulnerability and shortened the retention period for order information. It has also notified affected customers, contacted partners to determine whether the issue spread beyond its own environment and hired an external security company to assist with the investigation.
The company is additionally asking customers who believe they suffered financial losses connected to the incident to provide details. SafePal says it has contacted specialists capable of tracing cryptocurrency assets on-chain, although it emphasized that this does not constitute an admission of liability or a commitment to compensate victims.
The bigger risk is what attackers do nextThe SafePal breach is a useful reminder that the severity of a data leak cannot be measured exclusively by whether passwords or financial credentials were stolen.
Context matters.
A database containing an address and telephone number may appear relatively ordinary. Add the knowledge that the person purchased a cryptocurrency hardware wallet, however, and the information becomes substantially more valuable for targeted social engineering.
SafePal appears to have prevented the breach from directly exposing the cryptographic secrets protecting customer wallets. The next challenge is preventing attackers from convincing customers to surrender those secrets themselves.
For affected users, the most important rule remains simple:SafePal, or anyone legitimately assisting with the incident, should never need a customer’s seed phrase or private key to investigate the breach. Any message requesting those secrets should be treated as an attempt to steal the wallet.