TL;DR
- At data breach at SafePal exposed order information for 39,798 customers, including names, contact details, shipping addresses and purchase records.
- SafePal says it never stored wallet credentials in the affected system, but the exposed data could support targeted phishing and other security risks.
- A dataset matching SafePal’s disclosed customer count and order window has been advertised for sale online, though its authenticity has not been independently confirmed.
SafePal disclosed on August 16 that unauthorized parties accessed order information for approximately 39,798 customers. The exposed records included names, email addresses, shipping addresses, phone numbers and purchase details.
SafePal’s hardware wallets ship blank. Customers generate their own seed phrase, private key and wallet password after delivery. That data never reaches SafePal’s systems, meaning it was never there for the breach, or the attacker, to reach. The data breach also did not involve payment-card numbers or government identification, according to the company.
The immediate concern after this incident is targeted phishing. A scammer who knows which wallet someone bought and where it was delivered can make a fake support message look more convincing.
An order-tracking flaw exposed customer details
SafePal traced the incident to an authorization flaw in a plug-in used for tracking orders. Under certain conditions, the flaw allowed an unauthorized person to view another customer’s order information.
The affected records relate to orders placed from March 2, 2025, through April 11, 2026. SafePal has not said when the unauthorized access began or how long it lasted.
SafePal’s incident FAQ says the company received its first report consistent with the problem in early May. It initially treated the report as an isolated case, then opened a broader investigation. The company began rebuilding its order-processing pipeline in July and says that work confirmed the cause.
Apart from the order-tracking flaw, SafePal also detected a separate glitch in its data-retention process. The company’s automated cleanup process stopped working correctly between September 2025 and April 2026. Though it is not directly related to the authorization flaw, it kept customer records longer than needed, increasing the number of affected users.
>>> Read more: ShipMonk Breach Exposes Data of 13,689 Trezor Customers
Why the SafePal data breach creates phishing risk
Anyone who owns cryptocurrency has reason to treat their delivery details as sensitive, not just hardware-wallet buyers. A shipping address tied to a crypto purchase can reveal a location where a specific person can be found, whether that’s their home, workplace or anywhere else they receive deliveries. Phishing remains the primary risk from this kind of exposure. But wrench attacks, physical robberies where someone is targeted and coerced into handing over their crypto, are becoming more common. A data leak like this one can carry consequences beyond phishing.
SafePal warned customers about fraudulent calls, emails, text messages and letters. For example, a scammer might pose as support staff, offering a fake refund or a bogus replacement device as a pretext to ask for a recovery phrase or private key.
So far, the company says it has identified and removed more than 30 fraudulent websites and phishing links connected with the activity. The company has not provided estimates on how many customers lost money, or how much of the stolen data has actually been misused.
Meanwhile, the stolen dataset appeared for sale on a cybercrime forum, according to the security research account DarkWebInformer. The listing cites the same order window and the same customer count SafePal disclosed. There is no independent confirmation that the data offered for sale is authentic.
When affected users need to move funds
SafePal emailed affected customers from security@safepal.com on August 16. Buyers can also check an order number and shipping country through the verification page on SafePal’s website.
The company says customers do not need to replace their hardware wallet or move their assets solely because their order information was included in the incident. But if they entered a seed phrase or private key somewhere after receiving a suspicious message, that wallet should be treated as compromised. SafePal recommends creating a new wallet through a trusted device or official application and moving any remaining assets to it right away.
Customers should not follow any links in unexpected messages, and should instead type SafePal’s address directly into a browser. Genuine SafePal support staff will never request a recovery phrase, private key or wallet password.
>>> Read more: Coldcard Bitcoin Theft Expands with Fourth Wave
An independent review is still pending
SafePal says it fixed the authorization flaw and added more security controls. It also reduced the retention period for personal information in the relevant order-processing system to 90 days, subject to legal requirements.
The company also contacted its third-party logistics and fulfillment partners as part of the investigation. It found no evidence that the breach extended into their systems.
An independent review is underway, though SafePal did not name the security firm and did not publish any findings thus far.
There are still gaps to fill on when the data was accessed or how many unauthorized users were involved. SafePal must also evaluate any financial losses linked to phishing attempts stemming from the breach. The independent review and future incident updates should show whether the exposure remained limited to the records SafePal has identified.









[…] >>> Read more: SafePal Data Breach Exposes 39,798 Customer Orders […]