SafePal Data Breach Exposes Order Information of Nearly 40,000 Customers
Cryptocurrency hardware wallet provider SafePal has warned of a data breach affecting approximately 39,798 customers. The incident occurred after attackers exploited a vulnerability in the company’s order-tracking system to access customer information. Threat actors are now reportedly attempting to sell the stolen data on cybercrime forums.
SafePal said the breach affected customers who placed orders between March 2, 2025, and April 11, 2026. Exposed information may include names, email addresses, shipping addresses, phone numbers, and purchase details.
The company said the incident did not expose customer wallet seed phrases, private keys, passwords, bank account information, payment card numbers, government-issued identification numbers, or other authentication credentials.
“We have found no evidence that the incident itself compromised SafePal’s wallets or access to funds,” the company said in a security advisory published Sunday.
SafePal said it notified all affected customers by email on August 16. The message used the subject line: “[Important] SafePal ordering information is affected.”
The company also launched an online verification tool that allows customers to enter their order number and shipping country to determine whether their order information was involved in the breach.
SafePal warned that the stolen data could be used in targeted phishing and social engineering attacks. Customers have already reported receiving SafePal-themed phishing emails and phone calls since May.
SafePal order-tracking vulnerability exposed customer data
Threat actors are reportedly claiming to sell stolen SafePal customer data on cybercrime forums.
As reported by DarkWebInformer, the seller cited the same affected order period and approximate number of customers disclosed by SafePal.
The threat actor also reportedly shared order ID and shipping country information from the stolen records with potential buyers. This information can be checked using SafePal’s online verification tool, apparently as proof that the data sale is legitimate.
“I’m not interested in lowball. Come to me for the right price. If not, don’t message me at all,” the forum post reads.

Source: DarkWebInformer
BleepingComputer has not independently verified whether the threat actor possesses the stolen SafePal customer data.
SafePal said it first received a report consistent with the incident in early May 2026. The company initially treated the report as an isolated issue before escalating it to a formal security investigation.
It is unclear whether the report is directly related to the breach, but one customer posted on X in May that they had received a SafePal phishing email and a phone call from someone claiming to be a company employee.
The phishing email claimed that a security vulnerability had been discovered in the SafePal X1 hardware wallet and that a firmware update was required to fix it.
“We first received a report consistent with this issue in early May, and while we treated it as an isolated incident at the time, we escalated it to a formal security investigation and introduced additional safeguards,” SafePal said in its advisory.
“Because our e-commerce system involves multiple interconnected components and external integrations, as well as third-party logistics partners, we cannot immediately rule out several possible explanations.”
In July, SafePal began what it described as a “complete overhaul and rebuild” of its order-processing system after discovering an authorization flaw in an order-tracking plugin. The vulnerability allowed unauthorized users to access another customer’s order information.
SafePal said it has fixed the vulnerability and implemented additional security measures. The company is also working with a third-party security firm to validate the patch and is conducting an extensive review of its order-processing system.
As part of the investigation, SafePal determined that attackers had exploited the flaw to steal order information belonging to approximately 39,798 customers.
The investigation also uncovered a separate configuration error that caused the data-cleanup process to stop working correctly between September 2025 and April 2026. As a result, order information dating back to March 2025 remained available in the system.
SafePal said it has deleted personal data associated with the affected orders from active e-commerce servers. However, the company is retaining encrypted offline copies in case they are required for law enforcement investigations.
Customers should be cautious of targeted phishing emails and phone calls involving firmware upgrades, product returns, refunds, or supposed legal investigations.
SafePal said it has already removed more than 30 fraudulent websites and phishing links connected to the incident.
Customers whose order information was exposed do not need to replace their hardware wallets or move their cryptocurrency solely because of this breach, according to SafePal.
However, if you have shared your seed phrase or private key in response to a phishing email, text message, or phone call, treat the wallet as compromised. Transfer all assets to a new wallet using a trusted SafePal device or the official SafePal application.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses can drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




