SafePal disclosed a data breach exposing order details of 39,798 customers who purchased hardware wallets between March 2, 2025 and April 11, 2026.
The Binance Labs-backed wallet maker said in a security update that an "authorization flaw" in a plug-in used to track customer orders allowed attackers to view other customers' order information. The flaw functioned like a parcel-tracking system that let one customer view another customer's receipt and delivery details by changing the order number.
Exposed data included names, physical addresses, contact details, device models, quantities ordered, delivery locations, and payment methods used at checkout. SafePal said seed phrases, private keys, bank account information, payment card numbers, and government-issued IDs were not compromised. The company does not require KYC verification or account registration to use its services.
Affected users face heightened phishing and impersonation risk. SafePal has patched the vulnerability, hired an independent third-party security firm to audit the fix and review its order-processing systems, and removed more than 30 fraudulent websites and phishing links associated with the breach. The company will now retain customer personal data in its order-processing system for only 90 days from collection.
The incident draws comparisons to Ledger's 2020 database breach, which exposed personal information of more than one million customers and led to phishing emails, threatening letters, and physical threats tied to home addresses. SafePal has maintained a clean record on wallet security since its founding in 2018, with no known wallet hacks reported in that span.
The breach follows a separate incident involving Coldcard hardware wallets, in which an attacker reportedly stole at least $120 million in bitcoin after exploiting a firmware flaw in seed phrase generation. While the incidents do not point to a systemic weakness in hardware wallets, they show that no crypto-storage solution is entirely risk-free.
SafePal's S1 device is marketed as fully air-gapped, operating without Bluetooth, WiFi, NFC, or USB connectivity. Investigations conducted through mid-August 2026 found no evidence that seed phrases or private keys were compromised.
Customers can use a verification tool on SafePal's website to check whether their data was affected. SafePal notified all affected customers by email from [email protected]. Users who shared private keys or seed phrases via phishing emails, phone calls, or letters should treat their wallets as compromised and transfer assets to new wallets.
The breach could erode user trust in the wallet provider and raise short-term concerns about security practices across the broader crypto wallet sector. With hardware wallet demand surging — Russian retailers reported sales doubling ahead of new regulations taking effect Sept. 1 — data protection will likely face increased scrutiny from both users and regulators.
This article is for informational purposes only and does not constitute investment advice.