Crypto wallet provider SafePal has disclosed a data breach affecting approximately 39,798 customers after an authorization vulnerability in an order-tracking plugin allowed unauthorized parties to access personal information associated with hardware-wallet purchases. The exposed records covered orders placed between March 2, 2025, and April 11, 2026, according to SafePal’s disclosure on August 16.
Compromised information included customer names, email addresses, shipping addresses, phone numbers and purchase details. The company said wallet seed phrases, private keys, passwords, payment-card information, bank-account details and government identification documents were not exposed. SafePal also said it had found no evidence that the incident directly compromised users’ wallets or resulted in customer funds being stolen. The distinction is important for a non-custodial wallet provider. While attackers did not obtain the cryptographic credentials needed to directly control wallets, leaked contact and purchasing information can identify individuals as cryptocurrency holders and facilitate highly targeted phishing attacks.
Order-Tracking Plugin Created the Exposure
SafePal traced the incident to an authorization defect in a plugin used for tracking customer orders. Under certain conditions, the vulnerability allowed an unauthorized party to access information belonging to another customer. SafePal said the flaw has now been fixed and additional access controls have been implemented. The company first received a phishing report consistent with the eventual breach in early May. SafePal initially investigated it as an isolated incident before escalating its response and beginning a wider review of its order-processing infrastructure. A full review and rebuild of the order-processing pipeline began in July, when investigators ultimately confirmed the authorization flaw.
A separate data-retention configuration problem also contributed to the scale of the incident by keeping some older customer records available longer than SafePal intended. SafePal has since shortened the retention period for personal order information to 90 days.
Crypto Customer Data Creates a Unique Security Risk
Although no private keys were exposed, the combination of names, addresses and crypto-hardware purchase histories makes the breach particularly sensitive. Hardware-wallet customer databases can effectively identify people likely to hold digital assets. That information can be exploited for personalized phishing messages containing genuine order details, making fraudulent communications considerably more convincing. SafePal said it has already taken down more than 30 phishing websites associated with malicious activity and has individually notified affected customers. It has also introduced a verification tool allowing customers to check whether an order was affected using their order number and shipping country.
The incident follows other breaches involving hardware-wallet customer information, highlighting a recurring weakness around the physical distribution of otherwise highly secure self-custody products. A hardware wallet can keep private keys isolated from internet-connected systems, but purchasing and shipping the device still requires conventional e-commerce infrastructure containing personally identifiable information. For SafePal’s roughly 39,800 affected customers, the immediate cryptographic threat therefore appears limited. Their seed phrases and private keys remain unaffected by the disclosed breach. The longer-term risk is different: attackers may now possess enough legitimate personal and purchase information to convincingly impersonate SafePal and persuade customers to surrender those credentials themselves.
