Cryptelio

Hacks & Exploits

SafePal Reveals Security Flaw Exposing Data of Nearly 40,000 Customers

Cryptelio Editorial Published 17 Aug 2026 · 09:01 UTC

SafePal, a provider of crypto hardware wallets, has reported a serious authorization flaw in its order-tracking plug-in that compromised sensitive customer data. This breach affected around 39,798 customers who placed orders between March 2, 2025, and April 11, 2026.

The exposed information includes names, email addresses, shipping addresses, phone numbers, and purchase details. However, SafePal confirmed that no wallet credentials or financial data were involved in the breach.

Upon discovering the flaw, SafePal acted swiftly to rectify the issue, implementing additional security measures and engaging a third-party auditor. The company has also reduced its data retention policy to 90 days and has notified all affected customers via email on August 16.

In a related effort to enhance security, SafePal has taken down over 30 fraudulent websites and phishing links targeting its customers. A dedicated support channel has been established, allowing customers to verify their status using their order ID and shipping country.

This incident is part of a troubling trend in the hardware wallet sector, where security breaches have become increasingly common. Other providers, such as Trezor and Ledger, have also faced similar incidents, raising concerns about the overall security of hardware wallets.

FAQ

What type of data was compromised in the SafePal security breach?

The compromised data includes names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers. However, no wallet credentials or financial data were involved.

How did SafePal respond to the security flaw?

SafePal acted swiftly to rectify the issue by implementing additional security measures, engaging a third-party auditor, and reducing its data retention policy to 90 days.

When were affected customers notified about the breach?

All affected customers were notified via email on August 16.

What steps has SafePal taken to enhance security after the breach?

SafePal has taken down over 30 fraudulent websites and phishing links targeting its customers and established a dedicated support channel for customers to verify their status using their order ID and shipping country.

Is this breach part of a larger trend in the hardware wallet sector?

Yes, this incident reflects a troubling trend in the hardware wallet sector, where security breaches have become increasingly common, with other providers like Trezor and Ledger also facing similar incidents.

Read story →