TLDR
SafePal, a major non-custodial crypto wallet provider, has confirmed a data breach that exposed order information for 39,798 customers, but wallet funds and private keys remain unaffected.
- The breach revealed names, physical addresses and contact details tied to hardware wallet orders between March 2025 and April 2026.
- No seed phrases, private keys or payment card data were exposed, but affected users face elevated phishing and impersonation risk.
- SafePal has patched the flaw, tightened data retention and released tools for users to check exposure and harden their personal security.
Deep Dive
1. Scope Of The Breach
SafePal disclosed that an authorization flaw in a plug-in used to track customer orders allowed an attacker to view other customers order details by manipulating order numbers, exposing the names, street addresses and contact information of 39,798 customers who placed orders between 2 March 2025 and 11 April 2026 according to a detailed incident report.
Critically, SafePal states that cryptocurrency funds, seed phrases, private keys, bank details, payment card numbers and government IDs were not accessed in this incident. The breach targeted the commerce/order-tracking layer, not the wallets key-management systems.
SafePal already had a policy of periodically deleting hardware wallet order information and minimizing personal data retention, described in its earlier privacy blog. The new incident has pushed the company to further shorten retention windows.
2. Wallet Security And User Risk
SafePal emphasizes that the core security of its hardware and software wallets is intact. Private keys remain offline on devices, and there is no evidence the attacker accessed wallet internals or cryptographic material in the breach report.
However, exposed identity and contact data can be weaponized for phishing and social engineering. Attackers can craft credible emails, messages or even physical mail that reference real order details, trying to trick users into revealing seed phrases or authorizing transfers. Similar third-party data leaks at other hardware wallet brands, such as shipping-provider breaches affecting Trezor customers, have primarily led to scam attempts rather than direct wallet compromise.
Confidence: high, because the available reports consistently separate exposed order data from wallet secret material.
The main risk is not that your SafePal wallet suddenly became insecure, but that scammers now have better targeting data and may try harder to trick you into voluntarily giving up your keys.
3. SafePals Response And What Users Should Do
SafePal reports that it has patched the vulnerable plug-in, added extra security controls and hired an independent security firm to audit the fix and review its order-processing systems, per the incident disclosure. It also plans to retain personal order data for only 90 days going forward.
The company has removed more than 30 fraudulent websites and phishing links related to the incident and published a verification tool on its site that lets customers check whether their order data was affected. Users who ever responded to suspicious emails or messages by sharing seed phrases or private keys are advised to treat those wallets as compromised and move assets to a new wallet.
For general hygiene, SafePals own privacy guidance recommends using purpose-specific emails, avoiding real names on shopping accounts, rotating passwords, and considering business addresses or alternate phone numbers for deliveries, as outlined in its privacy practices.
If you bought a SafePal device in the affected window, check your status via SafePals official tools, be extremely skeptical of any contact asking for codes or seed phrases, and consider tightening how you use personal data for future crypto purchases.
Conclusion
This breach is serious for privacy but, based on current information, it did not directly compromise SafePal wallets or crypto funds. The main transmission mechanism into real loss is social engineering that convinces users to hand over their own secrets.
For crypto users, the takeaway is to treat identity leaks as a phishing amplifier, not as proof that non-custodial storage has failed. Vigilant verification of communications and careful handling of personal data remain central to staying safe around hardware wallets.
