TLDR
SafePal has confirmed a non wallet data breach that exposed personal and order information for about 39,798 customers.
- An authorization flaw in an order tracking plug in exposed names, emails, phone numbers, shipping addresses and purchase details for orders between March 2025 and April 2026.
- Seed phrases, private keys and wallet passwords were not touched, but the leaked data significantly raises phishing and even physical targeting risks for affected users.
- The incident fits a wider pattern of hardware wallet security failures, so crypto users should treat vendor data practices as part of their overall self custody risk.
Confidence: high, based on multiple consistent incident reports and SafePals own disclosure.
Deep Dive
1. What Was Exposed
SafePal reported that an authorization flaw in its e commerce order tracking system let attackers access personal data for roughly 39,798 customers who placed orders between 2 March 2025 and 11 April 2026, including names, email addresses, phone numbers, shipping addresses and purchase details as described in its incident reports and coverage by Bitcoin.com and Decrypt.
The company says it has patched the plug in, tightened data retention to around 90 days, taken down more than 30 related phishing sites, and emailed all known affected customers with a link to a status check page.
2. What Stayed Safe And Main Risks
SafePal has repeatedly stated that wallet credentials including seed phrases, private keys, wallet passwords, bank details, card numbers and government IDs were not stored in this system and were not compromised in the breach, and there is no evidence so far of funds being stolen directly from SafePal wallets.
The main risk is targeted social engineering and physical threats, because the leaked data combines proof that someone bought a hardware wallet with a real world address and contact details, which media reports tie to rising so called wrench attacks and home invasions against crypto holders in 20252026, as highlighted by CryptoSlate.
If you are a SafePal customer, the critical safeguard is strict skepticism toward any contact claiming to be support, especially offers of refunds, firmware updates or replacements that ask for recovery phrases or passwords.
3. Wider Hardware Wallet Security Trend
This breach comes alongside other hardware wallet incidents, including Trezors data leak via ShipMonk and Coldcards separate firmware flaw with large Bitcoin losses, showing that even non custodial devices depend on vendor infrastructure and third party services that can fail, as covered in wider analyses of hardware wallet security issues.
For crypto users, the emerging pattern is that hardware wallets protect keys against many on chain and software risks, but they do not remove exposure to off chain data leaks, poor retention policies, and weak supplier security.
Conclusion
The SafePal breach did not directly compromise wallets, but it did expose enough personal and order data to materially increase phishing and physical targeting risk for nearly forty thousand customers. For self custody users, the key takeaway is that evaluating a wallet provider now needs to include both device level security and how it collects, stores and cleans up customer data, with ongoing vigilance against social engineering as an integral part of protecting funds.
