TLDR
SafePal has confirmed a customer data breach affecting about 39,798 hardware wallet buyers, exposing order information but not crypto funds or private keys.
- An authorization flaw in an order tracking plugin exposed names, contact details and shipping addresses for orders placed between March 2025 and April 2026.
- The main risk is targeted phishing and impersonation, with some concern about physical targeting, but there is no evidence wallets or funds were directly compromised.
- SafePal has patched the flaw, reduced data retention and notified affected customers, while users should treat unsolicited support messages with extreme caution.
Deep Dive
1. Scope Of The Breach
SafePal disclosed that an authorization flaw in a plugin used to track customer orders allowed attackers to view other customers order details for approximately 39,798 people who bought products between 2 March 2025 and 11 April 2026, including names, emails, phone numbers, shipping addresses and purchase details, according to several reports and SafePals incident notice itself.
Crucially, the company and independent coverage agree that seed phrases, private keys, wallet passwords, bank account information, payment card numbers and government IDs were not exposed, meaning on chain access to funds was not directly compromised.
Confidence: high because SafePals own report and multiple major outlets like CoinDesk and crypto.news describe the same numbers, data types and time window.
2. Risks For Affected Users
The leaked data can be used to craft highly convincing phishing and impersonation attempts, such as fake refund offers, firmware updates, replacement devices or customer support contacts that try to trick users into revealing wallet credentials or seed phrases, as warned in SafePals incident report and summarized by outlets like TradingView and crypto.news.
Because physical addresses were exposed, some security researchers have also flagged the potential for so called wrench attacks, where criminals target individuals in person, a risk that has shown up in hardware wallet breaches more broadly.
The biggest threat is social engineering, not a direct hack of your wallet, so the practical defense is to never share your recovery phrase or private keys with anyone and to treat unexpected SafePal branded messages as suspicious unless verified through official channels.
3. SafePals Response And User Steps
SafePal says it has fixed the plugin flaw, implemented stricter access controls, hired a third party security firm to audit its order systems, shortened personal data retention to around 90 days and taken down more than 30 related phishing sites, while emailing all known affected customers individually.
For users, the key steps are behavioral rather than technical: assume attackers may know your name, address and what you ordered, verify any support interaction through SafePals official site or app, and if you ever entered a seed phrase or private key on a suspicious site or in response to a message, treat that wallet as compromised and migrate funds to a fresh wallet generated securely.
Conclusion
This breach is serious for privacy and phishing risk but, based on current evidence, it does not directly compromise SafePal wallets or crypto funds. The practical takeaway for crypto users is to harden their habits around recovery phrases and support communications, and to assume that order and contact data may be known to attackers even when their on chain assets remain technically secure.
