TLDR
SafePal has confirmed a data breach in its order-tracking system that exposed personal order information for about 39,798 customers but did not compromise wallets or private keys.
- The breach came from an authorization flaw in an order-tracking plugin, exposing names, emails, shipping addresses, phone numbers and purchase details for orders between March 2025 and April 2026.
- Affected users face elevated phishing and impersonation risks, plus potential physical targeting, even though seed phrases, private keys and funds remain technically secure.
- SafePal has patched the flaw, shortened data retention to 90 days and notified customers, but criticism over delayed disclosure means users should stay alert for follow up findings and scam activity.
Deep Dive
1. What Was Exposed
SafePal, a non custodial hardware and software wallet provider, reports that an authorization flaw in its order tracking plugin allowed external access to order data for around 39,798 customers who bought products between 2 March 2025 and 11 April 2026. Multiple outlets note that the exposed fields include names, email addresses, shipping addresses, phone numbers and detailed purchase information such as what devices were ordered. This matches descriptions in several reports that the incident was limited to e commerce order data, not in wallet software or blockchain level records.
If you ever ordered a SafePal device in that window, your real world identity and delivery address may now be linked to your hardware wallet use, even if your on chain activity is pseudonymous.
2. Wallet Safety And Main Risks
SafePal and independent coverage consistently state that no seed phrases, private keys, wallet passwords, payment card numbers, bank accounts or government IDs were exposed and there is no evidence that wallet access or crypto balances were directly compromised. The primary risk is social engineering using highly personalized data, for example emails or calls posing as SafePal support, offering refunds, replacements or firmware updates while trying to trick users into revealing recovery phrases or entering keys on fake sites. Some analysts also highlight the risk of so called wrench attacks, meaning physical coercion, because shipping addresses and device ownership are now known for thousands of users.
The technical security of SafePal devices is not the weak point here, but human factors are. The safest stance is to treat any unsolicited contact referencing your order as suspicious, and never share seed phrases or private keys.
3. SafePals Response And What To Watch
SafePal says it has fixed the plugin flaw, implemented extra access controls, hired a third party security auditor and reduced retention of order data to 90 days, while removing dozens of phishing sites that appeared around the incident. Affected customers were emailed individually and can check their status via a verification tool using order ID and shipping country. However, reports show SafePal first received phishing complaints months earlier and only publicly disclosed the breach in mid August 2026, drawing criticism over delayed transparency and leaving some uncertainty about how widely the data has already circulated.
Even if you receive an official notification, the more durable risk is ongoing phishing built on leaked data. Monitoring your inbox and social messages for impersonation, and considering diversifying storage solutions, can reduce single point of failure risk.
Conclusion
This breach underscores that hardware wallet security is not just about chips and firmware but also about how customer data and logistics systems are managed. For SafePal users, the core cryptography remains intact, but linking real world identities to device purchases creates a new layer of social and physical risk. The practical takeaway is to harden your behavior against phishing and impersonation and to treat any request for recovery phrases or keys as an immediate red flag, regardless of how convincing the sender appears.
