Need help? Support
BITCOIN
Tether Dominance USDT.D

SafePal data breach exposes nearly 40,000 customers

Published Updated 536 words 3 min read

TLDR

SafePal has confirmed a data breach that exposed order information and personal details for about 39,798 customers, but not any wallet keys or crypto funds.

  1. SafePal reports an authorization flaw in its order-tracking plug-in exposed names, emails, phone numbers, shipping addresses and purchase details for orders between March 2025 and April 2026.
  2. The company and multiple reports say seed phrases, private keys, wallet passwords, bank details and government IDs were not touched, but affected users face elevated phishing and impersonation risk.
  3. This incident adds to a wider pattern of hardware wallet security problems, highlighting that self-custody users must watch data handling and phishing protections, not just how keys are stored.

Deep Dive

1. What Was Breached

SafePals own security update states that an authorization flaw in an order-tracking plug-in let outsiders view other customers order records by manipulating order numbers, affecting orders placed from 2 Mar 2025 to 11 Apr 2026 and around 39,798 customers in total.SafePal security update

According to coverage from outlets like CoinDesk, the exposed dataset includes names, physical addresses, email addresses, phone numbers and purchase details for hardware wallet buyers, all tied to clear evidence of crypto ownership.SafePal reveals data breach

SafePal says it has patched the plug-in, tightened personal data retention in that environment to 90 days, emailed all affected customers and taken down dozens of phishing sites linked to the incident.SafePal security update

2. Wallet Impact And User Risk

SafePal repeatedly emphasizes that the breach did not involve seed phrases, private keys, wallet passwords, bank account information, payment card numbers or government IDs, and that there is no evidence of wallets or funds being compromised.SafePal security update

However, the leaked order data creates a strong basis for targeted phishing and impersonation, with attackers posing as SafePal support or refund teams and using accurate order details to gain trust.Wallet provider SafePal says data breach exposed personal info

Reports from security firms warn that combining home addresses and proof of crypto holdings can also raise the risk of wrench attacks, meaning physical coercion against identified holders.SafePal breach exposes 40,000 customers

What this means

The main danger is not direct wallet hacking but convincing scams and, in some regions, physical targeting of known crypto owners, so verification habits become critical.

3. Broader Hardware Wallet Security Trend

This breach lands in a string of hardware wallet incidents where supporting infrastructure, not the key-storage chip, failed. Recent cases include Trezor and Ledger data leaks and a Coldcard key-generation flaw tied to large Bitcoin losses.Safepal breach exposes 40,000 customers

Investigators like ZachXBT have started tracking these events as a pattern, arguing that customer data, logistics systems and third-party plugins are now as important to watch as the wallet firmware itself.ZachXBT hardware wallet scoreboard

For crypto users, the practical implication is that self-custody risk now spans device choice, where you buy it, how vendors store your order data and how well you can spot impersonation attempts.

Conclusion

SafePals breach did not directly compromise wallet keys or on-chain funds, but it did expose identifiable personal data for nearly 40,000 hardware wallet customers. That exposure significantly raises phishing and physical security risks and reinforces a broader lesson for self-custody users: strong key storage is only part of the story, and careful data handling plus strict verification of any contact about your wallet are now core to staying safe.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top