Need help? Support
BITCOIN
Tether Dominance USDT.D

SafePal wallet data breach exposes users

Published 496 words 3 min read

TLDR

SafePal (SFP) has confirmed a major data breach that exposed personal order details for nearly 40,000 hardware wallet customers, increasing real-world and phishing risks while leaving funds and wallet keys untouched.

  1. SafePal reported that a flaw in an order-tracking plug-in leaked names, emails, shipping addresses, phone numbers, and purchase details for about 39,798 customers, but no seed phrases or private keys.
  2. The stolen records are already being advertised on cybercrime forums, creating a targeting list for phishing, scams, and potential home-invasion style attacks against identifiable crypto holders.
  3. The breach extends a broader pattern of hardware wallet and broker data leaks, showing that self-custody protects keys but does not automatically protect user identity or privacy.

Deep Dive

1. Breach Details And Scope

SafePal disclosed that an authorization flaw in its e-commerce order-tracking plug-in exposed personal data for customers who placed orders between March 2 2025 and April 11 2026, including names, emails, shipping addresses, phone numbers, and purchase information for around 39,798 users. The company stated that seed phrases, private keys, wallet passwords, bank details, payment card numbers, and government IDs were not involved, and it has patched the plug-in, notified affected users, and set up a page for exposure checks. Multiple reports confirm these details from SafePals incident statement, including coverage by Decrypt.

Confidence: high, because independent outlets and SafePals own report align on the scale, timeframe, and data types involved.

2. User Impact And Risk Path

Investigators report that the leaked file is already being offered for sale on a cybercrime forum, pairing home addresses and phone numbers with proof of hardware wallet ownership, which turns it into a ready-made list for phishing and physical targeting. This raises the risk of tailored scam emails referencing real orders, impersonation of support staff, and so-called wrench attacks, where criminals threaten victims to extract crypto, as highlighted in The Defiants coverage.

What this means

Even if your funds and keys are safe, any exposed personal data materially increases the importance of strict phishing awareness and cautious handling of any messages that reference past SafePal orders.

3. Part Of A Wider Security Trend

The SafePal incident is not isolated and comes alongside recent data leaks at Trezor, Ledgers historical customer database leak, and breaches at brokers like Bits of Gold, as well as technical wallet failures like Coldcards key-generation flaw. Recent analysis notes a rising wave of hardware wallet related attacks, where data leaks and software bugs together have contributed to tens of millions of dollars in losses and heightened physical risk, as discussed by CryptoSlate. This underscores that the broader hardware wallet ecosystem must harden not only key storage, but also data handling and third-party integrations.

Conclusion

SafePals breach shows that in crypto, protecting private keys is only part of the security story, and poorly secured customer data can still expose users to serious phishing and real-world threats. For self-custody users, the practical takeaway is that wallet choice should factor in vendor data practices and third-party dependencies, and that strong operational hygiene around emails, messages, and identity remains as important as on-chain security.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top