Technology

SafePal Data Breach Exposes 39,798 Crypto Wallet Customers

A vulnerability in SafePal's order-tracking plugin exposed personal data of nearly 40,000 customers. While crypto funds remain secure, affected users face heightened phishing risks.

Crypto hardware wallet maker SafePal suffered a data breach exposing personal information of 39,798 customers who ordered between March 2025 and April 2026. Wallet seed phrases and private keys remain secure. Affected customers face heightened risk of targeted phishing attacks.

SafePal, a company that manufactures hardware cryptocurrency wallets, has disclosed a data breach affecting 39,798 customers. The breach exposed personal information including names, email addresses, shipping addresses, phone numbers, and purchase details of customers who placed orders between March 2, 2025 and April 11, 2026.

What Happened

SafePal discovered a vulnerability in an order-tracking plugin that could have allowed unauthorized access to user order information. The company fixed the vulnerability, but not before someone accessed the data without authorization[reference:37]. In a statement, SafePal emphasized that wallet seed phrases, private keys, and the crypto assets themselves remained secure[reference:38].

"While your SafePal wallet, seed phrase, and private keys are secure, we identified a flaw in the order-tracking plug-in that led to unauthorized access to information of a subset of customers," the company said.

The Irony of Hardware Wallets

SafePal makes hardware wallets — thin gadgets that resemble a cross between a credit card and a tiny smartphone. These devices are supposed to be the ultimate safeguard for cryptocurrency. They're air-gapped, theoretically un-hackable resources for storing the crucial information needed to perform blockchain transactions. The idea is that even if your phone or computer is compromised, your crypto stays safe as long as you have a hardware wallet and practice good security hygiene.

The breach didn't compromise that fundamental security promise. The actual crypto remained locked up. But the exposed data creates a different kind of risk.

The Real Threat: Phishing

SafePal has warned that affected customers "might be targeted by more sophisticated phishing attempts." The company's website features a prominent warning about phishing with the hashtag #BewareOfPhishing[reference:39].

The danger is clear. Attackers now have the phone numbers and email addresses of nearly 40,000 people who own enough cryptocurrency to justify buying a hardware wallet. Those wallets themselves are the keys to potentially significant fortunes. With a little social engineering — using real names and regional specifics to craft convincing messages — attackers could pry those holdings out of at least a handful of victims.

A Growing Threat Landscape

This type of attack is part of a broader trend in crypto crime. So-called "$5 wrench attacks" — where criminals physically threaten victims to obtain their crypto keys — have become increasingly prominent[reference:40]. Phishing, by comparison, is less bloody but potentially more scalable. A single successful phishing campaign could compromise dozens of victims without anyone ever leaving their keyboard.

What Affected Customers Should Do

SafePal customers who placed orders during the affected period should be on high alert for suspicious communications. Any email or text message claiming to be from SafePal that asks for personal information, wallet credentials, or seed phrases should be treated as a potential phishing attempt. The company will never ask for seed phrases or private keys.

Customers should also consider changing passwords on any accounts associated with their SafePal purchases and enable two-factor authentication where available. The breach exposed personal information, not wallet credentials, but that information is now a weapon in the hands of attackers.