Cryptocurrency hardware wallet maker SafePal has disclosed a data breach affecting roughly 39,798 customers after attackers exploited a flaw in its order-tracking system to steal personal order information. A threat actor is now claiming to sell the stolen data on a cybercrime forum.
According to SafePal’s security advisory, the breach affects customers who placed orders between March 2, 2025, and April 11, 2026. Exposed data includes names, email addresses, shipping addresses, phone numbers, and purchase details. SafePal says wallet seed phrases, private keys, passwords, payment card numbers, government-issued IDs, and other credentials were not exposed, and it found no evidence that wallets or funds were directly compromised.
Order-tracking flaw traced to third-party plug-in
SafePal says it first received a report consistent with the issue in early May 2026 but initially treated it as an isolated case. In July, the company launched a full review and rebuild of its order-processing system, uncovering an authorization flaw in the order-tracking function of a plug-in that allowed unauthorized access to other customers’ order information. The investigation later determined that a threat actor had exploited the flaw to steal data belonging to approximately 39,798 customers.
A separate configuration error was also found: a data-cleanup process stopped working correctly between September 2025 and April 2026, causing order data to be retained further back than intended, as far as March 2025.
Stolen data offered for sale
A seller on a cybercrime forum, spotted by DarkWebInformer, is advertising data matching the same affected period and customer count disclosed by SafePal. The seller is offering to share order IDs and shipping countries from stolen records, which buyers can verify using SafePal’s own online verification tool. BleepingComputer has not independently confirmed the seller actually possesses the data.
SafePal notified affected customers by email on August 16 and has published a verification tool where customers can check if their order was impacted using their order number and shipping country.
Phishing risk and recommended actions
SafePal warns that the stolen information could fuel targeted phishing and social engineering attacks, noting reports of SafePal-themed phishing emails and calls as early as May, including messages about a fake firmware update for the SafePal X1 hardware wallet. The company says it has taken down more than 30 fraudulent websites and phishing links tied to the incident.
Customers whose data was exposed do not need to replace their hardware wallets or move funds solely because of this breach. However, anyone who already shared a seed phrase or private key in response to a phishing message should treat that wallet as compromised and migrate assets to a new wallet using a trusted device or the official SafePal app.
