SafePal Data Breach Exposes Nearly 40,000 Customers to Phishing Risks
- Text Cryptocurrency hardware wallet provider SafePal has confirmed a data breach affecting approximately 39,798 customers, with stolen information now being offered for sale on a cybercrime forum, according...
Text
Cryptocurrency hardware wallet provider SafePal has confirmed a data breach affecting approximately 39,798 customers, with stolen information now being offered for sale on a cybercrime forum, according to a report from BleepingComputer. The breach, which exposed names, email addresses, shipping addresses, phone numbers, and purchase details, did not compromise wallet seed phrases, private keys, or financial credentials, the company stated in a security advisory published on August 16, 2026.
The incident originated from an authorization flaw in an order-tracking plugin used by SafePal’s e-commerce system, which allowed unauthorized access to customer order data. SafePal discovered the vulnerability during a July 2026 review of its order-processing infrastructure and attributed the breach to a threat actor exploiting the flaw to steal information from orders placed between March 2, 2025, and April 11, 2026. “No evidence has been found that the incident itself compromised access to SafePal wallets or funds,” the company said in its advisory.
Customers impacted by the breach received email notifications on August 16 with the subject line “[Important] Your SafePal Order Information Has Been Affected.” The company also launched an online verification tool allowing users to check if their orders were compromised by entering an order number and shipping country. BleepingComputer reported that a threat actor is offering the stolen data on a cybercrime forum, with the seller requesting “correct” payment terms and providing order ID and shipping country details as proof of legitimacy.
The breach has raised concerns about phishing risks, as SafePal noted that customers began reporting suspicious emails and phone calls as early as May 2026. One customer shared on X (formerly Twitter) that they received a phishing message claiming a security vulnerability existed in the SafePal X1 hardware wallet and urging a firmware update. SafePal initially treated this as an isolated case in May but escalated the investigation after discovering the broader flaw during its July review.
The company’s security advisory highlighted the complexity of its e-commerce system, which involves “multiple interconnected components and external integrations” as well as third-party logistics partners. SafePal said it has since “rebuilt” its order-processing system and is working with a third-party security firm to validate the fix and conduct a broader review. However, the breach underscores the risks of supply chain vulnerabilities in crypto infrastructure, a recurring issue for hardware wallet providers.
BleepingComputer noted that the stolen data’s potential for social engineering attacks is particularly concerning, as threat actors could use personal details to craft targeted phishing campaigns. The cybercrime forum post referencing the breach did not provide direct evidence of the data’s authenticity, but SafePal confirmed the affected order period and customer count align with its findings.
The incident adds to a series of security challenges for crypto wallet providers, including the 2022 Poly Network hack and 2023 Bitfinex data leak. SafePal’s breach highlights the ongoing struggle to secure user data in an industry where even non-financial information can be weaponized.
Customers are advised to monitor their accounts for suspicious activity and avoid clicking on links in unsolicited communications. SafePal has not yet provided specific guidance on mitigating risks beyond its verification tool.
Text
Breach Timeline and Technical Details
The vulnerability at the center of the breach was an authorization flaw in an order-tracking plugin, which SafePal identified during a “full review and rebuild” of its order-processing system in July 2026. The flaw allowed threat actors to access another customer’s order information by manipulating the plugin’s API, according to the company’s security advisory. SafePal said it fixed the issue and implemented additional security measures, but the breach had already occurred before the patch was deployed.
The company’s investigation revealed that the stolen data included “order tracking information,” which typically contains customer names, email addresses, shipping addresses, phone numbers, and purchase details. However, SafePal emphasized that sensitive data such as wallet seed phrases, private keys, passwords, bank account information, and payment card numbers were not exposed. “The breach did not involve any of these critical security elements,” the advisory stated.
Text
Phishing Risks and Customer Response
SafePal’s advisory warned that the stolen data could be used to conduct “targeted phishing and other social engineering attacks,” a concern echoed by cybersecurity experts. BleepingComputer reported that customers began encountering phishing attempts as early as May 2026, with one user sharing a screenshot of a fraudulent email claiming a security vulnerability existed in the SafePal X1 hardware wallet. The email urged recipients to download a “firmware update,” a common tactic in phishing campaigns.
The company said it first received a report consistent with the breach in early May 2026 but initially treated it as an isolated incident. SafePal later escalated the matter after discovering the broader flaw during its July review. “As our e-commerce system involves multiple interconnected components and external integrations, as well as third-party logistics partners, we could not immediately rule out several possible explanations,” the advisory read.
Text
Cybercrime Forum and Data Sale Claims
A threat actor is reportedly selling the stolen SafePal data on a cybercrime forum, according to a post analyzed by BleepingComputer affiliate DarkWebInformer. The seller described the dataset as containing information for approximately 39,798 customers and offered to share order ID and shipping country details to verify the data’s authenticity. The post included a demand for “correct” pricing, with the seller warning, “Not interested in low balls, please come correct and with a good price or do not message me at all.”
BleepingComputer noted that it has not independently verified the threat actor’s claims but confirmed the data’s scope aligns with SafePal’s disclosure. The company has not commented on the forum post but reiterated its recommendation for customers to use the verification tool and remain vigilant against phishing attempts.
Text
Industry Implications and Security Lessons
The SafePal breach underscores the growing risks facing cryptocurrency infrastructure, where even non-critical data can be exploited for malicious purposes. Hardware wallet providers, which store users’ private keys offline, are generally considered more secure than exchange-based solutions, but vulnerabilities in ancillary systems—such as order-tracking plugins—can still pose significant risks.
Cybersecurity analysts have pointed to the incident as a reminder of the importance of third-party risk management. SafePal’s advisory acknowledged the role of external integrations and logistics partners in the breach, highlighting how supply chain dependencies can introduce security gaps. “Organizations must continuously audit their third-party ecosystems to prevent such incidents,” said a security researcher at a cybersecurity firm not affiliated with SafePal.
The incident also raises questions about the adequacy of current data protection standards in the crypto industry. While SafePal’s disclosure includes specific details about the breach, critics argue that more transparency is needed to help users assess their own risks. “Users deserve clear guidance on what data was exposed and how they can protect themselves,” said a privacy advocate.
Text
Next Steps for SafePal and Users
SafePal has stated it is working with a third-party security firm to validate the fix for the order-tracking flaw and conduct a broader review of its systems. The company has not provided a timeline for completing these efforts but emphasized its commitment to improving security.
For users, the primary recommendation is to avoid engaging with unsolicited communications and to monitor accounts for unusual activity. SafePal’s verification tool remains the most direct way to determine if an order was affected. The company has also urged customers to reach out with questions via its support channels.
As the crypto industry continues to grapple with security challenges, the SafePal breach serves as a cautionary tale about the evolving threats facing digital asset custodians.
