SafePal Data Breach Exposes Details of 39,798 Customers
A data breach at SafePal, a hardware wallet maker, has exposed the names, email addresses, delivery addresses, phone numbers, and order details of 39,798 customers. The incident occurred on August 16, 2026, after an authorization flaw in a plugin used for order tracking was discovered. This allowed another customer's order to be viewed under certain conditions.
The company has notified affected customers by email and published a lookup tool that allows them to check if their order is part of the leak. The breach only affects orders placed between March 2, 2025, and April 11, 2026.
The leaked data alone cannot move funds, as seed phrases, private keys, wallet passwords, and other wallet credentials were not affected. However, an attacker who knows a customer's name, home address, phone number, and order date may try to have the seed phrase handed over, making targeted phishing or physical assaults on wallet owners possible.