Skip to main content
Emerging ThreatsData Breaches

SafePal Breach Exposes 39,798 Customer Records

A shipping box on a conveyor belt in a brightly-lit logistics facility with industrial equipment and shelving units.

"No evidence has been found that the incident itself compromised access to SafePal wallets or funds," SafePal said in a security advisory published Sunday.

What happened and who was affected

SafePal, a cryptocurrency hardware wallet provider, disclosed a data breach affecting about 39,798 customers whose orders were placed between March 2, 2025, and April 11, 2026. The company says the exposed fields include customer names, email addresses, shipping addresses, phone numbers, and purchase information. SafePal stated that sensitive credentials were not exposed: the breach did not reveal wallet seed phrases, private keys, passwords, bank account information, payment card numbers, government-issued identification numbers, or other credentials.

How the data was accessed: an order‑tracking plug‑in authorization flaw and a retention error

SafePal's investigation traced the incident to an authorization flaw in the order‑tracking function of a plug‑in used in its e-commerce system. The company said the flaw allowed unauthorized access to another customer's order information. In July, during a "full review and rebuild" of the order‑processing system, SafePal fixed the vulnerability and implemented additional security measures while engaging a third‑party security firm to validate the fix and conduct a broader review.

Separately, SafePal discovered a configuration error that stopped a data‑cleanup process between September 2025 and April 2026, which caused order data to be retained back to March 2025. For affected orders, SafePal says it has purged personal data from active e‑commerce servers but is retaining an encrypted offline copy for potential law‑enforcement investigations.

Theft, sale claims, and early phishing reports

A threat actor now claims to be selling the stolen SafePal customer data on a cybercrime forum. As reported by DarkWebInformer, the seller referenced the same order period and the approximately 39,798 customers disclosed by SafePal. The seller also offered to share order ID and shipping country information from stolen orders; SafePal's online verification tool can be used to confirm such order details, a tactic the seller apparently cites as proof of legitimacy. BleepingComputer has not independently verified that the threat actor possesses the stolen data.

SafePal says it first received a report consistent with the incident in early May 2026 and initially treated it as an isolated case before escalating to a formal security investigation. Customers reported SafePal‑branded phishing emails and phone calls as early as May; one customer posted on X that they received a phishing email and a phone call from someone claiming to be a company employee. The phishing email alleged a security vulnerability in the SafePal X1 hardware wallet and urged a firmware update.

Company response: notifications, verification tool, and takedowns

SafePal notified all impacted customers via email on August 16 with the subject line "[Important] Your SafePal Order Information Has Been Affected." The company also launched an online verification tool that allows customers to enter their order number and shipping country to determine whether that order’s details were stolen. SafePal says it has taken down more than 30 fraudulent websites and phishing links tied to the incident.

The advisory reiterates that customers whose order information was exposed do not need to replace their hardware wallets or move cryptocurrency because of the breach. However, SafePal warned that if a customer already shared their seed phrases or private key in response to a phishing email or text, they should treat the wallet as compromised and transfer any assets to a new wallet on a trusted SafePal device or official application.

What this means for technologists and customers, and for logistics partners

  • Technologists and security teams: the incident centers on authorization logic in an e‑commerce plug‑in and a separate data‑cleanup configuration error. These are the two concrete failure modes SafePal reported; teams should validate authorization checks in order‑tracking features and verify scheduled cleanup processes for data retention.
  • Affected customers: SafePal has provided a verification tool and direct email notifications; customers should monitor communications for targeted phishing and phone‑based social engineering about firmware upgrades, product returns, refunds, or legal investigations, all of which the company specifically warned about.
  • Third‑party logistics partners and takedown responders: SafePal cited "multiple interconnected components and external integrations, as well as third‑party logistics partners," and has already removed more than 30 fraudulent sites and links. Partners involved in order fulfillment or site hosting will be part of the remediation and takedown work the company described.

SafePal’s account ties the breach to an exploitable authorization flaw plus a data‑retention misconfiguration, and the company reports steps taken: a fix, a third‑party validation, customer notifications, a verification tool, data purges from active servers, and takedowns of fraudulent sites. The claimed sale of the same dataset on a cybercrime forum intensifies the immediate phishing risk for nearly 40,000 customers; SafePal is retaining an encrypted offline copy of the records for potential law‑enforcement investigations as it continues its review.

Source: BleepingComputer — SafePal data breach impacts 39,798 customers, stolen info for sale