
Popular hardware wallet manufacturer SafePal has confirmed a significant data breach affecting nearly 40,000 customers following an authorization flaw in its e-commerce order-tracking infrastructure. While all digital assets, seed phrases, and private keys remain secure, the exposed physical and contact details present serious phishing and physical security risks for impacted crypto holders.
On August 16, 2026, SafePal officially disclosed a security incident stemming from its e-commerce platform.The vulnerability was located within an order-tracking plugin integrated into SafePal’s online web shop, rather than within the underlying hardware or software wallet architecture.
An authorization flaw in the plugin allowed unauthorized third parties to query order status details, ultimately enabling attackers to extract customer information associated with hardware wallet purchases made between March 2, 2025, and April 11, 2026.
The scope of the breach was enlarged by a secondary operational oversight. According to SafePal’s technical investigation, a database configuration error failed to execute scheduled automated data cleanups between September 2025 and April 2026. As a consequence, legacy order records that were slated for deletion remained stored on the web server, extending the exposed dataset back to early 2025 and increasing the total number of impacted records to nearly 40,000.
Understanding the distinction between e-commerce data and wallet security is essential for affected users.
| Data Category | Status | Details |
| Personal Identity | EXPOSED | Customer full names, email addresses, phone numbers |
| Physical Location | EXPOSED | Delivery and shipping addresses |
| Purchase Records | EXPOSED | Device models purchased, quantities, order dates |
| Private Keys & Seed Phrases | SAFE | Never stored on e-commerce servers; completely isolated |
| Wallet Passwords & Credentials | SAFE | On-device security remain untouched |
| Financial / Payment Info | SAFE | Credit card details and banking data were not compromised |
| On-Chain Cryptocurrencies | SAFE | Cold storage funds and wallet balances remain intact |
Although user funds remain safe on-chain, cybersecurity analysts warn that e-commerce breaches involving crypto hardware wallets carry unique real-world dangers.
Armed with names, order history, phone numbers, and email addresses, threat actors can craft hyper-targeted phishing campaigns.Users should expect convincing emails, text messages, or phone calls claiming to be from SafePal Customer Support. Common tactics include:
Historical breaches across the hardware wallet industry demonstrate that physical address leaks can lead to sophisticated postal scams. Attackers may mail modified or tampered “replacement” hardware wallets directly to victims’ home addresses alongside letters directing them to initialize the device with their seed phrases.Additionally, doxxing and extortion demands remain a heightened concern for high-net-worth holders.
Following discovery, SafePal implemented several containment and mitigation steps:
If you purchased a SafePal hardware wallet between March 2025 and April 2026, take these safety measures immediately:
safepal.com manually into your browser.The SafePal incident highlights a growing vulnerability across the web3 sector: while blockchain cryptography and hardware vaults remain secure, peripheral supply chain tools and e-commerce web applications continue to be targeted by cybercriminals. Crypto hardware wallet manufacturers face growing pressure to adopt minimal data-retention frameworks to ensure customer physical locations are protected alongside their digital assets.