Key highlights:
- A SafePal data breach resulted in the exposure of about 40,000 users’ personal information
- The team confirmed that the hackers haven't gained access to customer wallets
- The hackers could still use the details for phishing and impersonation scams
Non-custodial crypto wallet SafePal has disclosed a security breach that exposed the personal details of nearly 40,000 customers. The SafePal breach resulted in the exposure of details such as names, addresses, and contact details of users who placed orders between March 2, 2025, and April 11, 2026.
Despite this security incident, the platform assured that the users’ crypto funds and wallets remain safe. Although seed phrases, private keys, passwords, payment details, and government-issued IDs remain untouched by the SafePal breach, the team added that the affected customer could be vulnerable to possible phishing and impersonation scams.
⚠️ALERT: SafePal discloses a data breach exposing nearly 40,000 customers' names, home addresses and phone numbers.
A flaw in the hardware wallet maker's order tracking plugin allowed unauthorized access to order details for more than a YEAR, with over 30 phishing sites tied to… pic.twitter.com/9pwzOuhXZs— Coin Bureau (@coinbureau) August 16, 2026
SafePal breach explained
Via an official blog post, SafePal disclosed a major security incident that exposed customer details. The platform noted, “We have recently identified a security incident involving unauthorized access to customer order information during a specific time frame.”
Notably, the SafePal breach was caused by an authorization flaw in a plugin used to track customer orders. In certain situations, the flow allowed a customer to view the order details of another customer by simply changing the order number. The company’s statement read,
“We are extremely sorry to inform the community that order information for customers who placed orders between March 2, 2025 and April 11, 2026. Information including name, email address, shipping address, phone number, and purchase details, was accessed externally without authorization due to the flaw. The affected data involves approximately 39,798 customers.”
However, the team hasn’t revealed when the vulnerable code was added or how many unauthorized parties might have accessed the details. Customer details like name, email addresses, phone numbers, shipping addresses, and purchase details have been exposed.
Although the hackers cannot use this information to directly access a crypto wallet, they can attempt phishing or impersonation hacks using it. Thus, users are urged to remain cautious with suspicious calls, messages, or emails. But what is reassuring is that the company has since identified and fixed the vulnerability.
Are SafePal wallets safe?
As assured by the team, the SafePal breach did not expose users’ seed phrases, private keys, wallet passwords, payment card numbers, bank account details, etc. The company also claimed that there is no evidence yet that the SafePal breach gave attackers access to users’ wallets or cryptocurrencies. The platform added,
“The incident itself did not expose seed phrases, private keys, or wallet passwords. You should not need to move your assets solely because your order information was affected. However, if you have already shared or entered your seed phrase or private key in response to a suspicious message, website, phone call, or letter, treat that wallet as compromised.”
This means that the SafePal breach is more likely to be a customer data compromise rather than a direct crypto wallet hack. However, affected users are required to remain alert as leaked personal information could still lead to other serious issues like phishing attacks.
Hardware wallet security incidents rise
Significantly, the SafePal breach comes amid rising hardware wallet security incidents. Recently, several major hardware wallet providers have faced similar issues, including personal information loss and even direct crypto fund losses.
For example, Trezor recently reported a security breach that exposed personal data of about 14,000 users. Ledger customers also faced an order-data breach with the exposure of customer data.
At the same time, the Coldcard hack resulted in the loss of more than $100 million worth of Bitcoin. The incident, as reported by CoinCodex, occurred due to a flaw in the wallet’s key generation process.