SafePal Data Breach Affects 39k Customers Stolen Info for Sale
Cryptocurrency hardware wallet manufacturer SafePal has announced that the personal information of nearly 40,000 customers has been stolen and is for sale on a cybercrime forum. The breach originated from a flaw in the order-tracking system.
What Happened
SafePal, a well-known provider of hardware wallets in the cryptocurrency world, disclosed a major data breach in an announcement on August 16, 2026. The company confirmed that the order information of approximately 39,798 customers had been stolen. Making the situation more alarming, the threat actor behind the cyberattack is now claiming to be selling this data on a popular cybercrime forum. This development has created a state of alert among SafePal users regarding their personal security and potential fraud attempts.
According to the official statement from SafePal, the data leak affects customers who placed orders between March 2, 2025, and April 11, 2026. The company stated that upon discovering the breach, it immediately launched a security investigation and took steps to notify all affected customers. The fact that the attacker is referencing SafePal's own verification tool to prove the authenticity of the stolen data underscores the seriousness of the situation. This tactic is intended to provide potential buyers with assurance about the legitimacy of the data for sale.
What Data Was Compromised
SafePal shared a clear list of the customer data that was leaked as a result of the breach. This is critically important for users to understand the types of risks they now face. The stolen information includes:
- Full Names: Basic personal information that directly reveals the identity of customers.
- Email Addresses: A primary target for phishing attacks and other fraudulent schemes.
- Shipping Addresses: Sensitive data that can be used for physical security risks and more targeted social engineering attacks.
- Phone Numbers: Can be used for SMS-based phishing (smishing) and fake support calls.
- Purchase Information: Details such as which products were ordered and when, allowing attackers to establish more convincing communication with their victims.
However, the company underscored a crucial detail to allay the biggest fears of its users. The announcement emphasized that the breach did not affect the most critical information that would directly endanger customers' crypto assets. Data that was not compromised includes wallet seed phrases, private keys, passwords, bank account information, payment card numbers, and government-issued identification numbers. SafePal stated, "No evidence has been found that the incident itself compromised access to SafePal wallets or funds," assuring users that their funds are safe.
How Did the Attack Happen
According to SafePal's security advisory, the attackers exploited a vulnerability in the company's e-commerce infrastructure. Specifically, the flaw that led to the customer data leak was located in the order-tracking system. However, the technical details of how the attack was precisely executed have not yet been made public.
The company's process of discovering the incident began in May 2026. A report from a customer, which was later found to be consistent with this breach, was initially treated as an isolated case. But as similar reports increased, the situation was escalated into a formal security investigation, and additional protective measures were implemented. The company explained the reason for the delay: "As our e-commerce system involves multiple interconnected components and external integrations, as well as third-party logistics partners, we could not immediately rule out several possible explanations." This complex structure slowed down the process of identifying the root cause of the problem.
Notably, in the sales post on the cybercrime forum spotted by DarkWebInformer, the attacker referenced the same number of affected customers and the same order date range as disclosed by SafePal. The threat actor also stated they are willing to share order ID and shipping country information from the stolen orders with potential buyers to prove the data's authenticity. This information can be confirmed using the online verification tool set up by SafePal on its own website.
Who Is Affected
The group directly affected by the data breach is defined as the 39,798 customers who placed an order for a hardware wallet or accessory through SafePal's official website between March 2, 2025, and April 11, 2026. It is stated that users who placed orders outside these dates or used the company's services in other ways are not affected by this specific incident.
SafePal took a proactive step by developing an online verification tool to help customers check their status. By entering their order number and shipping country into this tool, customers can instantly find out whether their order information was stolen. The company also announced that on August 16, it sent an informational email to all affected customers with the subject line "[Important] Your SafePal Order Information Has Been Affected."
What You Can Do
If you placed an order with SafePal between the specified dates or believe you may have been affected, there are several important steps you should take:
- Use the Official Verification Tool: First, confirm whether your order information was leaked by using the verification tool published on SafePal's official website.
- Be Vigilant Against Phishing Attacks: Attackers can use the stolen name, email, address, and order details to carry out highly convincing phishing emails or phone calls. As early as May, some users reported receiving fake emails claiming a security vulnerability was found in the SafePal X1 hardware wallet and that a firmware update was required. Be extremely skeptical of any communication claiming to be from SafePal that demands urgent action (like resetting a password, updating your wallet, or entering your seed phrase). Remember, SafePal will never ask for your seed phrase or private keys.
- Verify Suspicious Communications: If you receive a suspicious email or call, do not click on any links or follow any instructions. Instead, open your browser and go directly to SafePal's official website or check their official social media channels to verify the situation.
- Beware of Phone Scams: Since your phone number was leaked, you may receive calls from individuals impersonating SafePal support staff. They might ask for your personal information or give you instructions under the guise of helping you secure your wallet. Do not trust these calls.
What the Company Says
In its published security advisory, SafePal addressed the situation transparently and apologized to its customers. The company stated that the investigation is ongoing and that they are taking additional measures to strengthen their security infrastructure. The announcement repeatedly emphasized that the security of customer funds and wallets is their top priority and that this breach does not directly impact wallet security. The company reiterated that it has contacted all affected customers via email and provided a tool for them to check their status. SafePal warned users to be cautious of potential social engineering attacks in the coming days and reminded them that all official communication will only come through their verified channels.
Source
This content was generated with AI assistance through our Argus Flow application. We are continuously working to improve Argus Flow; if you encounter any issues such as translation errors, incorrect sources, or unverified information, you can report them using the button below. We appreciate your feedback.