SafePal Data Breach: 40,000 Customers' Information Stolen – Veri Sızıntısı

SafePal Data Breach Affects Tens of Thousands of Customers

Popular cryptocurrency hardware wallet manufacturer SafePal announced that the personal and order information of 39,798 customers has been leaked. The company has warned users about phishing attacks.

A concept image of a SafePal hardware wallet resembling a locked vault.

What Happened

SafePal, a popular manufacturer of cryptocurrency hardware wallets, has confirmed a data breach affecting tens of thousands of its customers. According to a statement released by the company on August 16, 2026, cyber attackers gained unauthorized access to the order information of approximately 40,000 customers. This incident has raised concerns, especially among cryptocurrency investors who prefer to protect their assets through physical security devices. SafePal stated that it took immediate steps to contain the situation and warned its customers about potential fraud attempts.

The Compromised Data

SafePal provided a transparent overview of the breach's scope. According to the announcement, the data compromised by the attackers includes:

  • Customer Names: Basic information that reveals users' identities.
  • Email Addresses: A primary target for phishing attacks.
  • Shipping Addresses: Customers' physical location information.
  • Phone Numbers: Can be used for SMS-based scams (smishing) and fraudulent calls.
  • Purchase Details: Information such as which product a customer ordered and when.

The company emphasized that the most critical information remains secure. The statement clarified, "This incident did not involve your seed phrase, private keys, wallet password, or other wallet credentials, bank account information, payment card numbers, or government-issued identification numbers." SafePal stressed that it never requests, collects, or stores such sensitive information from its customers. This indicates that the crypto assets in users' wallets are not under direct threat. However, the leaked personal information can be used to craft highly convincing social engineering attacks targeting users.

How the Attack Occurred

According to SafePal's explanation, the data breach stemmed from a vulnerability in the order-tracking function of a plug-in used by the company. Attackers exploited this flaw under certain conditions, allowing them to access one customer's order information, and due to a system error, they were also able to access another customer's data. "We remediated the issue upon discovery and introduced additional security measures," the company explained. Further technical details of the attack were not disclosed, but the fact that the breach originated from an external plug-in once again highlights the importance of supply chain security. You can use a Data Breach Search tool to check if your information has been exposed in other breaches.

Who Is Affected

The data breach affected 39,798 customers who placed an order with SafePal between March 2, 2025, and April 11, 2026. If you purchased a hardware wallet or any other product from the company during this period, there is a high probability that your data has been compromised. SafePal did not specify whether it had directly notified the affected users, but it alerted its entire customer base through its public announcement.

What You Can Do

If you are among those affected, you need to take proactive steps to protect your personal security, even if your crypto assets are not in immediate danger. Attackers can use the information they have obtained to launch tailored phishing attacks against you.

  • Be Vigilant Against Phishing Attempts: A fraudulent email, phone call, or text message from someone who knows your name, address, and what you ordered can be very convincing. Do not trust anyone claiming to represent SafePal who asks for your wallet information, password, or seed phrase.
  • Beware of Fake Offers: Scammers may try to lure you with promises like "refund offers," "free products," or "account security upgrades."
  • Be Skeptical of Firmware Updates: You might receive messages claiming you need an "urgent firmware update" for your wallet, directing you to a fake website. Always perform updates only through SafePal's official website or application.
  • Never Share Your Seed Phrase: Remember, your 12 or 24-word seed phrase is the master key to your wallet. Anyone who has this information can access your assets. SafePal or any other legitimate entity will NEVER ask for it.

To stay informed about the latest developments in cybersecurity and other breaches, you can follow the Data Breach News page.

What the Company Says

SafePal took responsibility quickly after the incident and chose to inform its customers. The company announced that it has patched the vulnerability and implemented additional security measures. It also stated that it had already taken down over 30 fraudulent websites and phishing links associated with the incident. This proactive approach aims to prevent further damage. On the other hand, according to screenshots posted on the social media platform X (formerly Twitter), an individual has claimed to be selling the stolen data. However, these claims have not yet been verified by independent sources. SafePal has urged its customers to be cautious and report any suspicious communications to them.

Source

https://www.infosecurity-magazine.com/news/safepal-data-breach-tens-thousands/

This content was generated with AI assistance through our Argus Flow application. We are continuously working to improve Argus Flow; if you encounter any issues such as translation errors, incorrect sources, or unverified information, you can report them using the button below. We appreciate your feedback.

Weekly Newsletter

Curated data breach news delivered to your inbox every week.