TechNewsReel
Live

SafePal Data Breach Exposes Personal Info of Nearly 40,000 Customers

An authorization flaw in an order-tracking plug-in leaked shipping and contact data, though core wallet security remains intact.

TechNewsReel Newsroom · August 17, 2026

SafePal has disclosed a security breach that exposed the personal information of 39,798 customers. The incident stems from a vulnerability in the company's order-tracking infrastructure rather than its blockchain security protocols.

The breach was caused by an authorization flaw within an order-tracking plug-in, which allowed unauthorized users to view the order details of other customers under specific conditions. According to company disclosures and reports from SQ Magazine and Gizmodo, the exposed data includes customer names, email addresses, phone numbers, shipping addresses, and detailed purchase records. The affected group consists of users who placed orders between March 2, 2025, and April 11, 2026.

Infrastructure vs. Wallet Security

To clarify the scope of the leak, SafePal noted that the breach occurred exclusively within its e-commerce and order-processing layer. This logistics infrastructure is logically separate from the wallet firmware and the systems used for private key storage. Consequently, the company stated there is no evidence that the incident compromised access to SafePal wallets or user funds, and all private keys and seed phrases remained intact.

The Risk of Spear-Phishing

While the breach did not result in the direct theft of cryptocurrency, the nature of the stolen data creates a significant secondary risk. By possessing specific purchase histories and contact details, malicious actors can launch highly targeted "spear-phishing" campaigns. Attackers may use known order dates and product specifics to craft convincing fraudulent communications, such as fake refund offers or urgent firmware update alerts. These tailored lures are designed to trick users into revealing their seed phrases, which would then grant attackers full control over their assets.

Next Steps for Users

SafePal published a security advisory regarding the event on August 17, 2026, following customer notifications on August 16. Users who purchased devices during the affected window should remain vigilant against unsolicited communications. Security experts recommend that hardware wallet users never share their seed phrases with any entity, regardless of how authentic a request for a "refund" or "update" may appear. The company continues to monitor for further exploitation of the leaked data.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.