Cybersecurity

SafePal Security Flaw Exposes Personal Data of Nearly 40,000 Customers

By Parviz Nasirov
SafePal Data Breach Exposes Nearly 40,000 Customers

SafePal disclosed a security flaw in its order-tracking infrastructure that exposed personal and shipping information belonging to nearly 40,000 customers. The company says seed phrases, private keys, wallet passwords, payment card data, and cryptocurrency assets were not compromised. The main risk now is targeted phishing and social engineering using the leaked customer information.

SafePal Security Flaw Exposes Personal Data of Nearly 40,000 Customers

Hardware wallet manufacturer SafePal has disclosed a security incident that exposed personal and order-related information belonging to nearly 40,000 customers. The company says cryptocurrency wallets, private keys, seed phrases, and payment card information were not compromised.

According to SafePal, the incident was linked to an authorisation weakness in a third-party plug-in used as part of its order-tracking infrastructure.

Under certain conditions, the flaw could allow unauthorised access to information associated with other customers' orders.

SafePal said approximately 39,798 customers were affected.

What Information Was Exposed?

The exposed data primarily consisted of personal and shipping information submitted when customers purchased SafePal products.

Potentially affected information included:

  • Full names

  • Email addresses

  • Phone numbers

  • Shipping addresses

  • Order details

  • Product information

The affected orders were reportedly placed between March 2, 2025 and April 11, 2026.

This date range refers to the affected orders and does not necessarily represent the exact period during which the vulnerability could be exploited.

Seed Phrases and Private Keys Were Not Compromised

For hardware wallet users, the most important aspect of the incident is whether attackers gained access to cryptocurrency credentials.

SafePal says the breach did not expose:

  • Seed phrases

  • Private keys

  • Wallet passwords

  • Wallet authentication credentials

  • Bank account information

  • Payment card numbers

  • Government-issued identification numbers

The company also said it has found no evidence that attackers gained direct access to SafePal wallets or users' cryptocurrency assets through the incident.

While this significantly reduces the risk of an immediate wallet compromise, the exposed personal information can still create serious security concerns.

Phishing Is Now the Biggest Risk

The most significant threat following this type of data breach is targeted phishing and social engineering.

An attacker who knows a person's name, email address, telephone number, physical address, and the fact that they purchased a hardware wallet can create highly convincing scams.

For example, a victim could receive a fake SafePal message claiming:

“Your wallet requires an urgent security update following a recent incident.”

The attacker could then redirect the user to a fraudulent website designed to steal their seed phrase or private key.

Similar attacks could also be carried out through:

  • Email

  • SMS

  • Phone calls

  • Messaging platforms

  • Fake customer support accounts

  • Fraudulent websites

  • Physical mail or deliveries

Users should therefore treat unexpected communications claiming to originate from SafePal with increased caution.

Why Leaked Physical Addresses Are Especially Concerning

Data breaches involving cryptocurrency users present a different risk profile compared with traditional account breaches.

A database containing:

Name + physical address + contact information + evidence of hardware wallet ownership

can potentially identify individuals who may own cryptocurrency.

This information can be valuable to cybercriminals conducting targeted attacks.

The threat is not limited to online phishing. In some cases, leaked physical addresses associated with cryptocurrency ownership can also introduce personal security risks.

This highlights an important cybersecurity principle: protecting cryptocurrency users involves more than securing blockchain credentials.

Personal data can itself become a security-sensitive asset.

How Was the Incident Discovered?

SafePal said information potentially related to the incident was first reported to the company in May 2026.

The issue was initially investigated as an isolated event, but the company later expanded its investigation.

SafePal subsequently conducted a broader review of its order-processing infrastructure and identified the authorisation weakness during that process.

Information allegedly associated with SafePal customers also reportedly appeared on a cybercrime forum.

The number of records and order dates advertised in that dataset appeared to correspond with information later disclosed by SafePal.

However, the company has not publicly confirmed that the dataset advertised on the forum was definitively obtained through this vulnerability.

SafePal's Response

Following the discovery of the issue, SafePal said it implemented several security measures.

These included:

  • Fixing the authorisation vulnerability

  • Introducing additional security controls

  • Reducing the retention period for personal order information

  • Removing affected information from active systems

  • Conducting additional security reviews

  • Reviewing systems used by logistics and fulfilment partners

  • Taking action against phishing websites impersonating SafePal

  • Providing customers with a mechanism to check whether their orders were affected

SafePal also reduced the standard retention period for certain customer order information to approximately 90 days.

Reducing unnecessary data retention can limit the impact of future security incidents because information that is no longer operationally required is not continuously exposed to potential attackers.

What Should SafePal Users Do?

There is currently no indication that users need to move cryptocurrency to new wallets solely because of this data breach.

However, customers should remain highly alert for social engineering attempts.

Most importantly:

Never share a seed phrase or private key with anyone.

Legitimate wallet manufacturers and support representatives should never require users to provide their recovery phrase through email, phone calls, Telegram, WhatsApp, social media, or customer support messages.

Users should also:

  • Avoid clicking links in unexpected SafePal-related emails

  • Verify security notifications through official channels

  • Install firmware updates only from legitimate SafePal sources

  • Be suspicious of wallet verification requests

  • Ignore requests for seed phrases or private keys

  • Carefully verify refund or compensation offers

  • Watch for highly personalised phishing messages

If a seed phrase has already been entered into a suspicious website or shared with an unknown person, the associated wallet should be considered compromised.

In that situation, users should create a new wallet using a trusted device and move their assets to newly generated addresses.

NasirovPE Analysis

The SafePal incident is an important example of how cryptocurrency security extends far beyond the cryptographic security of a hardware wallet.

The wallet itself was not necessarily compromised.

Instead, the weakness existed within the surrounding e-commerce and order-management infrastructure.

From an attacker's perspective, however, compromising a private key is not always necessary.

Information such as:

Name + email + phone number + home address + evidence of hardware wallet ownership

can provide enough intelligence to launch highly targeted spear-phishing and social-engineering campaigns.

This makes customer information particularly sensitive for cryptocurrency companies.

The incident also highlights the security risks created by third-party components and integrations.

Organisations may operate highly secure core infrastructure while still being exposed through:

  • Order-management platforms

  • CRM systems

  • Analytics tools

  • Logistics integrations

  • Customer support systems

  • Third-party plug-ins

Security assessments should therefore include not only the primary application but the entire technology ecosystem surrounding it.

Another important lesson is data minimisation.

Organisations should collect only the information they actually require and retain personal information only for as long as there is a legitimate operational or regulatory need.

The less sensitive information an organisation stores, the less information an attacker can obtain if a system is eventually compromised.

For cryptocurrency companies in particular, personal data protection should be treated not only as a privacy requirement but also as an element of financial and physical security.

 

Analysis and context

The SafePal incident shows that cryptocurrency security is not limited to protecting private keys and wallet software. Personal information such as names, phone numbers, email addresses, home addresses, and evidence of hardware wallet ownership can be highly valuable to attackers.

Even without access to a wallet, cybercriminals can use this data to create convincing phishing campaigns, impersonate SafePal support, or trick users into revealing their seed phrases.

The incident also highlights the risks of third-party plug-ins and supporting systems. A company may have a secure core product while still being exposed through e-commerce platforms, logistics systems, CRM tools, or external integrations.

For cryptocurrency companies, customer data should therefore be treated as security-sensitive information. Strong authorization controls, regular third-party security reviews, data minimization, and shorter retention periods can significantly reduce the impact of similar incidents.