SafePal Breach Exposes Customer Records, Not Wallet Keys

A flaw in an order-tracking plugin exposed records for nearly 40,000 customers, creating a phishing risk even though wallet credentials remained secure.

By Sofia Marin • • Blockchain

A blank black capsule protected under glass beside fractured transparent panels lit in red

Crypto hardware-wallet provider SafePal has disclosed a customer-data breach that illustrates a difficult security distinction: digital assets can remain cryptographically safe while the people who own them become more exposed. An authorisation flaw in an order-tracking plugin made purchase records accessible for approximately 39,798 customers who placed orders between March 2, 2025 and April 11, 2026, according to the company and Reuters.

The exposed information included names, email addresses, shipping addresses, telephone numbers and purchase details. SafePal said the incident did not expose seed phrases, private keys, wallet passwords, card or bank information, or government identification. On the narrow question of whether an attacker gained control of users’ wallets, the company’s answer is no. On the broader question of whether affected customers now face added risk, the answer is more complicated.

A shipping address connected to the purchase of a hardware wallet is unusually sensitive. It can identify someone as a probable crypto holder and give an attacker the ingredients for convincing, personalised fraud. An email that cites the correct product and purchase period can appear more credible than a generic phishing message. A telephone number enables text-message and voice impersonation. A physical address creates an additional safety concern for customers who bought a device specifically to hold assets outside an exchange.

SafePal attributed the exposure to an authorisation weakness in a third-party order-tracking component. It also said a scheduled data-cleanup process stopped working between September 2025 and April 2026, allowing records to remain available longer than intended. The overlap matters. The plugin flaw created the path to the data; the failed retention control increased the volume and age of information that could be reached through it. Security therefore failed at two layers: application access and data minimisation.

The company says it fixed the flaw, strengthened access controls and reduced the retention period for relevant order data to 90 days. It also reported identifying and removing more than 30 fraudulent websites and phishing links associated with the breach. That takedown work suggests attackers moved quickly to operationalise the information, even though SafePal has not reported the loss of wallet credentials through its systems.

Customers should understand the difference between technical custody and surrounding identity infrastructure. A hardware wallet protects private keys by keeping signing material away from an internet-connected device. It cannot protect the shipping database used to deliver the device, the email account used to place an order or a customer who is persuaded to reveal a recovery phrase. The likely attack path after this incident is therefore social engineering rather than a direct cryptographic compromise.

That distinction also shapes the appropriate response. Affected users do not need to move assets merely because purchase data was exposed, unless they have evidence that a seed phrase or device has separately been compromised. They should, however, treat unsolicited messages about SafePal orders, firmware updates, account verification, refunds or urgent wallet migration as hostile. SafePal and legitimate support teams should never need a recovery phrase. Unexpected physical contact or threats require local law-enforcement advice rather than engagement with the sender.

For wallet manufacturers, the incident is a reminder that privacy is part of product security. Hardware design attracts scrutiny, but ecommerce plugins, support tools and retention jobs can create an equally consequential attack surface. Companies selling self-custody devices hold a particularly revealing class of customer data. Minimising that data, isolating it from public-facing services and continuously testing authorisation boundaries should be treated as security controls, not administrative housekeeping.

The disclosure also raises questions that remain unanswered in the public account. SafePal has not detailed how the weakness was discovered, how long unauthorised parties actively accessed records, or whether all affected customers have been individually notified. The figure of 39,798 identifies the potential scope; it does not, by itself, establish how many records were downloaded or used. Those distinctions matter for assessing the ultimate harm.

Why it matters

The breach tests a central promise of self-custody: reducing dependence on intermediaries does not eliminate dependence on the services surrounding a wallet. Users may control their keys while remaining vulnerable through commerce, communications and identity data. For providers, the lesson is that a secure device cannot compensate for excessive data retention or weak access control in an adjacent plugin.

The immediate financial risk comes from targeted phishing and impersonation, not from a reported break in SafePal’s key storage. Keeping those facts separate avoids unnecessary alarm while recognising that leaked identity and address data can have long-lived consequences.

Sources