SafePal Confirms Breach Affecting Nearly 40,000 Customers—What Wallet Owners Need to Know
• August 17, 2026 7:08 am • CommentsSafePal says a flaw in an order-status plug-in exposed personal information tied to nearly 40,000 customers, creating a fresh phishing and physical-security concern for hardware-wallet owners.
The important dividing line is what the attackers did not get. SafePal says wallet credentials, seed phrases and private keys remained secure.
The breach hit customer information around the purchase, while the wallets themselves continued doing their cryptographic job.
Trending: XRP’s Strongest Network Signals Are Back. One Missing Buyer Still Controls What Happens Next
But that does not make the incident harmless.
According to Decrypt, the exposed information covered roughly 39,798 customers who placed orders between March 2, 2025, and April 11, 2026. The data included names, email addresses, shipping addresses, phone numbers and purchase details.
SafePal said bank details, payment card numbers, government identification, wallet passwords, seed phrases and private keys were not part of the exposure. The company also said it fixed the plug-in flaw and added security measures.
The report places the breach in a wider run of customer-information failures around hardware wallets. Trezor recently disclosed that a shipping-partner incident exposed information tied to about 13,700 customers, while Ledger’s much larger 2020 leak exposed details for roughly 272,000 customers and was followed by phishing and ransom threats.
SafePal, a non-custodial wallet provider that says it serves 30 million users, apologized and said its investigation is continuing. That distinction matters: the company says the security boundary around customers’ crypto held, but the personal information outside that boundary can still help criminals identify and pressure wallet owners.
SafePal Bitcoin Wallet Data Breach Stokes Fears of Physical Attackshttps://t.co/9BOT2Ez2Or
— Decrypt (@DecryptMedia) August 17, 2026
The risk now shifts from the device to the owner. A criminal who knows that a specific person bought a hardware wallet—and has that person’s contact and shipping information—has a much sharper starting point for a convincing impersonation attempt.
CryptoSlate emphasized that connection, warning that order information can be used for targeted phishing even when funds and credentials remain untouched. The practical danger is a message or call that appears unusually credible because it contains real purchase details.
The exposed combination is more useful to a scammer than a bare email list. A name, phone number, delivery address and known hardware-wallet purchase can support a carefully tailored support impersonation, fake replacement notice or urgent “security” call designed to get the victim to reveal the one thing that was not stolen: the recovery phrase.
The report also points to the physical-security concern created when home addresses are connected to crypto ownership. The exposed list identifies people who bought self-custody equipment, even though it says nothing about the value of anyone’s holdings.
That means affected customers should distrust unsolicited messages claiming to come from SafePal, especially anything asking them to “verify” a recovery phrase, connect a wallet, install software or transfer funds. No legitimate support interaction requires a seed phrase or private key.
ALERT: @SafePal discloses a data breach exposing personal data of 39,798 customers, funds and wallet credentials safe, but users warned of phishing attempts from scammers posing as SafePal staff. pic.twitter.com/wdzlwpKPyx
— CoinDesk (@CoinDesk) August 17, 2026
Customers should navigate to SafePal through a saved official address instead of links in incoming messages, enable strong unique passwords and multi-factor authentication on associated email accounts, and watch for SIM-swap attempts or unexpected password-reset notices.
There is also a broader lesson here for the hardware-wallet industry. A device can do its cryptographic job perfectly while fulfillment systems, support vendors or shopping plug-ins expose the human being behind it.
Security does not stop at the chip inside the wallet.
SafePal says the core wallet infrastructure remained secure. For the affected customers, however, the exposed information makes vigilance more personal—and more urgent.
Join the conversation!
We have no tolerance for comments containing violence, racism, profanity, vulgarity, doxing, or discourteous behavior. If a comment is spam, instead of replying to it please click the icon below and to the right of that comment. Thank you for partnering with us to maintain fruitful conversation.
