Loading market data...

SafePal Breach Exposes Personal Data of 40,000 Customers

SafePal Breach Exposes Personal Data of 40,000 Customers

SafePal, a hardware wallet maker, disclosed a security breach that exposed the personal information of about 40,000 customers. The company says an authorization flaw in its order-tracking system allowed the data to be taken. Private keys, recovery phrases, wallet passwords and payment card numbers were not exposed.

What data was taken

Names, email addresses, shipping addresses, phone numbers and purchase details were part of the leak. The breach hit the order-tracking system, not the wallet software itself. That's why the most sensitive material — seed phrases, private keys, wallet passwords — stayed out of reach.

SafePal also flagged a separate configuration error that stopped a scheduled cleanup process from running between September 2025 and April 2026. That left older order records in the system longer than intended, extending the affected dataset back to March 2025. The company's own 2020 support statement promised that delivered order info would be destroyed after 30 days. That didn't happen.

A rough stretch for hardware wallets

SafePal is not the only hardware wallet maker dealing with a breach this year. Trezor exposed about 14,000 customers through a shipping provider breach. Coldcard users lost more than $100 million in Bitcoin due to a key-generation flaw, with the theft happening in multiple waves. Ledger customers also had order data exposed via a breach at Global-e.

SafePal says it has taken down more than 30 fraudulent websites and phishing links targeting its customers. That's a start, but the data is already out there. Hardware wallets are supposed to be the most secure way to store crypto, but the past year has shown that the surrounding infrastructure can still leak.

The physical risk

Security experts warn that stolen personal data increases phishing, social-engineering and physical-security risks. Changpeng Zhao has highlighted these dangers. The numbers back that up. Chainalysis reported that wrench attacks — kidnappings and home invasions — caused about $30 million in thefts in the first half of 2026. The 2025 total was a record $58 million. Home invasions accounted for 37% of violent crypto attacks in 2026, and kidnappings made up more than half.

For SafePal customers, the immediate worry is phishing emails or calls that reference their real name and address. The company hasn't said whether it will offer any additional protection or how it plans to handle affected users beyond the takedowns. Those details are still unclear, and that's likely the next thing to watch.