SafePal reported a data leak affecting approximately forty thousand users

8/17/2026, 06:54 AMЕвгения Слив

On August 16, the manufacturer of hardware crypto wallets, SafePal, officially disclosed information about a data leak affecting approximately thirty‑nine thousand seven hundred and ninety‑eight users. Third parties gained access to names, delivery addresses, phone numbers, email addresses, and information about customers’ orders. The incident did not affect critically important information: seed phrases, private keys, passwords, banking details, card numbers, and document numbers, as the company fundamentally does not collect or store such data. The project team has not detected any signs that attackers have gained access to users’ wallets or funds.

The developers have warned that attackers may use the leaked information to carry out targeted attacks. Scammers may call, text, or send messages on behalf of the support service, offer a refund, demand that device firmware be updated, or redirect victims to phishing resources. Currently, SafePal is actively monitoring fake resources and seeking to have them blocked. The vulnerability arose due to an authorization error in the order tracking plugin, which is linked to customer data. The system incorrectly handled access to information, allowing unauthorized users to view other customers’ orders. The developers reported that by the time the statement was published, the issue had been fixed and protective measures had been significantly strengthened.

The incident affected customers who placed orders between March 2, 2025, and April 11, 2026. SafePal did not specify exactly when the attackers exploited the vulnerability or when the project team discovered it. Currently, the manufacturer of hardware crypto wallets is investigating what happened together with an independent cybersecurity company and plans to conduct a full audit of the entire order processing system. In accordance with the law, the company has reduced the data retention period in this system to ninety days and notified its logistics partners, asking them to check their own systems for similar issues. It should be recalled that on August 13, the Trezor project faced a similar situation. The hack of its logistics partner, ShipMonk, led to the leakage of personal information of nearly fourteen thousand customers.

Popular news