SafePal breach exposes 39,798 customers, funds remain secure

Share

On August 16, 2026, SafePal confirmed a data breach affecting 39,798 customers, triggered by an authorization flaw in an order tracking plugin. While private keys and funds remain untouched, the exposure of personal data opens the door to targeted phishing campaigns and identity theft attempts.

🔑 Key takeaways

  • 39,798 SafePal customers affected between March 2, 2025 and April 11, 2026
  • Exposed data: names, addresses, emails, phone numbers, purchase details
  • No private keys, seed phrases, or crypto funds compromised
  • 30+ phishing sites identified and taken down
  • Data retention reduced to 90 days; external audit launched

Timeline and nature of the flaw

SafePal, a provider of hardware cryptocurrency wallets, disclosed the breach on August 16, 2026. The incident covers all orders placed between March 2, 2025 and April 11, 2026, spanning just over thirteen months of activity. In total, 39,798 customers are affected, including buyers of the S1 and S1 Pro wallets, the brand’s flagship products.

According to the company, the flaw stemmed from an authorization defect in an order tracking plugin integrated into the online store. In practice, an attacker could simply modify an order identifier in the URL to access another customer’s shipping and purchase information. The mechanism resembles classic IDOR vulnerabilities (Insecure Direct Object Reference), among the most common issues in e-commerce.

« We identified an authorization flaw in a plugin used to track customer orders. »

SafePal, official statement

What was exposed — and what wasn’t

SafePal provided a precise breakdown of the data categories affected, while reassuring users about their digital assets. The table below summarizes the situation:

DataStatus
Full namesExposed
Physical addressesExposed
Email addressesExposed
Phone numbersExposed
Purchase detailsExposed
Private keys / seed phrasesNot exposed
Crypto fundsNot exposed
Bank detailsNot exposed
Payment card numbersNot exposed
Government-issued IDsNot exposed

The company stresses that the core security of its wallets remains intact. Assets have always been stored offline and self-custodied by users, a fundamental principle of the hardware wallet philosophy.

Concrete risks: targeted phishing and identity theft

While crypto holdings are not directly at risk, the exposed personal data is prime material for cybercriminals. The main risks identified by several specialized firms include:

  • Targeted phishing: attackers can cross-reference names, emails, and purchase history to send fake messages impersonating SafePal, an exchange, or a wallet firmware update service.
  • Identity theft (SIM swap): with a phone number and personal data, a malicious party can attempt a line transfer to intercept two-factor authentication (2FA) text messages.
  • Physical scams: the combination of a mailing address and a wallet purchase is a clue for targeted attempts, known as « $5 wrench attacks » (in-person extortion).
  • Fake technical support: direct phone contact pretending to be SafePal support, asking for the seed phrase.

« We do not store any personal information, including information related to purchase orders. All order information is deleted after 90 days. »

SafePal, post-incident policy

SafePal’s response: patch and hardening

Upon discovering the vulnerability, SafePal launched several corrective actions: patching the flaw, individual notifications by email from security@safepal.com, and hiring an independent security firm to audit the patch and review the entire order processing system.

The company also identified and removed over 30 fraudulent websites and phishing links linked to the breach. Going forward, SafePal has decided to reduce order data retention to 90 days from the date of collection, in line with its privacy policy. A verification tool is available on the official site, allowing each customer to check their order number and shipping country.

SafePal reiterated its core recommendation: anyone who has shared their seed phrase (the sequence of words allowing wallet recovery) or private key via email, phone, or letter must treat their wallet as compromised and immediately transfer their assets to a new wallet generated offline.

A new reminder after the Coldcard hack

This incident comes just weeks after the hacking of Coldcard hardware wallets, during which an attacker allegedly stole at least $120 million in bitcoin. While the two events are unrelated, they point to the same lesson: no storage solution is entirely risk-free, whether the weak link is software, human, or hardware.

Experts now recommend assessing concentration risks:
– diversify holdings across multiple wallets,
– never centralize all assets on a single device,
– and above all, never disclose your seed phrase, regardless of the context.

On the markets, no significant reaction was recorded. The native token SAFE showed no notable movement in the wake of the announcement, suggesting the community views the incident as an e-commerce operational risk rather than a flaw in the cryptographic layer.


Conclusion

The SafePal breach did not put user funds at risk, but it highlights the vulnerability of the crypto sector’s e-commerce infrastructure. As phishing attacks become increasingly personalized, personal data protection is becoming a pillar of crypto security in its own right. The coming months will show whether the corrective measures — 90-day retention, external audit, takedown of fraudulent sites — are enough to fully restore customer trust.

For users, the priority remains unchanged: never disclose your seed phrase, always verify the sender’s email address, and compartmentalize holdings across multiple independent wallets.

Sources

This article is published for informational and educational purposes only. It does not constitute investment advice in any form. Do your own research (DYOR) before making any decision.

Telemac
Telemachttp://cryptoinfo.ch
Passionné de nouvelles technologies, j’explore l’univers de la blockchain et des cryptomonnaies pour partager l’actualité et les innovations du secteur.

Lire la Suite

Articles