Skip to content
live markets
S&P 5007,698.92▲ 3.23%NASDAQ26,307.88▲ 3.09%DOW53,401.11▲ 2.41%GOLD4,408.70▲ 9.87%WTI84.05▲ 1.89%BRENT90.96▲ 3.25%EUR/USD1.1582▲ 1.20%USD/JPY159.60▼ 1.71%DXY99.64▼ 1.10%BTC$64,641▲ 0.70%ETH$1,913▲ 0.50%SOL$77.15▲ 1.80%TOTAL CRYPTO$2.29T▲ 0.49%
pulseofnations.
UTC --:--NYC --:--LON --:--WAW --:-- telegram ↗ bluesky ↗ Join the wire

SafePal Breach Exposes Data on 40,000 Wallet Customers

Hardware wallet maker SafePal says an authorization flaw and a failed data cleanup exposed names, addresses, and phone numbers of nearly 40,000 customers.

Partner Surfshark VPN

SafePal disclosed on August 16 that an authorization flaw in its order-tracking system exposed personal data of nearly 40,000 hardware wallet customers, in the latest in a string of security incidents affecting crypto wallet providers this year.

The breach allowed unauthorized access to customer records covering purchases made between March 2025 and April 2026. Exposed information includes names, email addresses, shipping addresses, phone numbers, and purchase details. SafePal said private keys, recovery phrases, wallet passwords, payment card numbers, and wallet access credentials were not exposed, and that it found no evidence the flaw was used to compromise wallets or steal cryptocurrency.

Two Failures Combined to Expand the Exposure

SafePal explained that two separate failures compounded the incident. First, an authorization weakness in the e-commerce order-tracking system permitted the unauthorized access. Second, a configuration error had prevented a scheduled cleanup process from operating correctly between September 2025 and April 2026, leaving older order records in the system far longer than intended.

That second failure expanded the pool of information available through the authorization flaw and extended the affected dataset back to March 2025. It also contradicts a SafePal support statement published in 2020, which said hardware wallet order data would be retained for only 30 days before being destroyed through a monthly cleanup cycle.

SafePal notified all affected customers by email on August 16 from security@safepal.com, and said it is commissioning an independent review of its data-handling practices. The company has not disclosed whether law enforcement has been contacted.

Part of a Broader Wave of Hardware Wallet Incidents

The SafePal breach is the latest in a series of security problems involving major hardware wallet companies and their customers. Trezor recently disclosed that a breach at its shipping provider exposed personal information belonging to nearly 14,000 customers, while Coldcard users suffered direct losses after a flaw in key-generation allowed attackers to drain Bitcoin from affected addresses. Ledger customers were also affected by an order-data breach involving third-party payment provider Global-e earlier this year.

The Coldcard incident produced the largest financial loss, with more than $100 million in Bitcoin stolen after a bug left some private keys insufficiently secure. Funds were drained across multiple attack waves beginning in late July.

Security experts have warned that the SafePal and Trezor breaches, which expose names, phone numbers, emails and delivery addresses, create elevated risks for targeted phishing, social engineering, and even physical attacks against identifiable crypto holders. Binance co-founder Changpeng Zhao highlighted these risks on social media, noting that the combination of personal information with known crypto ownership makes holders particularly attractive targets.

Sources: CryptoSlate; SafePal official blog; Reuters, all August 16-17 2026.

React to this dispatch
Share this dispatch Telegram X WhatsApp Report an error

discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Next dispatch Latvia CSDD Breach Exposes Data on 1.2 Million People Read →