Hardware wallet maker SafePal disclosed on Sunday that an authorization flaw in its order-tracking system exposed the personal details of roughly 39,798 customers, and within hours a seller on a cybercrime forum was advertising the same records. The exposed data covers names, email addresses, phone numbers, shipping addresses and purchase details for anyone who ordered between March 2, 2025 and April 11, 2026, a window of more than 13 months. No seed phrases, private keys, wallet passwords, bank details or government ID numbers were involved, the company said. The practical risk is not a drained wallet today. It is that a stranger now knows a customer’s home address and which device is sitting on their desk.
A seed phrase is the list of words that controls a crypto wallet, and anyone holding it can move the funds without ever touching the physical device.
Key takeaways
- An authorization flaw in a SafePal order-tracking plug-in let one customer read another customer’s order record, exposing 39,798 people who bought between March 2, 2025 and April 11, 2026.
- A threat actor is offering the stolen records for sale on a cybercrime forum and is citing the same order window and customer count SafePal published.
- Customers reported scam calls and phishing emails that quoted their order details as early as May, three months before SafePal identified the root cause.
- This is the third wallet vendor customer-data exposure in seven months, after Trezor on August 13 and Ledger in January.
Published: August 17, 2026, 09:20 UTC
The flaw let one customer read another customer’s order
SafePal traced the incident to an authorization flaw in the order-tracking function of a plug-in. In practice it behaved like a parcel-tracking page that returns someone else’s receipt and delivery address when the order number in the request is changed.
A second problem compounded the first. A configuration error stopped SafePal’s data-cleanup process running correctly between September 2025 and April 2026, so order records that should have been deleted stayed on the server going back to March 2025. That is why the exposure window stretches across 13 months rather than a few weeks.
SafePal said it patched the flaw, added further security controls, brought in an outside security firm to validate the fix, purged personal data from active e-commerce servers, and cut its retention period to 90 days. It notified affected customers by email on August 16 from security@safepal.com and published a verification tool that accepts an order number and shipping country.
The stolen records are already being sold
A threat actor is now advertising the SafePal customer data on a cybercrime forum, referencing the same affected order period and the same approximate figure of 39,798 customers that SafePal published. The listing was spotted by DarkWebInformer and reported by BleepingComputer, which said it has not independently confirmed the seller holds the data.
The seller’s proof-of-life method is the uncomfortable detail. To convince buyers the records are genuine, the seller is willing to hand over order IDs and shipping countries from the stolen set, which a buyer can then run through SafePal’s own breach-checking tool. The page SafePal built to reassure customers doubles as a free authenticity check for the person selling their addresses.

Customers flagged scam calls three months before the disclosure
SafePal said it received a first report consistent with the incident in early May, treated it as an isolated case, then escalated it and began a full rebuild of its order-processing pipeline in July. Public complaints predate the Sunday disclosure. A Trustpilot review dated July 4 and a Reddit post dated July 3 both describe callers who knew the customer’s name, address, phone number, email and prior order details, then steered them toward a fraudulent site at safepal.support to claim a replacement device.
Asked about those accounts by blockchain analyst Specter, SafePal replied on X that it “carried out investigations at the time but did not discover any breaches.” The company has not said when the flaw was introduced, when records were first accessed, or how many attackers obtained the data. It says it has taken down more than 30 fraudulent sites and phishing links tied to the incident.
Three wallet vendors, seven months, same weak point
The pattern across these incidents is that the cryptography holds and the commerce stack leaks. On August 13, Trezor disclosed that a breach at fulfilment partner ShipMonk exposed full names, phone numbers and shipping addresses for 11,742 customers, with a further 1,947 losing names, cities and email addresses. In January, Ledger told some customers their names and contact details had been exposed at Global-e, a third-party commerce provider. In every case the wallets and private keys were unaffected.
SafePal’s version is worse in two respects. The flaw sat in its own e-commerce system rather than a vendor’s, and it stayed open long enough to expose more than a year of orders. SafePal told The Block that landing days after Trezor’s announcement was “an unfortunate coincidence outside of” its control.
For a business whose product is self-custody, a customer list is not ordinary marketing data. It maps names to residential addresses and to a specific device model, which is a targeting file for both phishing and physical coercion. W3BN has covered the wider run of security failures this month, including the BTCPay flaw that drained Lightning nodes and the $8 million Coinsbuy hack.
What affected customers should do
SafePal says exposed customers do not need to replace their hardware or move their crypto because of the breach itself. The exception is anyone who already handed over a seed phrase or private key to a scammer, who should treat the wallet as compromised and move assets to a new wallet on a trusted device.
Beyond that, treat any unsolicited contact about firmware updates, refunds, returns, replacement devices or legal investigations as hostile, regardless of how much the caller appears to know. Knowing the order number is worthless as a trust signal now, because that is exactly what leaked.
Frequently asked questions
Was any crypto stolen in the SafePal data breach?
SafePal said it found no evidence that the incident compromised access to wallets or funds. Seed phrases, private keys, wallet passwords, bank account information, payment card numbers and government-issued ID numbers were not exposed. The company has not confirmed whether any customer later lost funds to the phishing campaigns that followed.
How do I check if my SafePal order was exposed?
SafePal published a verification tool that accepts an order number and shipping country and returns whether that order was affected. Affected customers were also emailed on August 16 from security@safepal.com with the subject line “[Important] Your SafePal Order Information Has Been Affected.”
Which orders fall inside the exposure window?
Orders placed between March 2, 2025 and April 11, 2026. The window runs that long because a configuration error stopped SafePal’s data-deletion process working between September 2025 and April 2026, leaving older order records on servers that should have cleared them.








