SafePal says an authorization flaw in its order-tracking system exposed personal data connected to roughly 39,798 customers, creating a phishing risk for hardware wallet owners whose names, addresses and purchase histories may now be available to criminals.
The company said the affected records relate to orders placed from March 2, 2025, through April 11, 2026. Exposed information includes customer names, email addresses, phone numbers, shipping addresses and purchase details, according to SafePal’s incident report and a Sunday statement on X.
SafePal said the breach did not expose seed phrases, private keys, wallet passwords, bank-account information, payment-card numbers or government-issued identification numbers. It also said it had found no evidence of unauthorized access to customer wallets or funds.
The disclosure places the immediate danger away from the devices’ cryptographic protections and into social engineering. Armed with a customer’s exact order and delivery information, scammers can produce far more credible messages claiming that a wallet needs an urgent firmware update, replacement, refund or security check.
Attackers can tailor impersonation attempts
SafePal warned customers to be alert for contacts impersonating its employees, particularly messages that seek wallet credentials or direct users to external websites. Hardware wallet manufacturers do not need a customer’s recovery phrase to process a replacement, update device software or provide account support.
A seed phrase, also called a recovery phrase, can restore a wallet on another device. Anyone who obtains it can generally control the associated assets, making it the central target in many hardware-wallet phishing campaigns.
SafePal said attackers may use the exposed purchase data to claim knowledge of a specific order or device model. Such details can make fraudulent outreach look less like a mass scam and more like a genuine support case, especially when messages arrive by phone, email or text shortly after a device delivery.
The company said it had identified and removed more than 30 fraudulent websites and phishing links associated with the campaign. It asked customers who believe they have lost assets to submit information through its support channels, adding that it was contacting asset-tracing specialists. SafePal did not say that it had confirmed any customer fund losses.
Review began after early reports
In a question-and-answer page about the incident, SafePal said it received the first report consistent with the breach in early May. The firm initially treated that report as an isolated event, then escalated its response as more concerns emerged.
SafePal said it began a full review and rebuild of its order-processing pipeline in July, eventually identifying the authorization issue as the root cause. The company did not disclose when the flaw was introduced, when unauthorized access first began or ended, or how many people accessed the records.
Public posts from early July had already described scam attempts using what appeared to be detailed SafePal customer information. A July 4 Trustpilot review by a user identified as “Jay Teng” said scammers contacted the customer with account information and directed them to a website at safepal.support for a replacement device.
A Reddit post dated July 3 described a similar approach from someone claiming to know the user’s name, address, telephone number, email address and order details. That person was also directed to the safepal.support website. Blockchain analyst Specter later highlighted the posts on X.
SafePal said it investigated reports at the time but did not identify a breach during those earlier inquiries. The company has not independently linked the individual online posts to the incident in its public statements.
Commerce systems have become a recurring weak point
The episode follows several data-security incidents involving the sales, shipping and customer-service systems around hardware wallets rather than the wallets’ signing systems themselves.
Trezor disclosed a breach at a shipping partner that affected nearly 14,000 customers. According to Trezor, the exposed data included names, phone numbers and full shipping addresses for 11,742 customers, while another 1,947 customers had names, cities and email addresses exposed.
Ledger also notified some customers in January that names and contact information had been exposed at Global-e, a third-party commerce provider that handled certain Ledger website purchases. Ledger said wallet assets and private keys were not affected.
These cases show why order-management and fulfillment data can carry unusually high stakes for hardware wallet providers. A database containing a name and email address creates opportunities for conventional spam. A record showing that a person bought a particular wallet model and received it at a specific address gives an impersonator material for a personalized support script.
Customers who receive an unexpected message about a SafePal order, replacement device, refund or firmware update should avoid links and attachments in that message. Entering SafePal’s official web address directly into a browser, then opening a support request from there, removes the attacker’s preferred route into a phishing page.
Users should also treat requests for a recovery phrase, private key or wallet password as fraudulent, regardless of whether the message includes accurate order details. SafePal’s disclosure indicates the information most useful to attackers is customer identity and purchasing data, not the cryptographic credentials required to access a wallet.
Learn how to spot phishing and secure your wallets in 2025—read our guide on crypto wallet mistakes to avoid.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
