SafePal has disclosed that an authorization flaw in an order-tracking plugin exposed the personal data of 39,798 hardware-wallet customers, creating a concentrated phishing and physical-security risk for people whose purchase histories can identify them as cryptocurrency holders.
The company said on Aug. 16 that the incident affected hardware-wallet orders placed between March 2, 2025, and April 11, 2026. Exposed information included customers’ names, email addresses, telephone numbers, shipping addresses and purchase details, such as the wallet model ordered.
SafePal said seed phrases, private keys, bank details, payment information and identity documents were not exposed. It also said it had found no evidence that the breach itself directly caused stolen cryptocurrency. Yet the fields involved are precisely those fraudsters can use to make a support impersonation attempt appear credible, or to identify a wallet owner’s home address.
The company has launched a self-check page that lets customers determine whether their information was involved. Its FAQ says SafePal has removed more than 30 phishing websites connected to the incident and shortened its data-retention period to 90 days.
Customer reports preceded SafePal’s July investigation
SafePal said it received its first report consistent with the incident in early May, but initially regarded it as an isolated case. The company said it began a full investigation in July and later confirmed the plugin authorization issue as the root cause.
That timeline has drawn attention because several customers had already described unusually detailed scam calls in May. In one account, a customer using the name Yedior said a caller claiming to be SafePal support knew his address, order time and wallet model. The customer said SafePal support responded at the time that it did not store, or could not access, that information.
Another customer, 0xRiim, reported receiving a May call from someone who knew his name, phone number, email address and street address down to the house number. He later said he had moved home, while the explanation offered at the time pointed to a potential disclosure somewhere in the delivery process.
A customer identified as m also posted a May 19 email from SafePal customer service saying logistics information was automatically anonymized and deleted after six months. SafePal’s later FAQ offered a different explanation for the extended exposure period: a configuration error caused a data-cleanup process to fail from September 2025 through April 2026, leaving older order records accessible in the system.
The failure extended the affected order window back to March 2025, rather than limiting it to recent purchases. Some users also said they submitted shipping information through a promotional offer for a free device, did not receive a package and were later told their data was among the records exposed.
Criminal listing adds pressure to phishing threat
On Aug. 17, the security monitoring account Dark Web Informer reported that a seller on a cybercrime forum was offering a dataset with fields corresponding to the information SafePal disclosed. The post described the data as being for sale.
SafePal customers had already flagged a spoofed website, safepal.support, in complaints posted on Trustpilot and Reddit by July. On X, on-chain analyst Specter questioned SafePal about the reports, and the company said it had investigated at that point without finding an intrusion.
A user claiming to be a victim said a caller posing as SafePal support directed them to scan a code, after which cryptocurrency was transferred from their wallet. The user said an address freeze prevented the assets from being cleared through KuCoin. The account has not established whether that loss was linked to SafePal’s disclosed incident.
A phone number and accurate order history can give a scammer an advantage that mass phishing emails lack. A caller who knows the wallet brand, purchase date and delivery address can present a fake security alert as a response to a customer’s real activity. The requested action may involve scanning a malicious QR code, entering a seed phrase into a fraudulent website or approving a transaction that gives an attacker control over tokens.
Hardware wallets are designed to keep private keys offline, but they do not protect the personal data collected during the purchase and delivery process. That separation is now central to the risk facing affected SafePal buyers: the device’s cryptographic protections may remain intact while ownership information becomes useful to criminals.
Address data raises physical-security concerns
The SafePal incident arrives amid increased attention on attacks that use public or leaked information to target cryptocurrency holders outside digital channels. Chainalysis reported more than 30 so-called wrench attacks in France during the first half of 2026, involving more than $30 million. These attacks involve threats, coercion or violence intended to force a victim to transfer cryptocurrency or reveal access credentials.
Chainalysis said the annual total could surpass France’s 2025 record of $58 million in such thefts. The figures do not establish that hardware-wallet customer databases are driving the increase, but addresses paired with evidence of a cryptocurrency-related purchase can narrow the pool of potential targets.
France has also seen personal information exposed through non-crypto incidents. A breach involving a French tax system affected nearly 678,000 people, exposing names, addresses and tax information. In Somme, a couple who did not own cryptocurrency reported three break-ins within a month after purchasing the former home of a cryptocurrency figure. They said they intended to sell the property.
The pattern makes delivery data more sensitive than a conventional retail record. A household address linked to a hardware-wallet purchase may be stale, and it does not prove that a person holds significant assets, but criminals do not need certainty for a targeted scam campaign to be worthwhile.
Buyers face a practical privacy problem
SafePal’s disclosure follows recent problems elsewhere in the hardware-wallet supply chain. A reported disclosure involving a Trezor logistics partner in mid-August affected nearly 14,000 customers. These episodes place attention on the vendors, fulfilment services and order-management tools that sit outside the secure element or recovery-phrase architecture of a wallet device.
Affected SafePal customers can check their status through the company’s dedicated page and should assume unsolicited calls, text messages and emails that reference their order may be fraudulent. Legitimate support representatives should not ask a user to disclose a recovery phrase, scan an unverified QR code, install remote-access software or transfer funds to a “safe” address.
Customers ordering hardware devices may also consider limiting the personal information attached to future deliveries where local rules and practical access permit, including using a post-office box or another controlled delivery option. Changing an email address or telephone number can be disruptive, but people who received convincing impersonation attempts may want to assess whether existing contact details have become a persistent fraud target.
SafePal’s reduced 90-day retention period would limit how long future order data remains in its systems. For the nearly 40,000 customers whose records were already exposed, the immediate threat is likely to come from impersonators using information that cannot be changed as easily as a password: a name, a past address and a documented connection to a hardware wallet.
Worried about breaches like SafePal’s? Strengthen your defenses with these essential crypto safety standards every trader should know today.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
