SafePal has disclosed that an authorization flaw in a plugin supporting its order-tracking system exposed the personal and purchase records of about 39,798 customers, creating a substantial phishing risk for hardware wallet buyers even though the company said wallet credentials and payment information were not affected.
The issue allowed unauthorized parties, under certain conditions, to view other customers’ order records. SafePal said the affected records covered some orders placed between March 2, 2025 and April 11, 2026.
Exposed information included customers’ names, email addresses, phone numbers, shipping addresses and purchase details, according to SafePal. The company said the dataset did not contain seed phrases, private keys, wallet passwords, bank card numbers, bank-account information or identity documents.
SafePal said it has found no evidence that the incident directly caused wallet takeovers or theft of digital assets. Access occurred through the company’s order-processing infrastructure rather than the security design used to store customers’ wallet keys.
Retained order data expanded the exposure
The incident was worsened by a separate failure in SafePal’s data-retention process. The company said it had previously outlined a policy, first described in 2020, under which delivered-order information would remain in online systems for six months before deletion.
During its investigation, SafePal found that an automated process intended to remove historical order records had stopped running between September 2025 and April 2026 because of a configuration error. That meant more completed-order data remained available in the affected system when the authorization weakness was exploited.
SafePal has since reduced the retention period for personal information held in its order system to 90 days. It also said it will appoint an independent third-party security firm to audit its order-handling infrastructure.
The retention failure places attention on a less visible part of hardware-wallet security: customer data often passes through ecommerce, fulfilment and support systems that sit outside the device’s key-storage protections. A hardware wallet can protect a user’s private keys while its seller still holds information that identifies the buyer and where the product was delivered.
Reports grew from a suspected isolated case
SafePal said it received an initial report from a user in early May that matched the characteristics of the later-identified incident. The company initially treated that report as an isolated case.
After additional reports emerged, SafePal expanded its inquiry and began a wider review of order-processing flows in July. The review eventually connected the activity to the order-tracking plugin’s authorization defect.
The company said it has identified and removed more than 30 phishing websites and malicious links associated with related scam activity, though it did not publish the domains. Such campaigns can use accurate names, purchase histories and delivery addresses to make fraudulent emails or messages appear more credible than broad, untargeted scams.
Customers whose information was exposed may face impersonation attempts claiming to come from SafePal, delivery companies or wallet-support teams. Messages could reference an order, shipping issue, firmware update or replacement device in an effort to persuade recipients to reveal a recovery phrase or install malicious software.
SafePal’s disclosure does not indicate that customers need to replace wallets or generate new recovery phrases solely because their order data was exposed. Customers should instead treat unsolicited contacts about their device with heightened caution and verify support requests through SafePal’s official channels rather than links or phone numbers supplied in an incoming message.
Trezor disclosed a separate logistics breach
The SafePal disclosure came three days after hardware-wallet maker Trezor reported a separate customer-data leak involving a third-party logistics provider.
Trezor said on Aug. 13 that names, email addresses, phone numbers and full shipping addresses belonging to 11,742 customers were exposed. Another 1,947 customers had partial information disclosed, according to the company.
The two incidents stemmed from different systems. SafePal traced its case to authorization controls in an order-tracking function, while Trezor linked its exposure to a logistics provider. Both cases involved customer identity and contact details rather than the cryptographic credentials needed to control wallet funds.
That distinction limits the immediate technical damage, but it does not eliminate the security consequences. A leaked shipping address and proof that someone purchased a self-custody device can help scammers narrow their targets. Unlike a compromised password, a home address or phone number cannot be easily changed, and a real purchase record gives an impersonator details that can make a fraudulent message feel routine.
Practical risks center on targeted impersonation
The most likely follow-on threat is tailored phishing. Attackers may send emails, texts or calls that cite a recent order and ask customers to “verify” delivery information, install an urgent update or move assets to a supposed secure wallet. No legitimate wallet manufacturer should ask a customer to disclose a seed phrase, which can be used to restore and drain a wallet.
Customers should independently check the sender address of messages claiming to come from SafePal, avoid clicking embedded update or support links, and access wallet software only through verified official websites or established applications. Any unexpected replacement-device offer or request to connect a wallet to a new website warrants particular scrutiny.
SafePal’s decision to cut personal-data retention to 90 days would reduce the volume of historical order information exposed in a similar future failure. The planned external audit will be more consequential if it tests whether customers can access only their own records across order tracking, support and fulfilment systems, rather than focusing narrowly on the plugin involved in this incident.
Worried about leaks leading to scams? Learn essential crypto safety steps in 5 ways to improve crypto safety today.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
