Published · 6d agoProduct3 min read
SafePal's breach came through an order-tracking plug-in, and that is the point
The wallets held. The customer list did not: 39,798 names, phone numbers and shipping addresses, taken through commerce plumbing nobody threat-models.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- SafePal said on Sunday that it had "recently" found and fixed a vulnerability in a system containing users' order information, and that it appeared someone had accessed that information without authorization.
- The exposure affected 39,798 customers, covering those who placed orders from March 2 of last year to April 11 of this year.
- SafePal says the exposed data includes name, email address, shipping address, phone number, and purchase details.
- In a post attributed to SafePal, the company said customer wallets, seed phrases and private keys are secure, that it identified a flaw in the order-tracking plug-in that led to unauthorized access to information of a subset of customers, and that the issue has been fixed with additional security measures.
- Hardware wallets such as SafePal's are air-gapped and intended as safeguards for the information needed to perform blockchain transactions, so that a compromised phone or computer does not expose the crypto.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
SafePal said on Sunday that it had recently found and fixed a vulnerability in a system containing users' order information, and that someone had already accessed that information without authorization [1]. The exposure covers 39,798 customers who placed orders between March 2 of last year and April 11 of this year, and the fields taken were name, email address, shipping address, phone number and purchase details [2][3].
The company was unusually specific about the location of the hole. In its post it said that customer wallets, seed phrases and private keys are secure, and that the flaw was in the order-tracking plug-in [4]. That is a more credible reassurance than most breach statements, because hardware wallets are air-gapped and exist precisely so that a compromised phone or laptop does not reach the keys [5]. The core product did its job. What leaked was the thing sitting next to the core product, doing logistics.
That distinction matters less than it sounds, because the value of the leaked asset is not device-level, it is list-level. A name joined to a phone number, a confirmed delivery address and a purchase record is a pre-qualified roster of people who own enough crypto to buy dedicated hardware for it, along with where the hardware was shipped. SafePal says affected customers may be targeted by more sophisticated phishing attempts [6], and the FAQ page it published for them opens with a large phishing warning carrying the hashtag #BewareOfPhishing [7]. Gizmodo also notes the physical version of the same risk, what it calls a "$5 wrench attack," in which someone turns up with a blunt object or a gun and demands the information that unlocks the holdings [8].
The pattern is not new to the category. Ledger, which also makes hardware wallets, notified users of a third-party data breach earlier this year [9].
For operators, the useful reading is procurement, not cryptography. Order tracking, shipping notifications, review widgets, support desks and marketing automation are usually bought by a different team than the one shipping the product, reviewed on a different cadence, and given read access to the exact join that makes a customer identifiable: who they are, where they live, what they bought and how much they spent. A wallet vendor can pour its entire security budget into the signing device and still hand that join to a plug-in. The core product's threat model does not cover the periphery, and the periphery is where the customer list lives.
The dates are worth holding on to. The last affected order is dated April 11, and the disclosure post is dated August 16, 2026 [2][10], a gap of roughly four months [12]. The affected order window itself runs about 13 months [11]. The source material does not say when the unauthorized access occurred or when SafePal detected it, beyond describing the discovery as recent [1].
Three things to watch. Whether SafePal names the plug-in and says whether it was vendor code or its own, which determines how many other merchants are running the same exposure. Whether the phishing wave the company is warning about actually arrives, and in what form, since the leaked fields support voice and postal approaches as well as email. And whether competitors in the category audit their commerce stack now or wait for their own incident, given that Ledger's disclosure this year already established the template [9].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
SafePal said on Sunday that it had "recently" found and fixed a vulnerability in a system containing users' order information, and that it appeared someone had accessed that information without authorization.
ReportedView cited source - [2]
The exposure affected 39,798 customers, covering those who placed orders from March 2 of last year to April 11 of this year.
ReportedView cited source - [3]
SafePal says the exposed data includes name, email address, shipping address, phone number, and purchase details.
ReportedView cited source - [4]
In a post attributed to SafePal, the company said customer wallets, seed phrases and private keys are secure, that it identified a flaw in the order-tracking plug-in that led to unauthorized access to information of a subset of customers, and that the issue has been fixed with additional security measures.
- [5]
Hardware wallets such as SafePal's are air-gapped and intended as safeguards for the information needed to perform blockchain transactions, so that a compromised phone or computer does not expose the crypto.
ReportedView cited source - [6]
SafePal notes that affected customers might be targeted by more sophisticated phishing attempts.
ReportedView cited source
Sources & coverage · 3 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- gizmodo.comMike Pearl6d agoBreach at Crypto Wallet Company Called ‘SafePal’ Exposes 39,798 Customers
- thenextweb.comAlina Maria Stan6d agoSafePal breach leaks the addresses but not the crypto, which may be the bigger problem
- techcrunch.comZack Whittaker



