Published · 6d agoSecurity3 min read
SafePal's leaked order book is a target list: 39,798 wallet buyers, with addresses
No seed phrases were touched. What was taken is names, phone numbers and shipping addresses for people known to own a hardware wallet, now advertised on a crime forum.
Not a builder's beat, but builders have a standing stake in it.See today for builders
What happened
- Cryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data.
- SafePal says the breach impacts customers who placed orders between March 2, 2025, and April 11, 2026, exposing their names, email addresses, shipping addresses, phone numbers, and purchase information.
- SafePal says the breach did not expose customers' wallet seed phrases, private keys, passwords, bank account information, payment card numbers, government-issued identification numbers, or other credentials.
- "No evidence has been found that the incident itself compromised access to SafePal wallets or funds," SafePal said in a security advisory published Sunday.
- SafePal says it notified all impacted customers via email on August 16 with the subject "[Important] Your SafePal Order Information Has Been Affected."
Compiled by The WatchSomething wrong?How this is made
Why it matters
Hardware wallet vendor SafePal says an authorization flaw in the order-tracking function of an e-commerce plug-in was exploited to steal order records for roughly 39,798 customers, and a threat actor is now advertising that data for sale on a cybercrime forum [1][14][8]. No seed phrases, private keys, passwords, card numbers or government ID numbers were exposed [3], which is the least interesting part of this incident: what did leak is names, email addresses, phone numbers, shipping addresses and purchase details for people confirmed to have bought a device for storing cryptocurrency [2].
That combination is not a privacy problem in the abstract. Strip out the credentials and what remains is a location and a phone number attached to a verified crypto holder [4]. SafePal's own advisory says the data could be used for targeted phishing and social engineering, and warns customers to expect approaches about firmware upgrades, product returns, refunds and legal investigations [7][18]. Those approaches started well before disclosure: customers reported SafePal-branded phishing emails and phone calls as early as May [7]. One customer posted on X that they received both an email and a call from someone claiming to be an employee, with the email asserting that a vulnerability had been found in the SafePal X1 and that a firmware update was needed [20]. The company says it has taken down more than 30 fraudulent sites and phishing links tied to the incident [19].
The exposure window is wide. Affected orders run from March 2, 2025 to April 11, 2026 [2], about thirteen months of customer records [1]. Part of that is a second failure: SafePal found a configuration error that stopped its data-cleanup process from working correctly between September 2025 and April 2026, roughly seven months during which records that should have aged out stayed live [16][2]. Old orders that no longer needed to exist are the ones now for sale.
The timeline is not flattering either. SafePal says it first received a report consistent with the incident in early May 2026 and treated it as an isolated case, citing an e-commerce stack with multiple interconnected components, external integrations and third-party logistics partners that made it hard to rule out other explanations [12][13]. It began a full review and rebuild of order processing in July, found the plug-in flaw, fixed it, and brought in an outside security firm to validate the fix [14][15]. Customers were emailed on August 16 [5], roughly three months after the first report landed [3].
There is a sharper problem with the remediation. SafePal published a verification tool that lets a customer enter an order number and shipping country to check whether that order was stolen [6]. The seller on the forum is offering prospective buyers order IDs and shipping countries precisely so they can run them through that tool as proof the goods are real [9]. A victim-notification mechanism is doubling as a free authenticity oracle for the market in the stolen data [5]. BleepingComputer says it has not independently verified that the seller holds the data [11].
Watch whether SafePal narrows or removes the lookup, and whether phishing shifts from firmware-update lures to pretexts that use the shipping address directly. SafePal says exposed customers do not need to replace their hardware wallets [21]; the device is not the asset at risk here, the customer list is.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Cryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data.
ReportedView cited source - [2]
SafePal says the breach impacts customers who placed orders between March 2, 2025, and April 11, 2026, exposing their names, email addresses, shipping addresses, phone numbers, and purchase information.
ReportedView cited source - [3]
SafePal says the breach did not expose customers' wallet seed phrases, private keys, passwords, bank account information, payment card numbers, government-issued identification numbers, or other credentials.
ReportedView cited source - [4]
"No evidence has been found that the incident itself compromised access to SafePal wallets or funds," SafePal said in a security advisory published Sunday.
ReportedView cited source - [5]
SafePal says it notified all impacted customers via email on August 16 with the subject "[Important] Your SafePal Order Information Has Been Affected."
ReportedView cited source - [6]
SafePal launched an online verification tool that lets customers enter their order number and shipping country to determine whether the details of that order were stolen.
ReportedView cited source
Sources & coverage · 8 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- bleepingcomputer.comLawrence Abrams6d agoSafePal data breach impacts 39,798 customers, stolen info for sale
- infosecurity-magazine.com6d agoSafePal Data Breach Hits Tens of Thousands of Customers
- securityweek.comIonut Arghire6d ago40,000 Impacted by SafePal Data Breach



