Security8 distinct publishers3 min readPublished Updated
No seed phrases were touched. What was taken is names, phone numbers and shipping addresses for people known to own a hardware wallet, now advertised on a crime forum.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Hardware wallet vendor SafePal says an authorization flaw in the order-tracking function of an e-commerce plug-in was exploited to steal order records for roughly 39,798 customers, and a threat actor is now advertising that data for sale on a cybercrime forum [1][14][8]. No seed phrases, private keys, passwords, card numbers or government ID numbers were exposed [3], which is the least interesting part of this incident: what did leak is names, email addresses, phone numbers, shipping addresses and purchase details for people confirmed to have bought a device for storing cryptocurrency [2].
That combination is not a privacy problem in the abstract. Strip out the credentials and what remains is a location and a phone number attached to a verified crypto holder [4]. SafePal's own advisory says the data could be used for targeted phishing and social engineering, and warns customers to expect approaches about firmware upgrades, product returns, refunds and legal investigations [7][18]. Those approaches started well before disclosure: customers reported SafePal-branded phishing emails and phone calls as early as May [7]. One customer posted on X that they received both an email and a call from someone claiming to be an employee, with the email asserting that a vulnerability had been found in the SafePal X1 and that a firmware update was needed [20]. The company says it has taken down more than 30 fraudulent sites and phishing links tied to the incident [19].
The exposure window is wide. Affected orders run from March 2, 2025 to April 11, 2026 [2], about thirteen months of customer records [1]. Part of that is a second failure: SafePal found a configuration error that stopped its data-cleanup process from working correctly between September 2025 and April 2026, roughly seven months during which records that should have aged out stayed live [16][2]. Old orders that no longer needed to exist are the ones now for sale.
The timeline is not flattering either. SafePal says it first received a report consistent with the incident in early May 2026 and treated it as an isolated case, citing an e-commerce stack with multiple interconnected components, external integrations and third-party logistics partners that made it hard to rule out other explanations [12][13]. It began a full review and rebuild of order processing in July, found the plug-in flaw, fixed it, and brought in an outside security firm to validate the fix [14][15]. Customers were emailed on August 16 [5], roughly three months after the first report landed [3].
There is a sharper problem with the remediation. SafePal published a verification tool that lets a customer enter an order number and shipping country to check whether that order was stolen [6]. The seller on the forum is offering prospective buyers order IDs and shipping countries precisely so they can run them through that tool as proof the goods are real [9]. A victim-notification mechanism is doubling as a free authenticity oracle for the market in the stolen data [5]. BleepingComputer says it has not independently verified that the seller holds the data [11].
Watch whether SafePal narrows or removes the lookup, and whether phishing shifts from firmware-update lures to pretexts that use the shipping address directly. SafePal says exposed customers do not need to replace their hardware wallets [21]; the device is not the asset at risk here, the customer list is.
Ranked by verification strength, evidence, and original report placement.
SafePal says the breach did not expose customers' wallet seed phrases, private keys, passwords, bank account information, payment card numbers, government-issued identification numbers, or other credentials.
"No evidence has been found that the incident itself compromised access to SafePal wallets or funds," SafePal said in a security advisory published Sunday.
The company warns that the stolen information could be used to conduct targeted phishing and other social engineering attacks, with customers reporting SafePal phishing emails and phone calls as early as May.
SafePal says it first received a report consistent with the incident in early May 2026, which it initially treated as an isolated case before escalating it into a formal security investigation and introducing additional protections.
SafePal advisory: "As our e-commerce system involves multiple interconnected components and external integrations, as well as third-party logistics partners, we could not immediately rule out several possible explanations."
Cryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Specific vendor disclosure, single-outlet relay
Core facts are precise and attributable: a named vendor advisory with an exact victim count, an exact order window, an enumerated field list, a named root cause and a stated remediation path, plus a corroborating crime-forum listing spotted by a third party whose figures match the disclosure. Evidence is capped, not high, because everything comes from one publisher relaying one self-reported advisory, the publisher states it has not verified the seller's possession of the data, and no regulator, law-enforcement body, named security firm or plug-in vendor independently confirms scope or root cause.
Real exploitation already in the wild
This is a realized incident rather than a proposal: a quantified victim population of ~39,798 customers, notification emails actually sent, the data actively advertised for sale, phishing emails and voice calls reaching customers since May, and more than 30 fraudulent sites already taken down. It falls short of the top of the range because the volume of successful phishing, any resulting fund losses, and the existence of an actual buyer for the data set are all unreported.
Residual risk understated by vendor framing
Nothing here is inflated: the reporting is sober, quantified and carries its own verification caveat. Slightly negative because the loudest framing in the material is reassurance — no seed phrases, no evidence of wallet or fund compromise, no need to replace devices — while the same material shows a verified purchaser target list with home addresses and phone numbers already being sold and already being worked by voice and email impersonation. The lasting risk to named wallet owners is understated relative to the evidence of active exploitation.
Self-reported scope with reassurance motive on both sides
Every quantitative fact originates with the breached vendor, which has a direct commercial interest in bounding scope and preserving confidence in a product sold on secret-keeping — visible in the emphasis on what was not exposed and on customers not needing new devices. The counterparty is equally motivated in the other direction: a forum seller talking up the data to attract a price. The publisher is a security outlet whose article closes with a vendor-sponsored report promotion, adding a mild commercial layer, though its explicit non-verification caveat cuts against uncritical amplification.
Consistent but single-sourced
Internal consistency is high — the forum listing's period and count match the advisory, the timeline is coherent, and the publisher flags its own verification limit. Confidence is held to the low-60s because there is exactly one publisher and one primary document, no independent confirmation of scope or root cause, and no external record of the exploitation window, so a later revision of the victim count, the retention window or the attribution of the flaw would be unsurprising.
invest
A hardware wallet's real attack surface is its order database, not its air gap4 distinct publishers
invest
Order data ShipMonk promised to delete pushes Trezor's breach count to 80,7001 distinct publisher
build
A UDP packet is now enough: IKEEXT RCE moves from patch queue to fire drill1 distinct publisher
product
SafePal's breach came through an order-tracking plug-in, and that is the point3 distinct publishers
Distinct publishers with included, body-backed reporting in this cluster.
bleepingcomputer.com
1 article · August 16, 2026
helpnetsecurity.com
1 article · August 17, 2026
infosecurity-magazine.com
1 article · August 17, 2026
scworld.com
1 article · August 17, 2026
securityaffairs.com
1 article · August 17, 2026
securityweek.com
2 articles · August 18, 2026
thehackernews.com
2 articles · August 18, 2026
therecord.media
1 article · August 17, 2026