What happened
Cryptocurrency hardware wallet maker SafePal disclosed a data breach affecting approximately 39,798 customers, caused by an authorization flaw in a plug-in used for its order-tracking system. The flaw let an unauthorized party pull up other customers' order records, including names, email addresses, shipping addresses, phone numbers and purchase details. SafePal says wallet seed phrases, private keys, passwords, payment card numbers, bank details and government IDs were not exposed or accessible through the flaw. A separate configuration error compounded the problem: between September 2025 and April 2026, the system failed to properly clear out old order data, so information that should have been deleted stuck around longer than intended. SafePal says it first received a report about the issue in early May 2026 and found the underlying flaw in July while rebuilding its order-processing system. The company notified affected customers and disclosed the incident publicly on August 16, patched the vulnerability, purged personal data from active servers, and says it has taken down more than 30 fraudulent websites set up to exploit the breach. The stolen data is reportedly being offered for sale on cybercrime forums.
Why it matters for your business
Crypto payments and hardware wallets have moved well past hobbyist territory, and any business that accepts crypto or issues hardware wallets to staff or clients should treat a breach like this as a phishing setup, not just a privacy footnote. Attackers with a name, email, shipping address and knowledge that someone owns a specific wallet brand have everything they need to send a convincing fake support email or fraudulent replacement-device offer. The breach is also a useful reminder for any business running an online store: the flaw was in an order-tracking plug-in, the exact kind of bolted-on e-commerce component many small sites rely on without a second look.
What to do
If your business or staff use SafePal, be skeptical of any unsolicited email or call referencing a recent order, and never enter a wallet seed phrase anywhere in response to one. If you run an online store, ask your web team when order-related plug-ins were last audited for access-control flaws like this one.
