SafePal Discloses Data Breach Affecting 40,000 Customers; Personal Details Exposed, Crypto Wallets Safe

Precise count of affected customers identified as 39,798, with SafePal notifying them on August 16 and providing an order lookup page by order ID and shipping country; the firm has also shut down more than 30 fraudulent websites linked to the incident.
Data exposed extended beyond names, addresses and emails to include phone numbers.
Investigations through May to August 2026 found no seed phrases or private keys exposed and confirmed SafePal S1 remains fully air-gapped; there is no evidence that wallet access or funds were compromised.
SafePal uses no KYC or account registration for its wallet services, and states it does not retain payment information or personal data indefinitely, implementing a 12-month data deletion policy.
Crypto wallet provider SafePal has disclosed a data breach affecting exactly 39,798 customers, exposing names, addresses, phone numbers, emails, and shipping and purchase details. The company notified affected users on August 16 and set up a lookup page where customers can check if their order was involved, according to crypto.news.
The good news: no seed phrases or private keys were exposed. SafePal says no wallets were accessed and no funds were lost. But the breach still raises real risks — criminals can use stolen names and addresses to run phishing scams and impersonation attacks.
The breach stemmed from an authorization flaw in an order-tracking plugin. The bug could allow one customer to view another customer's order data. SafePal says the vulnerable window ran from March 2, 2025, to April 11, 2026 — roughly 13 months of orders, according to U.Today.
Chain analyst Specter publicly criticized SafePal for taking too long to tell users about the problem. Specter argued the vulnerability existed no later than April 2025, meaning customers went over a year without knowing their data may have been exposed, as reported by KuCoin.
Investigators reviewed the situation from May through August 2026 and found no evidence that seed phrases or private keys were taken. SafePal confirmed its S1 hardware wallet remains fully air-gapped — meaning it never connects to the internet, so hackers cannot reach it remotely, according to Hokanews.
SafePal also says it does not require account registration or identity verification to use its wallet services. The company does not keep payment information long-term. It runs a 12-month data deletion policy, so older customer records are regularly wiped, according to cryptonews.net.
After discovering the breach, SafePal moved to limit the fallout. The company shut down more than 30 fraudulent websites that bad actors had set up to target affected customers. Those sites likely used the stolen data to trick users into handing over wallet access, according to crypto.news.
Affected customers are still at risk of phishing emails and impersonation calls. Anyone who bought a SafePal product should be suspicious of unexpected messages asking for wallet details. SafePal says it will never ask for a seed phrase.
This incident is not the first of its kind. In 2020, hardware wallet rival Ledger suffered a major data breach that exposed over 270,000 customer shipping addresses. That data was later dumped online and used for targeted scam campaigns against crypto users, according to U.Today.
SafePal's breach is smaller, but the pattern is the same: physical product sales create a paper trail that software-only wallets avoid. As long as crypto companies ship hardware, customer shipping data remains a target. The industry has yet to find a clean solution to this problem.
Publishers
10
Articles
13
Reach
23