SafePal confirmed a data breach on August 16 exposing names, delivery addresses, phone numbers and order details of 39,798 customers, while seed phrases and private keys stayed safe.
SafePal said in a security notice that an authorization flaw in its order-tracking plugin let one customer view another's order information, compounded by a misconfiguration that kept old records from being deleted on schedule between September 2025 and April 2026. The company has notified affected customers by email and published a lookup tool that checks an order number against the leak.
The exposed records cover orders placed between March 2, 2025 and April 11, 2026. Not affected, SafePal said, are seed phrases, private keys, wallet passwords, bank details, card numbers and government IDs. The seed phrase is the sequence of 12 or 24 words from which every key in a wallet can be restored; anyone who knows it has full access to the balance.
The combination of a home address and the knowledge that someone there holds a hardware wallet is what makes this leak dangerous. An attacker who knows a name, address, phone number and purchase date does not need to steal the seed phrase — they can try to have it handed over through targeted phishing. BleepingComputer and Help Net Security reported that customers received phishing emails and calls about firmware updates as early as May 2026, months before the official statement, and SafePal has taken down more than 30 fake websites and phishing links tied to the breach.
Why a delivery address outlives a leaked password
A leaked password can be changed in two minutes. A home address and phone number cannot, and the fact that someone at that address holds crypto in self-custody does not go stale. Two risk paths follow: targeted phishing that cites a real purchase date and device model, and physical attacks — the industry term "wrench attack" — where an owner is pressured into handing over keys. SafePal has warned customers to treat every unexpected approach and every unexpected hardware delivery as suspicious, because a tampered device shipped with a pre-supplied recovery phrase hands control of later holdings to the sender.
Second wallet-maker leak in two weeks
The incident follows a Trezor breach on August 13 in which 13,689 customers' names, phone numbers and home addresses leaked through logistics provider ShipMonk. The technical causes differ — one lay with an external shipping partner, the other in a self-operated plugin — but both hit the ordering process, not the device or its cryptography. SafePal has said it will delete purchase records after 90 days in future, where legal requirements do not allow otherwise. Shorter retention is the most effective remedy against this kind of leak, because leaked data can only be as old as the records still held.
For EU customers, the General Data Protection Regulation applies because goods were delivered to people in the EU. Under Article 15, customers can request information about which data is stored about them; under Article 34, a controller must notify data subjects without undue delay where a breach is likely to result in high risk. The chronology — first indication in early May, notification in mid-August — is for supervisory authorities to assess.
Affected customers should check the lookup tool through www.safepal.com typed directly, follow no link from an email, and treat every incoming approach about their purchase as unverified. There is nothing to reset: since no wallet credentials were affected, replacing the device or re-setting the wallet is not required. The risk is not that funds move on their own, but that the exposed context makes a convincing fraud easier to run.
This article is for informational purposes only and does not constitute investment advice.