Breach analysis · 7 min read

SafePal Breach: What Leaked and What to Do

A flaw in SafePal's order-tracking plug-in exposed 39,798 buyers' names, emails, addresses and phone numbers. What it means and what to do now.

YeyMail Team ·

On Sunday 16 August 2026, SafePal, which sells hardware cryptocurrency wallets, told customers that a flaw in an order-tracking plug-in had let someone pull the order details of approximately 39,798 customers. The exposed records cover anyone who bought from SafePal between 2 March 2025 and 11 April 2026, and they contain names, email addresses, shipping addresses, phone numbers and purchase details.

The wallets themselves are not affected. SafePal has been explicit on this point, and the distinction matters. Nobody's seed phrase, private key or wallet password was in the exposed data. What was exposed is the shopping record: who bought a device that holds cryptocurrency, where it was sent, and how to reach them.

That is a narrower breach than most of the ones we look at, though larger than Trezor's a few days ago. It is also, for the people in it, one of the more dangerous kinds, because the data does not need to be cracked or combined with anything else to be useful. It is a ready-made target list. Here is what SafePal and the security press have said, and what to do if you are on it.

What happened, and when

SafePal's advisory, published on 16 August, describes the cause as an authorization flaw in the order-tracking function of a plug-in associated with customer order information. It does not name the plug-in or say who built it, and we will not guess. In plain terms, the flaw let a request for one customer's order return another customer's, and someone used that to walk through the order book. BleepingComputer's report on the same day says the flaw allowed access to another customer's order information, which is consistent.

The timeline is longer than the disclosure date suggests. According to BleepingComputer, SafePal first received a report consistent with the issue in early May 2026 and treated it as an isolated case at the time; a customer had received a phishing email and a phone call from someone claiming to be a SafePal employee. In July, the company began what it called a full review and rebuild of its order-processing system, and that is when the flaw was found. Affected customers were emailed on 16 August from security@safepal.com, with the subject line "[Important] Your SafePal Order Information Has Been Affected". If you received that email, you are in the set. If you did not, SafePal's position is that you are not.

SafePal says it has fixed the flaw, added further security measures, and taken down more than 30 fraudulent websites and phishing links that were impersonating it. That last figure is worth pausing on. Thirty-odd fake sites is not what you build to defraud people at random. It is what you build when you have a list of people who own a particular product.

What leaked, and what did not

SafePal's own statement lists five categories: name, email address, shipping address, phone number and purchase details. It states that seed phrases, private keys, wallet passwords and other wallet credentials, bank account information, payment card numbers and government-issued identification numbers were not exposed. It also says no evidence has been found that the incident itself compromised access to any wallet or funds. The disclosure does not spell out what "purchase details" contains, so treat that category as unspecified rather than harmless.

The data is being offered for sale. BleepingComputer reports that a seller on a hacking forum is advertising the stolen records and offering to prove the listing is genuine by sharing order IDs and shipping countries from real orders, which buyers can check against SafePal's own online verification tool. That is a grim little irony: the tool built to help customers confirm whether they were affected also lets a criminal demonstrate the goods. Whether the seller is the person who found the flaw or a middleman is not stated, and we are not going to speculate.

At the time of writing the incident has not appeared in Have I Been Pwned, so the notification email and SafePal's own tool are the only ways to confirm you are included.

Are you affected

If you bought a SafePal device, or anything else through its store, between 2 March 2025 and 11 April 2026, assume yes until shown otherwise. Check the inbox you used at checkout for the 16 August email, and check the spam folder too, because a message with "[Important]" and "Affected" in the subject line is precisely what filters are suspicious of. If it is there, remember that it tells you which address and which phone number were in the leak; whatever the attackers do next, they will do it to those.

If the incident later appears in a breach database, our guide to reading a Have I Been Pwned result covers what a hit does and does not tell you: what to do with a Have I Been Pwned result. A hit there would add nothing you do not already know from SafePal's email, but for people who no longer have access to the checkout address it may be the only signal they get.

The checklist for this one

The general steps after any leak are in our checklist, what to do when your email is leaked. For this incident, weight it towards the following.

  • Treat every "SafePal" contact as hostile by default. SafePal's own advisory warns of fraudulent phone calls, emails, text messages, letters, refund offers and firmware-update requests. It says it will never ask for your seed phrase, private key or wallet password by phone, by email or through any other channel, under any circumstance. If a message asks for any of those, that is your answer.
  • Do not "verify", "migrate" or "update" a wallet because a message told you to. The most likely scam against this list is a fake firmware or app update that captures the seed phrase. Reach the official app or site by typing the address yourself, never through a link.
  • If you have typed your seed phrase into anything since May, move the funds now. SafePal's advice to anyone who shared a seed phrase in response to a phishing attempt is to transfer assets to a new wallet created on a trusted device. Do that before reading further.
  • Expect the physical angle. The list pairs shipping addresses with the fact that the recipient owns a hardware wallet. Letters and doorstep visits are rarer than emails, but SafePal lists letters explicitly, and the leaked data supports them.
  • Watch the phone number as closely as the email. A call that quotes your name and order will feel legitimate. Hang up and ring back on a number taken from SafePal's site.
  • Change any password reused between the checkout email account and anything else. Passwords were not in this leak, but the address now sits on a list of people worth attacking, and credential stuffing follows lists.

One thing not to do: do not abandon the device because of this. The wallet's security model is not what failed. A shop database did.

The pattern it repeats

This is the second hardware wallet vendor in a fortnight to disclose that its customer list has leaked without a single wallet being touched. Trezor's came through a shipping partner; SafePal's came through an order-tracking plug-in. The mechanisms differ, the outcome does not: names, addresses, phone numbers and emails of people who own a device whose whole purpose is to hold value, now in circulation. Our earlier analysis of the Trezor and ShipMonk incident covers the same fallout, and most of it transfers.

The lesson is not that hardware wallets are unsafe. It is that the buying record is a separate asset from the wallet, held in a separate and much weaker place, and that the weakest link in that record is usually a component nobody thought of as security-relevant. An order-tracking plug-in exists so customers can see where their parcel is. It is the sort of thing that gets installed, works, and is never looked at again. Every online shop has several.

For readers, the practical consequence is that the details you give a shop are exposed to that shop's whole supply chain, plug-ins included. There is a limit to what you can do about the shipping address; a parcel has to arrive somewhere. The email address and phone number are more flexible. Giving each merchant its own contact address, so that a leak identifies its source and can be shut off, is the approach we set out in who leaked my email address, and this incident is a clean example of where it pays. An address used only for a SafePal order, receiving a "firmware update required" email, tells you exactly which database it came from and can be switched off without touching anything else. The wallet still works. So does the phone, unfortunately, which is why the vishing warnings above matter more than the email ones.

By BleepingComputer's account, more than three months passed between the first report and the customer notice. Whether that was too long is a fair question for the customers involved. What is not in question is that the people on the list are being contacted now, by criminals with dozens of fake sites and a phone number for each of them, and that the only defence that works today is refusing to hand over the one thing that was never leaked.

The YeyMail takeaway
One address per shop, and a way to switch it off

The SafePal leak is a shop record, not a wallet failure, and the shop record is what forwarding aliases are for. With YeyMail you give each merchant its own address on yeymail.com or on a domain you own; when a "firmware update" email arrives at the SafePal-only address, you know exactly where it came from, and the kill switch refuses further mail to that alias at SMTP time, with nothing queued or filtered. It keeps working after you cancel. Trial is free for 7 days with no card and includes 25 shared-domain aliases and one custom domain; paid plans start at $0.99 a month. Be clear about what this does not cover: it does nothing for a leaked phone number or shipping address, and it will not stop a scam you type your seed phrase into. For those, the advice above is the whole defence.

Start free — one alias per signup7-day trial · No credit card

Sources

Common questions

Was my SafePal wallet or crypto stolen in the SafePal breach?

SafePal says no. The exposed data was order information: names, email addresses, shipping addresses, phone numbers and purchase details. Seed phrases, private keys and wallet passwords were not part of the affected system, and SafePal says it has found no evidence the incident itself gave anyone access to wallets or funds. The risk is the phishing that follows, not the breach itself.

How do I know if I am one of the 39,798 affected SafePal customers?

SafePal says it emailed every affected customer on 16 August 2026 from security@safepal.com with the subject "[Important] Your SafePal Order Information Has Been Affected". If you ordered between 2 March 2025 and 11 April 2026, check that inbox and its spam folder. Reports also describe an online verification tool that takes an order number and shipping country. As of 17 August the incident is not in Have I Been Pwned.

What will scammers do with the SafePal data?

The most likely use is targeted phishing: emails, calls or texts pretending to be SafePal and asking you to "verify" or "update" your wallet, or offering a refund. SafePal says it has already taken down more than 30 fraudulent sites. Anything that asks for a seed phrase, private key or wallet password is a scam; SafePal says it will never ask for those through any channel.

Should I move my funds to a new wallet after the SafePal breach?

Not because of the breach alone, since the keys were not exposed. SafePal's advice is that anyone who has already shared a seed phrase in response to a phishing message should transfer assets to a new wallet created on a trusted device. If that is you, do it immediately. If it is not, your priority is refusing every unsolicited request for credentials from now on.

Why is this similar to the Trezor breach?

Both are hardware wallet vendors whose customer lists leaked through something other than the wallet: a shipping partner for Trezor, an order-tracking plug-in for SafePal. In each case the leaked data pairs a home address, email and phone number with the fact that the person owns a device that stores cryptocurrency, which is exactly what a targeted scam needs.

Would using an email alias have helped with the SafePal breach?

Partly. An address used only for the SafePal order would tell you where any later phishing came from and could be switched off without affecting anything else. It would not have protected the phone number or shipping address, which were also exposed, so the phone and physical warnings still apply.

Keep reading

Breach analysis
Trezor's Shipping Breach Exposes 13,689 Wallet Buyers
Breach response
Your Email Was Leaked: The Complete What-Now Checklist
Privacy guide
How to Find Out Which Company Leaked Your Email