On Sunday 16 August 2026, SafePal, which sells hardware cryptocurrency wallets, told customers that a flaw in an order-tracking plug-in had let someone pull the order details of approximately 39,798 customers. The exposed records cover anyone who bought from SafePal between 2 March 2025 and 11 April 2026, and they contain names, email addresses, shipping addresses, phone numbers and purchase details.
The wallets themselves are not affected. SafePal has been explicit on this point, and the distinction matters. Nobody's seed phrase, private key or wallet password was in the exposed data. What was exposed is the shopping record: who bought a device that holds cryptocurrency, where it was sent, and how to reach them.
That is a narrower breach than most of the ones we look at, though larger than Trezor's a few days ago. It is also, for the people in it, one of the more dangerous kinds, because the data does not need to be cracked or combined with anything else to be useful. It is a ready-made target list. Here is what SafePal and the security press have said, and what to do if you are on it.
What happened, and when
SafePal's advisory, published on 16 August, describes the cause as an authorization flaw in the order-tracking function of a plug-in associated with customer order information. It does not name the plug-in or say who built it, and we will not guess. In plain terms, the flaw let a request for one customer's order return another customer's, and someone used that to walk through the order book. BleepingComputer's report on the same day says the flaw allowed access to another customer's order information, which is consistent.
The timeline is longer than the disclosure date suggests. According to BleepingComputer, SafePal first received a report consistent with the issue in early May 2026 and treated it as an isolated case at the time; a customer had received a phishing email and a phone call from someone claiming to be a SafePal employee. In July, the company began what it called a full review and rebuild of its order-processing system, and that is when the flaw was found. Affected customers were emailed on 16 August from security@safepal.com, with the subject line "[Important] Your SafePal Order Information Has Been Affected". If you received that email, you are in the set. If you did not, SafePal's position is that you are not.
SafePal says it has fixed the flaw, added further security measures, and taken down more than 30 fraudulent websites and phishing links that were impersonating it. That last figure is worth pausing on. Thirty-odd fake sites is not what you build to defraud people at random. It is what you build when you have a list of people who own a particular product.
What leaked, and what did not
SafePal's own statement lists five categories: name, email address, shipping address, phone number and purchase details. It states that seed phrases, private keys, wallet passwords and other wallet credentials, bank account information, payment card numbers and government-issued identification numbers were not exposed. It also says no evidence has been found that the incident itself compromised access to any wallet or funds. The disclosure does not spell out what "purchase details" contains, so treat that category as unspecified rather than harmless.
The data is being offered for sale. BleepingComputer reports that a seller on a hacking forum is advertising the stolen records and offering to prove the listing is genuine by sharing order IDs and shipping countries from real orders, which buyers can check against SafePal's own online verification tool. That is a grim little irony: the tool built to help customers confirm whether they were affected also lets a criminal demonstrate the goods. Whether the seller is the person who found the flaw or a middleman is not stated, and we are not going to speculate.
At the time of writing the incident has not appeared in Have I Been Pwned, so the notification email and SafePal's own tool are the only ways to confirm you are included.
Are you affected
If you bought a SafePal device, or anything else through its store, between 2 March 2025 and 11 April 2026, assume yes until shown otherwise. Check the inbox you used at checkout for the 16 August email, and check the spam folder too, because a message with "[Important]" and "Affected" in the subject line is precisely what filters are suspicious of. If it is there, remember that it tells you which address and which phone number were in the leak; whatever the attackers do next, they will do it to those.
If the incident later appears in a breach database, our guide to reading a Have I Been Pwned result covers what a hit does and does not tell you: what to do with a Have I Been Pwned result. A hit there would add nothing you do not already know from SafePal's email, but for people who no longer have access to the checkout address it may be the only signal they get.
The checklist for this one
The general steps after any leak are in our checklist, what to do when your email is leaked. For this incident, weight it towards the following.
- Treat every "SafePal" contact as hostile by default. SafePal's own advisory warns of fraudulent phone calls, emails, text messages, letters, refund offers and firmware-update requests. It says it will never ask for your seed phrase, private key or wallet password by phone, by email or through any other channel, under any circumstance. If a message asks for any of those, that is your answer.
- Do not "verify", "migrate" or "update" a wallet because a message told you to. The most likely scam against this list is a fake firmware or app update that captures the seed phrase. Reach the official app or site by typing the address yourself, never through a link.
- If you have typed your seed phrase into anything since May, move the funds now. SafePal's advice to anyone who shared a seed phrase in response to a phishing attempt is to transfer assets to a new wallet created on a trusted device. Do that before reading further.
- Expect the physical angle. The list pairs shipping addresses with the fact that the recipient owns a hardware wallet. Letters and doorstep visits are rarer than emails, but SafePal lists letters explicitly, and the leaked data supports them.
- Watch the phone number as closely as the email. A call that quotes your name and order will feel legitimate. Hang up and ring back on a number taken from SafePal's site.
- Change any password reused between the checkout email account and anything else. Passwords were not in this leak, but the address now sits on a list of people worth attacking, and credential stuffing follows lists.
One thing not to do: do not abandon the device because of this. The wallet's security model is not what failed. A shop database did.
The pattern it repeats
This is the second hardware wallet vendor in a fortnight to disclose that its customer list has leaked without a single wallet being touched. Trezor's came through a shipping partner; SafePal's came through an order-tracking plug-in. The mechanisms differ, the outcome does not: names, addresses, phone numbers and emails of people who own a device whose whole purpose is to hold value, now in circulation. Our earlier analysis of the Trezor and ShipMonk incident covers the same fallout, and most of it transfers.
The lesson is not that hardware wallets are unsafe. It is that the buying record is a separate asset from the wallet, held in a separate and much weaker place, and that the weakest link in that record is usually a component nobody thought of as security-relevant. An order-tracking plug-in exists so customers can see where their parcel is. It is the sort of thing that gets installed, works, and is never looked at again. Every online shop has several.
For readers, the practical consequence is that the details you give a shop are exposed to that shop's whole supply chain, plug-ins included. There is a limit to what you can do about the shipping address; a parcel has to arrive somewhere. The email address and phone number are more flexible. Giving each merchant its own contact address, so that a leak identifies its source and can be shut off, is the approach we set out in who leaked my email address, and this incident is a clean example of where it pays. An address used only for a SafePal order, receiving a "firmware update required" email, tells you exactly which database it came from and can be switched off without touching anything else. The wallet still works. So does the phone, unfortunately, which is why the vishing warnings above matter more than the email ones.
By BleepingComputer's account, more than three months passed between the first report and the customer notice. Whether that was too long is a fair question for the customers involved. What is not in question is that the people on the list are being contacted now, by criminals with dozens of fake sites and a phone number for each of them, and that the only defence that works today is refusing to hand over the one thing that was never leaked.