The SafePal data breach exposed order information for about 39,798 customers, the hardware-wallet maker disclosed on August 16, 2026. SafePal traced the incident to an authorization flaw in an order-tracking function used by a plugin associated with customer order information.
The company says the incident did not involve seed phrases, private keys, wallet passwords, payment cards, bank accounts, or government IDs. That distinction matters: an exposed shipping record does not by itself give someone control of a wallet. It can, however, give a scammer enough personal context to make a fake support call, delivery message, refund offer, or firmware-update warning sound convincing.
Who was affected and what data was exposed?
SafePal says the issue affected orders placed from March 2, 2025 through April 11, 2026. The company sent notices from [email protected] on August 16 with the subject “[Important] Your SafePal Order Information Has Been Affected.”
| SafePal disclosure detail | What it means for customers |
|---|---|
| Affected records | Name, email address, shipping address, phone number, and purchase details |
| Not involved | Seed phrases, private keys, wallet passwords, wallet credentials, payment cards, bank accounts, and government IDs |
| Company’s wallet finding | No evidence that wallets or funds were accessed through this incident |
| Order window | Orders placed from March 2, 2025 through April 11, 2026 |
If you ordered in that period but did not receive a notice, verify your status through SafePal’s official support path instead of replying to an unexpected message. Type safepal.com into the browser yourself. Do not trust a link, phone number, or QR code supplied by someone claiming to “check” whether you were affected.
Why order data can make wallet phishing more dangerous
A criminal who knows the product you bought, your name, telephone number, and delivery address can impersonate SafePal or a courier with unusually specific details. The lure may claim that your device needs a security update, a replacement, a refund, or an urgent wallet “validation.” None of those stories requires the attacker to possess your keys first; the goal is to make you disclose them.
Expect attempts over email, SMS, phone calls, messaging apps, and even physical mail. A caller may quote a real order detail and then ask you to install software, visit a lookalike site, share a screen, approve a transaction, or enter a seed phrase. Similar tactics appear in crypto-wallet validation email scams, where the warning itself is designed to create urgency.
SafePal says it has fixed the authorization issue, added controls, engaged a third party for an audit, and reduced retention of this order data to 90 days. It also reports working with partners to remove more than 30 fraudulent websites and phishing links. These measures reduce future exposure, but copies already obtained by criminals can support targeted scams long after the original flaw is closed.
What SafePal customers should do now
- Verify the notice independently. Open the official SafePal site manually and use its published support form. Do not use contact details from an unsolicited caller or message.
- Do not move funds solely because order data was exposed. SafePal says there is no evidence that wallets or funds were compromised in this incident. Moving assets in response to a stranger’s instructions can create the very loss the warning claims to prevent.
- Never disclose a seed phrase or private key. SafePal support does not need it to investigate an order. Do not enter it on a website, send it in chat, read it over the phone, or import it into an app suggested by another person.
- Protect the accounts attackers can target. Use a unique email password, enable phishing-resistant multi-factor authentication where available, add a carrier account PIN, and watch for unauthorized password-reset requests.
- Treat unexpected downloads as hostile. Do not install a “firmware updater,” remote-support program, browser extension, or mobile app delivered through a message. A suspicious file or URL can be checked with the Gridinsoft Online Virus Scanner before it is opened.
- Reduce physical risk. Because a shipping address may be exposed, avoid discussing crypto holdings with unknown callers, secure the delivery location, and consider local law-enforcement advice if a message contains a credible threat.
If you already interacted with a suspicious message
- You only received or opened the message: do not reply, block the sender, preserve a screenshot or headers, and report it through SafePal’s official scam-reporting channel.
- You clicked but entered nothing: close the page, clear any downloads, and check the URL carefully. Review the device if the page requested notifications or installed an extension.
- You installed a file or remote-access tool: disconnect the affected device from the network, remove remote access, scan it from a trusted environment, and change important passwords from a different clean device.
- You shared an email or SafePal account password: change it immediately, terminate active sessions, enable MFA, and secure any other account where that password was reused.
- You entered a seed phrase or private key: treat the wallet as compromised. On a clean device, create a new wallet using an official trusted SafePal app or device and transfer remaining assets to addresses controlled by the new seed. Never reuse the exposed seed.
- You approved an unknown transaction: revoke token approvals where applicable, move remaining assets from the compromised wallet, record transaction hashes, and contact the relevant exchange or law-enforcement channel promptly.
What this breach does not prove
The disclosure does not mean every SafePal device is compromised, and it does not show that the company’s wallet keys were extracted. It also does not make every breach notification authentic. Attackers can imitate the real subject line and sender display name, so the safest response is to navigate independently and verify through the official site.
The incident follows a separate disclosure involving Trezor customer contact and shipping data. The affected dates and notification process are different, but the defensive rule is the same: order details may make the approach believable, while only you can hand an attacker the secret that controls the wallet.
References
- SafePal, “Security Update”, published August 16, 2026; accessed August 17, 2026.
- SafePal, “Scam Protection”, accessed August 17, 2026.

