SafePal says order-tracking flaw exposed data of 39,798 hardware wallet customers

SafePal says attackers stole order information for 39,798 customers who bought products between March 2, 2025 and April 11, 2026. The company says an authorization flaw in an order-tracking plug-in let unauthorized users view other customers’ order details, and the stolen data includes names, email addresses, shipping addresses, phone numbers, and purchase information. SafePal says wallet seed phrases, private keys, passwords, payment-card data, and government ID numbers were not exposed.
Why it matters: Hardware-wallet customer lists are highly useful for phishing, impersonation calls, and even physical-targeting scams because they identify people likely to hold cryptocurrency. Affected users should treat any SafePal-themed email, text, or phone call as suspicious and watch for tailored social-engineering attempts.

Sources

SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers
info@thehackernews.com (The Hacker News) 2026.08.18 99% relevant
This article reports the same SafePal customer-data exposure event, adding source confirmation from The Hacker News and reiterating the affected customer count and exposure via an order-tracking flaw.
SafePal latest crypto hardware wallet maker affected by breach, with nearly 40,000 impacted
2026.08.17 99% relevant
This article is a direct follow-up on the same SafePal breach, adding mainstream confirmation, the August 17 disclosure timing, and context that SafePal is the third hardware-wallet maker hit recently while reiterating the exposed data types and phishing risk.
40,000 Impacted by SafePal Data Breach
Ionut Arghire 2026.08.17 98% relevant
This article is a direct report on the same SafePal breach, adding details that attackers exploited a vulnerability in a customer order-information plugin's order-tracking function, that SafePal first received a report in May, rebuilt its order-processing pipeline in July, and has taken down more than 30 phishing sites tied to the incident.
SafePal data breach impacts 39,798 customers, stolen info for sale
Lawrence Abrams 2026.08.16 100% relevant
This article is the breach disclosure itself, with scope, affected date range, attack mechanism, and downstream abuse risk now public.
← Back to all stories