discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

SafePal data breach impacts 39,798 customers, stolen info for sale

Cryptocurrency hardware wallet provider SafePal disclosed a data breach affecting 39,798 customers after an order-tracking flaw was exploited, with stolen data now being sold on a cybercrime forum.

By Lawrence Abrams·Aug 16·bleepingcomputer.com·3 min read

Intelligence analysis by Llama

SafePal data breach impacts 39,798 customers, stolen info for sale
Image: bleepingcomputer.com

SafePal is warning that an authorization flaw in its order-tracking plug-in exposed names, addresses, phone numbers, and purchase details for roughly 39,798 customers who ordered between March 2025 and April 2026. Wallet seed phrases and private keys were not exposed, but a threat actor is already selling the data on a cybercrime forum.

Why it matters

The breach highlights how e-commerce side-channels can leak sensitive customer data even when the core crypto custody systems remain intact, and it gives phishers a verified contact list tied to known crypto hardware wallet owners.

A company that makes special devices for keeping cryptocurrency safe had a website problem. Bad guys peeked at about 40,000 customers' orders, learning their names, addresses, and phone numbers. The secret codes that protect the actual money were not stolen. But the bad guys might try to trick those customers with fake emails or phone calls.

Analysis

The 39,798-customer exposure

SafePal disclosed that the breach affected customers who placed orders between March 2, 2025, and April 11, 2026, exposing names, email addresses, shipping addresses, phone numbers, and purchase information. The company emphasized that wallet seed phrases, private keys, passwords, bank account information, payment card numbers, and government-issued identification numbers were not part of the leak. According to SafePal, "no evidence has been found that the incident itself compromised access to SafePal wallets or funds," a distinction that matters enormously for the roughly 39,798 affected customers deciding whether to rotate their holdings. The company notified impacted customers via email on August 16 with the subject line "[Important] Your SafePal Order Information Has Been Affected," and launched an online verification tool that lets users enter an order number and shipping country to confirm exposure.

The order-tracking authorization flaw

The root cause was an authorization flaw in the order-tracking function of a plug-in that allowed unauthorized access to another customer's order information, according to SafePal's advisory. A separate configuration error caused a data-cleanup process to stop functioning correctly between September 2025 and April 2026, resulting in order data being retained as far back as March 2025 and widening the blast radius of the original flaw. SafePal says it first received a report consistent with the incident in early May 2026, initially treated it as isolated, then escalated into a formal investigation in July that included a "full review and rebuild" of its order-processing system. The company has fixed the vulnerability, brought in a third-party security firm to validate the fix, and purged personal data from active e-commerce servers while retaining an encrypted offline copy for potential law-enforcement use.

DarkWebInformer's forum listing

A threat actor is now selling the stolen SafePal customer data on a cybercrime forum, as spotted by DarkWebInformer, and the listing references the same affected order period and approximately 39,798 customers that SafePal disclosed. To prove the data is real, the seller is willing to share order ID and shipping country information from stolen orders, which buyers can verify against SafePal's online tool. The forum post reads, "Not interested in low balls, please come correct and with a good price or do not message me at all," suggesting the seller expects serious buyers. BleepingComputer has not independently verified that the threat actor possesses the stolen data, but the alignment of the claimed victim count and date range with SafePal's own disclosure gives the listing credibility. SafePal says it has already taken down more than 30 fraudulent websites and phishing links tied to this incident, and warns customers to expect targeted phishing about firmware upgrades, product returns, refunds, or legal investigations.

Key points

  • SafePal disclosed a breach affecting 39,798 customers who ordered between March 2, 2025 and April 11, 2026
  • Exposed data includes names, emails, shipping addresses, phone numbers, and purchase details, but not seed phrases or private keys
  • The root cause was an authorization flaw in an order-tracking plug-in, compounded by a data-cleanup configuration error that ran from September 2025 to April 2026
  • A threat actor spotted by DarkWebInformer is selling the data on a cybercrime forum and offering verifiable samples tied to SafePal's own verification tool
  • SafePal has taken down more than 30 phishing sites and warns customers to expect targeted phishing about firmware updates, refunds, and legal investigations
The Upside

SafePal's verification tool and prompt takedown of more than 30 fraudulent sites give affected customers a concrete way to confirm exposure and reduce phishing risk. The fact that seed phrases and private keys were not exposed means most users do not need to migrate funds, limiting the long-term damage to a contained set of order metadata.

The Downside

The verified forum listing gives phishers a high-confidence target list of known crypto hardware wallet owners, raising the odds of successful social engineering even though on-chain funds remain safe. The authorization flaw in a third-party plug-in and the months-long data-retention configuration error suggest broader weaknesses in SafePal's e-commerce security posture that may surface again.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritycryptodata-breachhardware-walletphishing

Author

Lawrence Abrams

Intelligence analysis by

Llama

Published

Aug 16, 2026

Source

bleepingcomputer.com

Share

Topics

securitycryptodata-breachhardware-walletphishing

Related

More from this desk

Aug 16·bleepingcomputer.com

Anthropic confirms Claude is down in major outage affecting multiple services

Anthropic's AI model Claude is experiencing a major outage, affecting multiple services including Claude.ai, Claude Code, and Claude Cowork. Users are reporting login problems and degraded performance.

Aug 16·bleepingcomputer.com

Large-scale DDoS attacks disrupted Threema secure messaging service

Threema, a secure messaging service, was disrupted by large-scale DDoS attacks earlier this week. The attacks targeted both Threema and its colocation partner, Nine, and were difficult to defend against due to the threat actor constantly changing patterns.

Aug 16·bleepingcomputer.com

New AmnesiaStealer macOS malware hijacks browser sessions via remote control

A new information-stealing malware called AmnesiaStealer targets macOS users via ClickFix attacks, including a streaming module that allows the attacker to interactively control the victim's web browser. The malware can collect data in 16 Chromium-based web browsers as we…

Aug 15·bleepingcomputer.com

New Evooo1Bot Linux botnet turns routers into traffic relay nodes

A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes. The malware's capabilities extend beyond turning devices into proxy nodes and include credential theft, SSH br…