SafePal data breach impacts 39,798 customers, stolen info for sale
Cryptocurrency hardware wallet provider SafePal disclosed a data breach affecting 39,798 customers after an order-tracking flaw was exploited, with stolen data now being sold on a cybercrime forum.
Intelligence analysis by Llama

SafePal is warning that an authorization flaw in its order-tracking plug-in exposed names, addresses, phone numbers, and purchase details for roughly 39,798 customers who ordered between March 2025 and April 2026. Wallet seed phrases and private keys were not exposed, but a threat actor is already selling the data on a cybercrime forum.
A company that makes special devices for keeping cryptocurrency safe had a website problem. Bad guys peeked at about 40,000 customers' orders, learning their names, addresses, and phone numbers. The secret codes that protect the actual money were not stolen. But the bad guys might try to trick those customers with fake emails or phone calls.
Analysis
The 39,798-customer exposure
SafePal disclosed that the breach affected customers who placed orders between March 2, 2025, and April 11, 2026, exposing names, email addresses, shipping addresses, phone numbers, and purchase information. The company emphasized that wallet seed phrases, private keys, passwords, bank account information, payment card numbers, and government-issued identification numbers were not part of the leak. According to SafePal, "no evidence has been found that the incident itself compromised access to SafePal wallets or funds," a distinction that matters enormously for the roughly 39,798 affected customers deciding whether to rotate their holdings. The company notified impacted customers via email on August 16 with the subject line "[Important] Your SafePal Order Information Has Been Affected," and launched an online verification tool that lets users enter an order number and shipping country to confirm exposure.
The order-tracking authorization flaw
The root cause was an authorization flaw in the order-tracking function of a plug-in that allowed unauthorized access to another customer's order information, according to SafePal's advisory. A separate configuration error caused a data-cleanup process to stop functioning correctly between September 2025 and April 2026, resulting in order data being retained as far back as March 2025 and widening the blast radius of the original flaw. SafePal says it first received a report consistent with the incident in early May 2026, initially treated it as isolated, then escalated into a formal investigation in July that included a "full review and rebuild" of its order-processing system. The company has fixed the vulnerability, brought in a third-party security firm to validate the fix, and purged personal data from active e-commerce servers while retaining an encrypted offline copy for potential law-enforcement use.
DarkWebInformer's forum listing
A threat actor is now selling the stolen SafePal customer data on a cybercrime forum, as spotted by DarkWebInformer, and the listing references the same affected order period and approximately 39,798 customers that SafePal disclosed. To prove the data is real, the seller is willing to share order ID and shipping country information from stolen orders, which buyers can verify against SafePal's online tool. The forum post reads, "Not interested in low balls, please come correct and with a good price or do not message me at all," suggesting the seller expects serious buyers. BleepingComputer has not independently verified that the threat actor possesses the stolen data, but the alignment of the claimed victim count and date range with SafePal's own disclosure gives the listing credibility. SafePal says it has already taken down more than 30 fraudulent websites and phishing links tied to this incident, and warns customers to expect targeted phishing about firmware upgrades, product returns, refunds, or legal investigations.
Key points
- SafePal disclosed a breach affecting 39,798 customers who ordered between March 2, 2025 and April 11, 2026
- Exposed data includes names, emails, shipping addresses, phone numbers, and purchase details, but not seed phrases or private keys
- The root cause was an authorization flaw in an order-tracking plug-in, compounded by a data-cleanup configuration error that ran from September 2025 to April 2026
- A threat actor spotted by DarkWebInformer is selling the data on a cybercrime forum and offering verifiable samples tied to SafePal's own verification tool
- SafePal has taken down more than 30 phishing sites and warns customers to expect targeted phishing about firmware updates, refunds, and legal investigations
SafePal's verification tool and prompt takedown of more than 30 fraudulent sites give affected customers a concrete way to confirm exposure and reduce phishing risk. The fact that seed phrases and private keys were not exposed means most users do not need to migrate funds, limiting the long-term damage to a contained set of order metadata.
The verified forum listing gives phishers a high-confidence target list of known crypto hardware wallet owners, raising the odds of successful social engineering even though on-chain funds remain safe. The authorization flaw in a third-party plug-in and the months-long data-retention configuration error suggest broader weaknesses in SafePal's e-commerce security posture that may surface again.



