Crypto hardware wallet maker SafePal has confirmed a data breach affecting 39,798 customers, caused by an authorization flaw in the order-tracking plug-in on its e-commerce site. The bug let customers view other customers’ order records: names, email addresses, shipping addresses, phone numbers and purchase details, for orders placed between March 2, 2025 and April 11, 2026. SafePal said it first received a report of the issue in early May 2026, fixed the flaw and hired outside security consultants, then began notifying affected customers on August 16. In its security update, the company stated: “This incident did not involve your seed phrase, private keys, wallet password, or other wallet credentials.” SafePal has taken down more than 30 phishing sites linked to the incident, and unverified claims suggest the exposed data was listed for sale on a cybercrime forum.
The distinction SafePal draws, that wallet credentials were never at risk, is real but incomplete. What leaked is a list of 39,798 verified hardware wallet owners matched to real names, phone numbers and home addresses, a targeting list for phishing and SIM-swap operators who specifically hunt for a population known to hold digital assets.
That is the gap this breach exposes: crypto infrastructure companies tend to harden the wallet stack itself, seed phrase generation, signing, firmware, because that is where the funds live. The order-tracking plug-in bolted onto the storefront gets far less scrutiny, even though it is exactly the kind of ancillary system that turns a customer list into a qualified phishing campaign. Third-party and ancillary-system breaches keep landing at organizations whose core systems were never touched, and in crypto specifically, that ancillary data can be worth more to an attacker than the custody stack it sits beside. Security leaders evaluating vendor risk in this sector should weight customer-identity exposure in supporting systems as seriously as the custody stack itself. SafePal’s disclosure also shows a roughly three-and-a-half-month gap between receiving the report and notifying customers, a disclosure timeline worth watching as the incident is assessed further.