SafePal Hardware Wallet Maker Discloses Data Exposure Affecting Nearly 40,000 Customers
SafePal, a hardware wallet maker, has disclosed an authorization flaw in an order-tracking plug-in that exposed the data of approximately 39,798 customers.

The SafePal hardware wallet maker has disclosed an authorization flaw in an order-tracking plug-in that exposed the data of approximately 39,798 customers.
The exposed data includes names, email addresses, shipping addresses, phone numbers, and purchase details, but does not include wallet credentials or financial information. SafePal has stated that it has found no evidence that the incident compromised access to SafePal wallets or funds.
The affected orders were placed between March 2, 2025, and April 11, 2026. SafePal has notified all affected customers individually by email, with the subject line "[Important] Your SafePal Order Information Has Been Affected."
The company has warned that affected customers may face "fraudulent phone calls, emails, text messages, letters, refund offers, firmware-update requests, fake customer-support communications." SafePal has advised customers to treat any unexpected contact or hardware delivery referencing their SafePal purchase as suspect.
| Feature | Affected Range | | --- | --- | | Orders Placed | March 2, 2025 - April 11, 2026 | | Number of Customers | 39,798 |
SafePal has taken steps to address the issue, including fixing the flaw, introducing additional security measures, and purging affected records from active servers. The company has also engaged an independent third-party security firm to validate the fix and review order-processing systems more broadly.
In related news, Chainalysis has reported a jump in French cases of stolen tax records on crypto holders, with 30 cases documented by mid-2026. The company has attributed this increase to the fact that crypto holders are high-value targets due to their wealth in an instantly and irreversibly transferrable form.
SafePal has also disclosed that a scheduled data-cleanup process had stopped working correctly between September 2025 and April 2026 due to a configuration error, leaving older order records in the system longer than intended. The company has stated that this issue did not cause the unauthorized access itself, but is why the affected range extends back to March 2025.
The incident has led to the creation of a threat actor who has advertised a dataset on a cybercrime forum that cites the same order window and the same customer count. SafePal has listed the following measures to address the issue:
- The flaw has been fixed and additional security measures introduced. - Retention of personal information in the relevant order-processing environment has been cut to 90 days, subject to applicable legal requirements. - Affected records have been purged from active servers, with a secured offline backup kept solely to support potential investigations. - An independent third-party security firm is being engaged to validate the fix and review order-processing systems more broadly. - Third-party logistics and fulfillment partners have been contacted to confirm the issue had not spread within their systems. - Over 30 fraudulent websites and phishing links "tied to the scam activities" have been taken down. - A status-check page using an order ID number and shipping country has been published, alongside a dedicated support channel.
SafePal has advised customers not to move assets solely because of the exposure, but to treat any wallet that has had a seed phrase or private key entered in response to a suspicious message as compromised.
Ledger has previously disclosed a breach that exposed approximately 272,000 detailed records with postal addresses, names, and phone numbers. Researchers have surveyed 104 of those customers and found spam, scams, phishing, and two reports of tampered devices "possibly tied to the breach," along with heightened safety concerns.
Neither SafePal nor any mainstream news outlet covering the incident has reported a confirmed financial loss. The company has asked customers who believe they suffered a loss to contact its support channel, and said it is "contacting on-chain asset-tracing specialists on this incident." It has not said that any loss has been traced to the exposed data.





