SafePal Data Breach Exposes Names and Home Addresses of 40,000 Hardware Wallet Customers

SECURITY

Hardware wallet maker SafePal disclosed on August 16, 2026, that an authorization flaw in its order-tracking plugin allowed unauthorized access to the personal information of approximately 39,798 customers who placed orders between March 2, 2025, and April 11, 2026. The exposed data includes customer names, email addresses, phone numbers, shipping addresses, and purchase details. SafePal confirmed that no seed phrases, private keys, wallet passwords, bank details, payment card numbers, or government-issued identification were compromised, and that no evidence has been found of unauthorized access to user wallets or funds.

The vulnerability was caused by a verification defect in a third-party plugin used for order tracking. The flaw improperly handled access controls, allowing one customer to view another customer’s order details simply by modifying parameters. SafePal stated the issue has been resolved and additional security measures have been introduced.

Phishing Attacks Already Underway

The real danger is not the breach itself but what follows from it. SafePal warned that attackers may use the exposed information to impersonate SafePal support staff, contacting affected customers through calls, messages, or emails offering fake firmware updates, refunds, or replacement devices before attempting to extract wallet credentials. Over 30 phishing sites tied to the stolen data have already been identified and taken down. One affected user publicly stated they had flagged the issue to SafePal four months ago and were ignored.

For Bitcoin holders who use hardware wallets specifically because they want to keep their assets off exchanges and away from third parties, having their name, home address, and the fact that they own a hardware wallet exposed to attackers is a serious physical security concern. A leaked customer database tells criminals exactly who owns hardware wallets and where they live.

The Third Hardware Wallet Incident in Weeks

The SafePal breach arrives in the same month as the Coldcard exploit that saw over $120 million in Bitcoin stolen from approximately 500 users, and the Boltz infrastructure shutdown triggered by AI-assisted attacks. In January 2026, Ledger also confirmed that customer information was exposed through a breach at its third-party payment processor Global-e. Together, these incidents represent the most concentrated period of hardware wallet and Bitcoin infrastructure security failures in recent memory, and raise urgent questions about whether the supply chain behind self-custody tools is keeping pace with the sophistication of the attacks targeting it.

ENJOYED THIS ARTICLE?Support the authorSend a zap over Lightning or on-chain