SafePal, the crypto hardware wallet maker, confirmed on August 16, 2026, that a security flaw exposed order information for 39,798 customers.
This SafePal Data Breach News report covers how the exposure happened, what was involved, and what affected users should do now.
The company said the cause was a flaw in a third-party order-tracking plug-in on its e-commerce site, not its wallet software or hardware. Seed phrases, private keys, and wallet passwords were not involved in this SafePal Data Breach News event.
The firm found an authorization flaw in the plug-in used to track customer purchases. The flaw let one buyer view another buyer's shipment details under certain conditions. The company says the flaw is now fixed, and extra checks were added to the tracking system.
The exposure covers purchases placed between March 2, 2025, and April 11, 2026. Exposed records include name, email address, shipping address, phone number, and purchase details. Bank details, payment card numbers, and government ID numbers were not part of this incident, based on the official disclosure.
Detail | Information |
Customers affected | 39,798 |
Order window | March 2, 2025, to April 11, 2026 |
Info exposed | Name, email, address, phone, order details |
Wallet funds affected | No |
Disclosure date | August 16, 2026 |

Source: Official Notice
Purchase details alone cannot move funds out of a hardware device, since keys stay offline in an isolated environment away from e-commerce servers.
But contact details from this SafePal Data Breach News case can fuel convincing phishing attempts. Scammers could pose as support staff and ask a buyer to enter a seed phrase or scan a QR code to "verify" a device.
Affected users may face fake calls, emails, texts, letters, refund offers, or firmware-update requests built around this incident.
This development pushed the company into a fast response. Steps taken since the flaw was found include:
Fixing the plug-in flaw and adding new checks to the tracking system
Hiring an outside security firm to review the fix and the wider purchase process
Cutting the storage period for personal purchase records to 90 days
Opening a dedicated support channel for this case
Emailing every affected customer from security@safepal.com
Removing more than 30 fake websites and phishing links tied to the case
Publishing a scam-protection page for status checks
Buyers can check their status on the official scam-protection page using an order number and shipping country. Updates on the outside review will be posted on the official blog.
This SafePal Data Breach News case is not an isolated event. Crypto wallet makers and exchanges have reported a steady stream of security disclosures through 2026, ranging from phishing waves to third-party plug-in flaws like this one.
The pattern shows that customer-facing web services, not just wallet hardware, are now a regular target for attackers. It also explains why this was flagged as an order-system issue rather than a wallet compromise.
Following this SafePal data breach news event, affected users should:
Avoid clicking links in unexpected emails, texts, or letters about a purchase
Type the official web address directly into a browser instead of following a link
Never share a seed phrase, PIN, or password with anyone, including claimed support staff
Report suspicious contact through the scam-protection page
Move funds to a new wallet only if a seed phrase was already entered on a fake site
The SafePal Data Breach News case fits a pattern across the crypto hardware industry, where the weak point is often a connected web service rather than the device itself.
Keeping cold storage isolated from purchase and support systems limited the fallout here to contact records rather than funds. The bigger test is how the ongoing phishing wave is handled and whether the outside audit finds gaps beyond this single plug-in flaw.
YMYL Disclaimer: This article is for informational and educational purposes only. It is not financial, investment, or legal advice. Always verify security incidents through official company channels before taking action.