Today3h ago
Project update
SafePal discloses an order-data breach affecting ~40K users

SafePal discloses an order-data breach affecting ~40K users

Hardware wallet maker SafePal has disclosed a security incident: an authorization flaw in its order-tracking system let outsiders access the order records of about 39,800 customers who ordered between March 2025 and April 2026.


The exposed data covers names, emails, phone numbers, shipping addresses and purchase details. Crucially, it did not include seed phrases, private keys, wallet passwords or payment card data, which SafePal says it never stores, and the company says it found no evidence that any wallets or funds were affected.


The bigger danger is targeted phishing and impersonation. SafePal says it has patched the flaw, engaged an independent security firm, cut order-data retention to 90 days, notified affected users by email and taken down more than 30 fraudulent sites.