SafePal disclosed the incident on August 16, saying it had identified an authorization flaw in a plug-in used for its order-tracking function. Under certain conditions, the vulnerability allowed unauthorized access to another customer's order information.
The affected records cover approximately 39,798 customers who placed orders between March 2, 2025 and April 11, 2026. The exposed information included customers' names, email addresses, phone numbers, shipping addresses and details of the SafePal products they had purchased.
SafePal emphasized that the incident was limited to its order-processing environment and did not compromise the wallet infrastructure itself. Seed phrases, private keys, wallet passwords, bank-account information, payment-card numbers and government-issued identification numbers were not exposed.
The company said it has found no evidence that the incident itself provided unauthorized access to SafePal wallets or customer funds. As a result, affected customers do not need to replace their hardware wallets or transfer their assets solely because their order information was exposed.
The main security risk now comes from social engineering and targeted crypto phishing attacks. With access to a SafePal wallet customer's real name, phone number, shipping address and previous hardware-wallet purchase details, scammers can create far more convincing phishing campaigns than ordinary mass emails.
An attacker could, for example, impersonate SafePal support and contact a customer about a supposed refund, firmware update, device replacement or security problem. Because the scammer may already know which product the customer purchased and where it was delivered, the communication can appear legitimate before the victim is eventually asked to visit a fraudulent website or disclose a seed phrase or private key.
SafePal specifically warned users about fraudulent phone calls, emails, text messages, physical letters, refund offers, fake firmware updates and customer-support impersonation. The company reiterated that its employees will never ask customers to provide a recovery phrase, private key or wallet password.
Signs of targeted phishing had appeared months before the company publicly disclosed the breach. SafePal said it received its first report consistent with the incident in early May 2026. At the time, the company treated it as an isolated case while introducing additional protections and examining several possible causes.
The investigation expanded in July, when SafePal began a full review and rebuild of its order-processing pipeline. During that process, the company identified the authorization flaw in the order-tracking plug-in as the root cause of the unauthorized access.
The investigation also uncovered a separate configuration problem. A scheduled data-cleanup process had stopped functioning correctly between September 2025 and April 2026, causing older order records to remain in the system longer than intended. SafePal said this issue did not cause the breach itself, but it explains why potentially affected records extend as far back as March 2025.
Some users had already described suspicious contacts that appeared to rely on genuine SafePal purchase information. In a Reddit report published in July, a customer said a caller impersonating SafePal knew their name, address, phone number, email and previous order details. The caller allegedly claimed that a firmware vulnerability had been discovered and offered a refund or replacement before directing the user to the fraudulent safepal.support domain.
SafePal has since patched the authorization flaw and strengthened access controls around the affected system. The company is also engaging an independent cybersecurity firm to verify the fix and conduct a broader review of its order-processing infrastructure.
At the same time, SafePal has shortened the retention period for sensitive order information in the relevant environment to 90 days, subject to applicable legal requirements. It has opened a dedicated support channel for affected customers and contacted its logistics and fulfillment partners to determine whether the incident extended into external systems. So far, the company says it has found no evidence of a related breach at those logistics partners.
The company has also identified and taken down more than 30 fraudulent websites and phishing links associated with scam activity and continues to monitor for newly created domains.
SafePal has not said that the exposure itself resulted in direct access to customer assets. Customers who believe they suffered a financial loss connected to subsequent phishing have been asked to provide information through the company's dedicated channel, while SafePal says it is working with on-chain asset-tracing specialists to support investigations.
The disclosure comes only days after another major hardware-wallet provider reported a customer-data incident. On August 13, Trezor disclosed that a breach at logistics partner ShipMonk had exposed information belonging to approximately 13,689 customers.
In that case, 11,742 customers had their names, email addresses, phone numbers and shipping addresses exposed, while another 1,947 customers experienced more limited exposure involving names, cities and email addresses. Trezor stressed that its own systems and hardware wallets were not compromised.
Ledger faced a similar third-party problem earlier in 2026 when an incident involving e-commerce partner Global-e exposed customer order data. As with the SafePal and Trezor cases, the security concern was not the extraction of private keys from the hardware wallet itself, but the ability of criminals to use leaked customer information for targeted phishing and impersonation.
A much more serious and technically different incident affected COLDCARD users this summer. Coinkite, the manufacturer of the Bitcoin hardware wallet, confirmed a flaw affecting seed generation on several firmware versions. The issue reduced the effective randomness of some device-generated seeds, potentially allowing attackers to reconstruct vulnerable keys without gaining physical access to the device.
The problem traces back to firmware introduced in March 2021 and affected multiple COLDCARD models and software versions. Coinkite has since released corrected firmware, but updating a device does not repair a seed that was originally generated under an affected version. Users with vulnerable seeds have therefore been advised to generate a new seed using fixed firmware and migrate their funds.
Galaxy Research estimated that attackers had drained approximately $130 million worth of Bitcoin across multiple waves by early August. Unlike the SafePal and Trezor incidents, where customer contact information was exposed while wallet credentials remained secure, the COLDCARD vulnerability directly affected the cryptographic process used to create wallet keys.
The incidents have nevertheless intensified a broader debate over hardware wallet security and crypto self-custody. A hardware wallet can keep private keys isolated from online systems, but the SafePal and Trezor cases show that customer databases, e-commerce platforms and logistics providers can create a separate layer of security risk even when the wallet device itself remains uncompromised.
On-chain investigator ZachXBT had already sparked controversy in July by arguing that existing hardware wallets have too many potential points of failure and saying he would prefer a dedicated smartphone used exclusively for crypto in some situations.
However, the recent cases illustrate different categories of risk rather than a single flaw in the concept of hardware wallets. SafePal and Trezor highlight the dangers created by e-commerce databases, shipping providers and leaked customer identities, while COLDCARD demonstrates how a defect in key-generation software can directly threaten assets. In both cases, protecting a private key alone may not address every security risk surrounding self-custody.
For users reconsidering how they store digital assets after the recent SafePal, Trezor and COLDCARD incidents, choosing a crypto wallet requires looking beyond the device itself. Security architecture, private-key management, recovery options, transparency and the provider's broader infrastructure all matter. FORECK.INFO compares these factors in its regularly updated Best Crypto Wallets ranking, where SafePal is evaluated alongside other leading hardware and self-custody wallets.