Community Trust ScoreVerified
Nearly 40,000 customers affected. SafePal confirmed on Saturday: a flaw in an order tracking plugin allowed third parties to access personal data. Private keys and recovery phrases remain untouched — but the rest, not so much.
The compromised information covers orders placed between March 2, 2025, and April 11, 2026. Names, email addresses, delivery addresses, phone numbers, purchase details — all leaked. SafePal clarifies that banking details and card numbers remain protected, and nothing directly affecting wallet access has changed. Affected customers have received an email, and a dedicated page allows them to check if their data is part of the breach. The investigation is ongoing, and SafePal promises to post updates on their blog as developments occur.
No crypto stolen. But that doesn’t mean it’s safe.
Why This Breach Really Worries
The real issue is what can be done with this data. A name, an address, a hardware wallet purchase — that’s enough to know someone likely holds digital assets. And that’s a target. Physical attacks against crypto holders have sharply increased recently. Chainalysis recorded 46 violent incidents in just the first half of 2026, with over $30 million stolen. That number, in itself, says it all.
The risk of phishing follows the same logic. An attacker who knows you ordered a SafePal wallet can craft a very credible phishing email — fake security alert, fake customer support, fake verification link. Users who aren’t careful can fall for it.
And SafePal is not alone in this situation. Trezor recently reported a similar breach, affecting 13,700 customers. Ledger, in 2020, faced a much larger breach — about 272,000 customers exposed at the time. These incidents are piling up, and the hardware wallet sector is starting to look like a recurring target for attacks aimed at the logistical layer rather than the funds themselves.
Not the keys. But still.
SafePal Faces Its Customers: Apologies and Promises
SafePal has apologized to its community. The company emphasizes the distinction between commercial data and critical wallet security data — a clear line, according to them, that hasn’t been crossed. Customers are encouraged to follow upcoming communications to stay informed.
That’s the official version. In reality, the question is how a third-party plugin could access so much customer information without stronger safeguards in place. The source doesn’t specify exactly which plugin is at fault or how the flaw was discovered. Not clear yet.
What is certain: SafePal says it is working to strengthen its security protocols, with more frequent audits and regular updates to its protection systems. Corrective measures have been taken since the breach was discovered. But the damage is done for the 39,798 people whose data is out there.
Thirty-nine thousand seven hundred ninety-eight. It’s not abstract.
A Sector Under Increasing Pressure
Hardware wallet manufacturers occupy a unique position in the crypto ecosystem. They are supposed to be the ultimate security layer — the physical vault that protects assets even if everything else is compromised. But their commercial operations remain vulnerable to the same flaws as any online store: customer databases, third-party plugins, logistical partners.
And that’s where it gets stuck. The funds may be safe. The users, however, are exposed — their names, addresses, crypto buyer profiles. Data that is worth something in underground markets, especially in a context where targeted attacks against wealthy crypto individuals are becoming an increasingly used strategy.
The breach at Trezor, the one at Ledger in 2020, now SafePal — the pattern repeats. The flaws don’t come from the hardware, they come from the management of customer data around the hardware. That’s probably where the sector’s next security audits should focus.
SafePal says it will release new information on its blog. The 39,798 affected customers are waiting to see.
Frequently Asked Questions
What data was exposed in the SafePal breach?
Names, email addresses, delivery addresses, phone numbers, and purchase details were compromised. Private keys, recovery phrases, banking details, and card numbers were not affected.
How many SafePal customers are affected and over what period?
39,798 customers are affected, for orders placed between March 2, 2025, and April 11, 2026. SafePal has set up a dedicated page to check if their data is part of the breach.
Which other hardware wallet manufacturers have experienced similar breaches?
Trezor recently reported a breach affecting 13,700 customers. Ledger suffered a breach in 2020 exposing approximately 272,000 customers.
Why It Matters
This data breach highlights the ongoing vulnerabilities that can exist in crypto service platforms, even when core security features like private keys and recovery phrases remain intact. The exposure of personal information raises concerns about user trust and the potential for phishing attacks, which could have broader implications for the adoption of crypto services. As the industry continues to mature, maintaining robust security protocols will be crucial for protecting customer data and ensuring confidence among users in the ecosystem.





