Community Trust ScoreVerified
A plugin broke. Nearly 40,000 people paid for it.
SafePal, the Seychelles-based hardware wallet maker, confirmed a data breach affecting 39,798 customers after a faulty order-tracking plugin leaked sensitive personal information over a span stretching from March 2, 2025, to April 11, 2026. Names, email addresses, shipping addresses, phone numbers, and purchase details all got exposed. Wallet security — seed phrases, private keys — was not touched. But the rest of it? Pretty much wide open for over a year.
The company says it’s fixed the plugin flaw now.
What the Plugin Actually Leaked
The breach came through a third-party plugin SafePal used to track customer orders. Unauthorized individuals got into that system and pulled personal data. The company didn’t name the plugin or explain exactly how the access happened — no details on that front. What SafePal did confirm is the scope: close to 40,000 customers, a long window of exposure, and the kind of data that makes phishing campaigns trivially easy to run.
SafePal warned customers directly about the phishing risk. Fraudulent emails, fake websites, deceptive messages designed to pull wallet credentials out of people who already handed over their home addresses — that’s the threat model here. And it’s not a small one. Shipping addresses combined with purchase records tell a bad actor exactly who bought a hardware wallet and where they live. That’s a specific, actionable list.
Security researcher Tay flagged that the exposure goes beyond phishing. Physical data like shipping addresses opens the door to targeted, real-world attacks on people known to hold crypto. The concern isn’t hypothetical — France has seen a wave of so-called wrench attacks, where cryptocurrency holders are physically targeted at home. Exposed customer databases make those attacks easier to plan and execute.
The Disclosure Delay Problem
Here’s where it gets messy. Another researcher, Specter, pointed out that phishing reports tied to this breach started coming in as early as April. SafePal apparently sat on the public disclosure until August. That’s months of customers receiving suspicious messages with no warning from the company that their data was already out there.
That gap is a real problem. Affected users had no way to know they were being targeted using their own leaked information. Some of them probably clicked things they shouldn’t have. And SafePal, by all accounts, knew something was wrong before it told anyone.
One affected customer went public with a specific complaint: his data had already been deleted before the breach disclosure came out. That’s not a minor detail. It raises questions about whether SafePal’s data retention practices were consistent, and whether the 90-day retention window the company now claims to have adopted was actually in place when it mattered.
SafePal says it has since reduced data retention to 90 days and taken down 30 websites connected to scams targeting its users. Thirty sites. That number alone tells you the phishing infrastructure built around this breach was already substantial by the time the company went public.
Trezor’s Shipmonk Breach and a Wider Pattern
SafePal isn’t alone in this. Trezor went through something similar when its shipping provider, Shipmonk, suffered a breach that compromised customer data across multiple countries. Two of the most recognized names in hardware wallets, both hit through their logistics and operational supply chains rather than through their core security products.
That’s the pattern worth watching. The wallets themselves hold up. The seed phrases stay safe. But the companies around the wallets — the plugins, the shipping partners, the order-tracking services — those are the weak links. And they’re holding data that’s arguably more dangerous in some ways, because it connects a crypto purchase to a physical person at a physical address.
The industry keeps running into this. Better hardware security doesn’t help if a third-party plugin is quietly vacuuming up customer records for fourteen months.
SafePal hasn’t said what additional security measures it’s planning beyond the plugin fix, the retention change, and the takedowns. No timeline on further disclosures. No comment on whether it’s auditing other third-party integrations. Unclear whether affected customers will get any direct support beyond the warning to watch for phishing.
Thirty scam sites dismantled, 39,798 people still waiting to see what comes next.
Frequently Asked Questions
What personal data did the SafePal breach expose?
The breach exposed names, email addresses, shipping addresses, phone numbers, and purchase details for 39,798 customers. Seed phrases and private keys were not compromised.
How did SafePal respond to the breach?
SafePal fixed the faulty order-tracking plugin, cut its data retention period to 90 days, and took down 30 scam websites targeting its users.
How long did the SafePal data breach last?
The breach ran from March 2, 2025, to April 11, 2026 — over a year of unauthorized access through the compromised plugin.
Why It Matters
This data breach highlights ongoing vulnerabilities in the crypto hardware wallet sector, where customer trust is paramount. As security incidents can directly impact consumer confidence in digital asset management solutions, this leak may deter potential users from adopting hardware wallets, ultimately affecting market growth and the reputation of crypto security providers. Moreover, the exposure of personal information raises concerns about user privacy and the potential for targeted phishing attacks, which could further undermine the integrity of the broader cryptocurrency ecosystem.