SafePal confirmed that the following information was accessible to attackers during the exposure window :
SafePal explicitly stated that the following sensitive data was not accessed, as the company never collects or stores such information from customers :
The company also confirmed that no evidence was found suggesting the incident compromised access to SafePal wallets or funds .
SafePal identified an authorization flaw in its order-tracking plugin — a component used to monitor customer orders . This vulnerability allowed the plugin to let one customer view another customer's order data without proper authorization
. The issue was fixed after discovery, and SafePal stated that additional security measures have been implemented
.
The breach spanned orders placed over approximately 13 months, from March 2, 2025, to April 11, 2026 . SafePal disclosed the incident via an X post and a security update on its official blog on August 16, 2026
.
While SafePal's wallets and funds remained secure, the exposed data set is highly attractive for cybercriminals. Verified names, physical addresses, and purchase history provide ideal fuel for targeted phishing, impersonation, and identity theft attempts .
SafePal warned affected users to remain vigilant against phishing and impersonation attempts . Industry observers noted that over 30 phishing sites had been linked to the breach
. The risk is especially acute because the data confirms the victim owns a specific hardware wallet model, including its delivery address, enabling highly convincing scams.
SafePal notified affected customers via email and provided an official verification page where customers can check their status using their order number and shipping country .
The SafePal breach is the third major data exposure in the hardware wallet industry within roughly a week and echoes the pattern of the massive 2020 Ledger leak.
Volume: The 2020 Ledger leak was far larger (1M emails vs. 40K for SafePal and ~14K for Trezor), and its data was actively dumped on a hacking forum, leading to years of sustained phishing attacks .
Attack vector: Each breach had a different origin — Ledger's was an API key compromise; Trezor's was a third-party logistics provider breach; SafePal's was an authorization flaw in its own internal plugin .
What remained safe across all three incidents: In every case, seed phrases, private keys, and wallet funds were not compromised, and no stolen cryptocurrency was directly linked to any of the breaches .
Combined impact: The three-day window between Trezor (Aug 13) and SafePal (Aug 16) breaches placed over 53,000 hardware wallet customer records into the open, amplifying overall phishing risk for the crypto community .