SafePal hit by data breach exposing 39,798 customers

A cryptocurrency hardware wallet maker has disclosed a data breach impacting nearly 40,000 customers after attackers exploited a software flaw to steal order details—and now the stolen data is being advertised for sale online.
SafePal revealed that an unspecified vulnerability allowed threat actors to access customer order information, including names, physical addresses, phone numbers, email addresses, and partial payment details. The company emphasized that no wallet recovery phrases, private keys, or passwords were compromised, and it has since patched the flaw. However, the breached dataset has reportedly surfaced on a dark-web marketplace, raising concerns about potential phishing and identity theft campaigns.
A flaw in the supply chain
The security incident traces back to a weakness in SafePal’s order-processing pipeline rather than a direct intrusion into its wallet software. While the company did not detail the exact nature of the flaw, the fact that order data—often stored separately from core wallet databases—was still accessible suggests gaps in segmentation or access controls. Such breaches underscore the risks of third-party integrations and the need for layered defenses even in non-core systems.
What’s at stake for users
For SafePal customers, the immediate risk is elevated spam, phishing emails, or targeted social-engineering attempts using their exposed personal data. Although cryptocurrency funds stored on SafePal devices remain secure, attackers could leverage the stolen information to impersonate support agents or trick victims into revealing additional credentials. The company has urged users to enable two-factor authentication and monitor accounts for unusual activity, standard advice in the wake of any data leak.
Why it matters
This breach highlights how even hardware wallet providers—whose primary selling point is security—must treat customer data with the same rigor as private keys. A flaw in seemingly peripheral systems can still have real-world consequences, from identity theft to reputational damage. For the broader crypto ecosystem, it serves as a reminder that convenience and security must evolve in lockstep, especially as hardware wallets integrate more cloud services and third-party services.
Source: BleepingComputer. AI-assisted editorial synthesis — TechnoExpress.

