SafePal disclosed a data breach affecting nearly 40,000 customers after an order-tracking plug-in flaw leaked names, emails, and shipping addresses. No funds or private keys were compromised, but experts warn of heightened phishing and physical risks for crypto holders.
In the high-stakes world of cryptocurrency security, a data breach that leaves private keys and funds untouched can still spell serious trouble. That is exactly what happened at SafePal, the Binance-backed maker of hardware and software crypto wallets.
On August 16, 2026, SafePal disclosed that an authorisation flaw in a third-party order-tracking plug-in exposed personal information belonging to approximately 39,798 customers. The affected records cover orders placed between March 2, 2025, and April 11, 2026. The leaked data includes names, email addresses, phone numbers, physical shipping addresses, and purchase details.
What Was Not Compromised
SafePal has been clear on one critical point: no cryptocurrency funds were lost. Seed phrases, private keys, wallet passwords, bank account information, payment card numbers, and government-issued IDs remained secure. There is no evidence that wallets themselves were accessed or drained.
For a company whose core product is the safekeeping of digital assets, this distinction is vital. The wallets held. The shopfront did not.
How the Breach Happened
The vulnerability was a classic insecure direct object reference (IDOR) flaw. Attackers could simply manipulate order numbers in the tracking system to view other customers’ order details. SafePal described it as an authorisation flaw in a third-party plug-in used for order tracking. The company says it patched the issue immediately after confirming the root cause.
SafePal received early reports consistent with the breach in May 2026 but initially treated them as isolated cases. A full investigation and rebuild of the order-processing pipeline began in July, leading to the public disclosure on August 16.
Why This Breach Hits Differently
In most industries, a leak of names and addresses is inconvenient. In crypto, it can be dangerous.
Hardware wallet buyers are, by definition, people who hold cryptocurrency outside of exchanges. A list that pairs a real name with a home address and confirms they purchased a cold wallet creates a high-value target list. The immediate risk is sophisticated phishing and impersonation attacks. Scammers already know what the customer bought and where it was shipped, making fraudulent “firmware updates,” “refunds,” or “replacement device” messages far more convincing.
The darker risk is physical. Crypto holders have increasingly faced “wrench attacks” — real-world coercion or robbery aimed at forcing victims to hand over seed phrases. Because blockchain transactions are irreversible, the incentive for such crimes is real. A clean list of confirmed crypto owners with delivery addresses is precisely the kind of data criminals seek.
SafePal’s Response
The company’s handling of the incident has been relatively swift and transparent by industry standards. Steps taken include:
- Immediate patching of the vulnerability
- Email notifications to all affected customers from security@safepal.com
- Hiring of an independent third-party security auditor
- Reduction of personal data retention in the order system to 90 days
- Identification and removal of more than 30 fraudulent websites and phishing links
- Launch of a verification tool allowing customers to check whether their order was affected
SafePal has also warned users to be extremely cautious of any unsolicited communications claiming to be from the company.
Broader Lessons for Crypto Users
This incident follows a familiar pattern seen across the industry: the core product holds, but a third-party integration fails. Similar issues have appeared in other high-profile breaches where the main system remained secure while an accessory or plug-in became the entry point.
For crypto users, the takeaway is clear. Operational security extends beyond seed phrases and hardware devices. Physical privacy matters. Using a P.O. box or alternative shipping address for hardware wallet purchases, enabling strong email filters, and remaining skeptical of any unexpected contact from wallet providers are practical steps that now carry extra weight.
SafePal deserves credit for keeping customer funds safe and for a relatively clean response. Yet the episode underscores an uncomfortable reality: in crypto, privacy is not a secondary feature. For those whose names and home addresses are now circulating, it is inseparable from security itself.
Also read: Top 5 Cryptocurrencies Dominating the Global Market in 2026: Bitcoin, Ethereum, Binance Coin & More






