SafePal Discloses Breach Hitting Nearly 40,000 Wallet Customers
A flaw in the crypto hardware wallet maker's systems exposed order records for 39,798 buyers, and a criminal is now advertising the stolen data for sale.

Key points - SafePal, a maker of hardware wallets for cryptocurrency, told customers a flaw in its systems was used to steal order information for around 39,798 people. - The stolen records include names, shipping addresses, phone numbers and email addresses, along with details of what each person ordered. - BleepingComputer first reported that a criminal is now advertising the data for sale on an underground forum. - SafePal says wallet secrets, the private codes that control the crypto itself, were not touched. - Affected customers are being warned to expect targeted phishing attempts and fake support messages.
SafePal, a company that sells small physical devices used to store cryptocurrency offline, has told customers that criminals stole records tied to roughly 39,798 orders. Hardware wallets are marketed as one of the safest ways to hold digital coins, which makes any leak of buyer information especially sensitive.
The company says an attacker found and exploited a flaw in one of its systems to pull down order data. Recovery phrases, the codes that unlock the coins themselves, sit only on the device in a customer's hand and were not part of what was taken.
What was taken is still a serious problem for the people on that list.
What data was stolen?
The stolen records cover customer order details rather than crypto keys. SafePal's notice says the exposed fields include full names, shipping addresses, phone numbers, email addresses and the specific products ordered.
That's the exact information a scammer needs to send a convincing fake package notice, a fake "firmware update required" email, or a call pretending to be SafePal support. Anyone who bought a hardware wallet is, by definition, someone with cryptocurrency worth protecting. The buyer list is valuable on its own.
| Detail | Figure |
|---|---|
| Customers affected | ~39,798 |
| Data type | Order and shipping details |
| Wallet keys exposed | None |
| Status of data | Advertised for sale on a criminal forum |
Who is behind it?
Attribution here is thin. There's no public evidence tying this intrusion to a named threat cluster. Treat any claim otherwise as low confidence for now.
Capability and intent are different questions. Whoever pulled the records may simply flip the list to phishing crews who handle the follow-on work. Crypto firms have been a steady target for financially motivated actors for years, and hardware wallet buyers are a particularly attractive subset of that pool.
This breach is three times the size of the Trezor ShipMonk incident we covered on 13 August, where roughly 13,700 buyer records leaked through a third-party logistics partner. The attack surface is consistent: shipping data doesn't require breaching the wallet itself.
Should customers be worried?
Yes, but in a specific way. Someone can't empty your wallet remotely using this data. What they can do is contact you, pretend to be SafePal, and trick you into typing your recovery phrase into a fake site or app.
A few practical steps:
- Treat any email or call claiming to be from SafePal with suspicion, especially anything urgent about your order or a "security update".
- Never type your recovery phrase into a website or a support form. A legitimate wallet maker will never ask for it.
- If a package arrives that you didn't order, don't plug it in. Physical wallet swaps have been used against crypto holders before.
- Turn on two-factor authentication on any exchange accounts linked to the same email address.
SafePal hasn't published a full technical account of the flaw or confirmed when it was closed. The company says the underlying issue has been fixed and that affected customers are being notified directly.



