SafePal Discloses Breach Hitting Nearly 40,000 Wallet Customers

A flaw in the crypto hardware wallet maker's systems exposed order records for 39,798 buyers, and a criminal is now advertising the stolen data for sale.

ThreatVectr Newsdesk· 3 min read
Photoreal editorial image, full frame 16:9, of a dimly lit call centre workstation at night: a headset resting on a keyboard, a blurred screen showing an abstra
Share

Key points

  • SafePal, a maker of hardware wallets for cryptocurrency, told customers a flaw in its systems was used to steal order information for around 39,798 people.
  • The stolen records include names, shipping addresses, phone numbers, email addresses and details of what each person ordered.
  • A criminal is now advertising the data for sale on an underground forum, first reported by BleepingComputer.
  • SafePal says wallet secrets, the private codes that control the crypto itself, were not touched.
  • Affected customers are being warned to expect targeted phishing attempts and fake support messages.

SafePal, a company that sells small physical devices used to store cryptocurrency offline, has told customers that criminals stole records tied to roughly 39,798 orders. Hardware wallets are marketed as one of the safest ways to hold digital coins, which makes any leak of buyer information especially sensitive.

The company says an attacker found and used a flaw in one of its systems to pull down order data. Wallet secrets, meaning the private recovery phrases that unlock the coins themselves, sit only on the device in a customer's hand and were not part of what was taken.

What was taken is still a serious problem for the people on the list.

What data was stolen?

The stolen records cover customer order details rather than crypto keys. According to SafePal's notice, the exposed fields include full names, shipping addresses, phone numbers, email addresses and the specific products ordered.

That is the exact information a scammer needs to send a convincing fake package notice, a fake "firmware update required" email, or a phone call pretending to be SafePal support. Anyone who has bought a hardware wallet is, by definition, someone with cryptocurrency worth protecting. The buyer list is valuable on its own.

Detail Figure
Customers affected ~39,798
Data type Order and shipping details
Wallet keys exposed None
Status of data Advertised for sale on a criminal forum

Who is behind it?

Attribution here is thin. A user on a well-known cybercrime forum is offering the database for sale, but that alone tells us little: brokers routinely resell data they did not steal, and forum handles rotate.

Crypto firms have been a steady target for financially motivated crews for years, including groups tracked as UNC4899 and TraderTraitor by Mandiant and the FBI respectively, both linked with medium to high confidence to North Korea. There is no public evidence tying this particular SafePal intrusion to a named cluster. I would treat any claim otherwise as low confidence for now.

Capability and intent are different questions. Whoever pulled the records may simply flip the list to phishing crews who will do the follow-on work.

Should customers be worried?

Yes, but in a specific way. The risk is not that someone empties your wallet remotely using this data. The risk is that someone contacts you, pretending to be SafePal, and tricks you into typing your recovery phrase into a fake site or app.

A few practical steps:

  • Treat any email, text or call claiming to be from SafePal with suspicion, especially anything urgent about your order, shipping, or a "security update".
  • Never type your recovery phrase into a website, a chat, or a support form. A legitimate wallet maker will never ask for it.
  • If a package arrives that you did not order, do not plug it in. Physical wallet swaps have been used against crypto holders before.
  • Turn on two-factor authentication on any exchange accounts linked to the same email address.

SafePal has not published a full technical account of the flaw or said when it was closed. The company says the underlying issue has been fixed and that affected customers are being notified directly.

© 2026 Threat Vectr