HackMyIP
← Back to News
2026-08-18 The Hacker News

SafePal Data Breach Exposes 39,798 Customers via Order-Tracking Flaw

Data BreachVulnerabilityPrivacy

Hardware wallet manufacturer SafePal has disclosed a data breach affecting nearly 40,000 customers, triggered by an authorization flaw in a third-party order-tracking plug-in used by the company. According to a notice issued on August 16 from security@safepal.com, the vulnerability exposed names, email addresses, shipping addresses, phone numbers, and purchase details for approximately 39,798 customers whose orders were placed between March 2, 2025, and April 11, 2026. SafePal has not publicly named the affected plug-in, its vendor, or the version impacted, and no CVE identifier has been assigned to the issue. Affected users can verify whether their personal email was exposed using our email breach checker to cross-reference known incidents.

The company stressed that the exposed records did not include seed phrases, private keys, wallet passwords, bank account information, payment card numbers, or government-issued IDs, and stated it found no evidence that wallet access or funds were compromised. However, the combination of a named individual, home address, and purchase history creates a credible phishing and social-engineering risk. Separately, SafePal revealed that a scheduled data-cleanup process had silently failed between September 2025 and April 2026 due to a configuration error, allowing older order records to persist in the system longer than intended; the company clarified this retention bug did not cause the unauthorized access but explains why the breach window stretches back to March 2025.

SafePal warned customers to treat any unsolicited contact referencing their SafePal purchase as suspect, including fraudulent phone calls, spoofed emails, text messages, refund offers, firmware-update requests, and fake customer-support communications potentially delivered by phone, mail, or in person. Given the scale of the exposure, users should also run a privacy checkup to identify other accounts or services linked to the same contact details, and verify the strength of any reused credentials with our password checker. The disclosure comes three days after Trezor reported a separate breach at shipping provider ShipMonk, which Trezor said was contained by a pre-existing 90-day data-storage policy.

In related industry context, blockchain analytics firm Chainalysis reported 46 violent incidents targeting crypto holders globally through late June, with over $30 million stolen and a success rate of just 26% (12 of 46), down from 49% in 2025. French cases in particular jumped from a handful before 2025 to 30 by mid-2026, a trend Chainalysis attributed to criminals exploiting stolen tax records to identify crypto holders. "Criminals have recognized that crypto holders are high-value targets because they possess wealth in an instantly and irreversibly transferrable form," the firm noted, underscoring why even non-financial personal data, like that leaked in the SafePal incident, remains valuable to attackers.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →