SafePal Leak Exposes ~40,000 Customers — Hardware Wallet Drama Escalates
Okay, horror-movie plot twist: a hardware-wallet company that’s supposed to keep your crypto safe accidentally left a chunk of customer info wide open. SafePal announced a security incident that put roughly 40,000 customer records on the table — not private keys, but enough to make phishing scammers and pesky stalkers raise an eyebrow.
What went down
On Aug. 16 SafePal disclosed that an authorization bug in its order-tracking system let unauthorized parties access order records. The snag affected purchases made between March 2, 2025 and April 11, 2026. Exposed fields reportedly included customer names, emails, shipping addresses, phone numbers, and order details — the kind of info scammers love for impersonation and targeted attacks.
Before you panic: SafePal says sensitive wallet secrets were not leaked. Private keys, recovery phrases, wallet passwords, payment card numbers, and direct wallet access were not part of the exposed data, and the company found no sign that the flaw was used to steal crypto from wallets.
But wait, there’s a sequel. A separate configuration mistake disabled a scheduled cleanup process between September 2025 and April 2026, which meant older orders stuck around much longer than they should have. That retention screw-up widened the window of records available through the authorization hole and pushed the affected dataset back to March 2025.
This incident didn’t happen in a vacuum. Other hardware-wallet vendors have had trouble lately — shipping-provider leaks and third-party payment blunders have spilled customer info, and a catastrophic bug at another company allowed attackers to siphon more than $100 million in Bitcoin. In short: it’s been a bad few months for folks who thought hardware wallets were a drama-free fortress.
Why you should care (and what to do)
Exposed names, phones, emails and home addresses don’t directly pull crypto out of your wallet, but they fuel scams, social engineering, and even physical threats. Law enforcement and research groups have warned that violent “wrench” attacks, home invasions and kidnappings targeting crypto holders are on the rise — recent data pointed to millions in theft from such incidents and a worrying share of violent attacks tied to crypto ownership.
If your info might be in the leak, don’t freak out — but do get proactive. Basic steps that help: be extra suspicious of unsolicited messages or calls, double-check URLs before visiting, avoid clicking links from unknown senders, and report phishing sites to the company’s official support channels. Consider changing passwords and enabling two-factor authentication where possible. If you’re worried about someone knowing you own a hardware wallet, think about alternate shipping methods (PO boxes, work addresses) for future orders.
For hardware-wallet users, remember that the device and the surrounding services are separate things — a hardware wallet can keep keys offline, but account systems, shipping partners, and support databases are all attack surfaces too. Keep firmware up to date, follow official security advisories from your device maker, and treat any unexpected outreach claiming to be from vendor support with extreme skepticism.
Finally: companies should be held to cleanup schedules and tested access controls. For users, the takeaway is the same as always — protect your seed phrase, stay alert for scams, and don’t assume that a physical device alone solves every security problem.
