Hardware wallet provider SafePal disclosed on August 16, 2026 Sunday that an authorization flaw in an order-tracking plugin exposed order information belonging to approximately 39,798 customers, though the company says wallet access, funds, and seed phrases were not affected.
What Was Exposed, and What Wasn’t
The exposed data included names, email addresses, shipping addresses, phone numbers, and purchase details for customers who placed orders between March 2, 2025 and April 11, 2026.
SafePal said seed phrases, private keys, wallet passwords, payment card numbers, bank account information, and government-issued identification numbers were not exposed, and it found no evidence the incident compromised wallet access or funds directly.
The company notified affected customers individually by email from security@safepal.com and published a verification tool that lets customers check their status using an order ID and shipping country.
The flaw itself involved an authorization defect in a plugin used to track customer orders, which under certain conditions allowed one customer to view another customer’s order information, similar to a store’s parcel-tracking system letting someone view another customer’s receipt just by changing the order number.
A separate issue expanded the affected period due to a scheduled data-cleanup process that stopped working correctly between September 2025 and April 2026 due to a configuration error, and while that failure did not cause the unauthorized access itself, it left older order records stored well past when they should have been deleted, extending the affected range back to March 2025.
A Detection Gap Worth Understanding
SafePal’s own incident FAQ describes a longer timeline than the headline breach date suggests. The company first received a phishing report consistent with this issue back in early May, but initially treated it as an isolated case rather than escalating it immediately.
It was not until July, during a full review and rebuild of its order-processing pipeline, that SafePal confirmed the underlying plugin flaw.
Why This Matters Even Without Wallet Compromise
The real risk from this specific incident is phishing, not direct fund theft. Attackers now have genuine names, addresses, phone numbers, and purchase details for affected customers, which can make follow-up phishing attempts, fraudulent calls, fake customer-support messages, refund offers, or firmware-update requests considerably more convincing than a generic scam attempt.
SafePal has already identified and removed more than 30 fraudulent websites and phishing links tied to this specific incident and says it continues monitoring for new ones.
This is the second notable hardware wallet security story in recent weeks. Our earlier coverage of the Coldcard firmware vulnerability covered a separate incident in which an attacker reportedly stole at least $120 million in Bitcoin through a randomness-generation flaw.
Moreover, a separate, similarly structured breach recently exposed shipping information for 13,689 Trezor customers, and scammers have separately mailed fake Trezor and Ledger letters containing QR codes designed to steal recovery phrases.
What Comes Next
SafePal said it is engaging an independent third-party security firm to validate its fix and conduct a broader review of its order-processing systems, though it has not named the firm publicly yet.
The company has also reduced personal data retention in its order-processing environment to 90 days going forward and says it is contacting on-chain asset-tracing specialists to help customers who report financial losses tied to follow-on phishing, while explicitly stating this does not represent an admission of liability or a commitment to compensation.
What this means for you: You don’t need to move your existing assets solely because your order information was exposed, but if you have ever entered your seed phrase or private key into a suspicious website or message, treat that wallet as compromised immediately and move your funds to a newly created wallet through an official SafePal device or app.
Our guide to common wallet security mistakes covers more on protecting yourself from this exact kind of follow-on phishing attempt.







