Crypto hardware wallet maker SafePal has disclosed a data breach that exposed the order information of approximately 39,798 customers, the result of an authorization flaw in a third-party plugin the company used to let customers track their shipments.
The flaw worked similarly to a package-tracking system with no access controls: changing the order number in a request let one customer view another customer’s receipt and delivery details. The exposure covered orders placed between March 2, 2025 and April 11, 2026, and the leaked information included customer names, email addresses, shipping addresses, phone numbers and purchase-related details.
What Wasn't Exposed
SafePal said in an official security update posted to its blog that seed phrases, private keys, wallet passwords, payment information and government-issued identification were not affected, and that the company found no evidence attackers gained access to any customer’s cryptocurrency wallet or funds. For a hardware wallet manufacturer, that distinction is the difference between a serious inconvenience and a fund-draining catastrophe — the exposed data could still expose affected customers to targeted phishing attempts, but not direct asset theft through the flaw itself.
Response and Notification
The company said it has patched the vulnerability, launched additional security measures, and notified all affected customers individually by email. SafePal also said it engaged an independent third-party security firm to audit the fix and review its broader order-processing methods going forward.
Related: DefiLlama Delayed Its App Launch to Wait Out Apple Store Impostors
A Recurring Risk for Hardware Wallet Makers
The incident is a reminder that crypto hardware wallet companies carry two distinct categories of security risk: the cryptographic integrity of the device itself, and the mundane e-commerce infrastructure — order tracking, shipping, customer support tooling — sitting around it. SafePal’s core wallet security doesn’t appear to have been compromised, but the breach still hands attackers a list of real names and shipping addresses tied to confirmed hardware wallet ownership, information that has previously been used elsewhere in the industry to target victims with fake support calls or phishing emails referencing their actual order details.