SafePal Order Data Breach Exposes 39,798 Buyers to Targeted Phishing

SafePal Order Data Breach Exposes 39,798 Buyers to Targeted Phishing

August 17, 2026

WARSAW, August 17, 2026, 08:16 CEST

  • SafePal says an order-tracking flaw exposed data for about 39,798 customers.
  • Names, contact details, shipping addresses and purchase records were accessed.
  • Wallet keys and funds were not exposed, but targeted phishing risk has increased.

SafePal disclosed that an authorization flaw exposed order information for about 39,798 customers. The crypto-wallet provider says the incident did not compromise wallet credentials or funds.

The distinction matters. Attackers gained data that can identify hardware-wallet owners, their addresses and purchases. That creates a narrow, credible path for tailored scams.

SafePal published the disclosure on Sunday and notified affected customers separately. Reuters independently reported the incident the same day.

Incident measureVerified detailStatus on August 17
Affected customersApproximately 39,798Individually notified
Orders in affected rangeMarch 2, 2025 to April 11, 2026Historical exposure window
Initial warning signalReport consistent with the issue in early May 2026Escalated into a formal investigation
Root-cause workOrder-processing review and rebuild began in JulyAuthorization flaw identified and fixed
Fraud infrastructure removedMore than 30 websites and phishing linksMonitoring continues
New retention period90 days, subject to legal requirementsIntroduced after the incident

The flaw sat in an order-tracking plug-in. Under certain conditions, it let an unauthorized party access another customer’s order record. SafePal says it fixed the defect and strengthened access controls.

“Your hardware wallets, private keys, seed phrases, and crypto assets are safe and unaffected,” SafePal says. It found no evidence that the incident itself opened wallets or funds. SafePal phishing alert and FAQ

System or data layerWhat SafePal says was accessedWhat SafePal says was not accessedPractical implication
E-commerce order trackingName, email, shipping address, phone number and purchase detailsPayment-card and bank-account informationAttackers can construct convincing order-related messages
Hardware wallet and cold storageNo access identifiedSeed phrases, private keys and wallet passwordsThe device does not need replacement solely because of this incident
Identity recordsContact and delivery dataGovernment-issued identification numbersImpersonation risk remains despite narrower data exposure
Wallet fundsNo evidence of accessCrypto assets through the incident itselfLoss becomes possible if a victim later gives credentials to a scammer

The exposed data can make a fake refund, support call or firmware notice look authentic. SafePal also warns about malicious letters, QR codes and unexpected hardware deliveries.

The investigation found a separate retention problem. A scheduled cleanup stopped working correctly between September 2025 and April 2026. SafePal says that error did not cause access, but kept older records available longer.

SafePal shortened relevant data retention to 90 days. It is engaging an independent security firm to validate the fix and review its order-processing systems. No audit result has yet been published.

User situationRecommended responseWhy it matters
Received the official affected-customer emailVerify status through SafePal’s manually typed web addressAvoids links embedded in copied or forged notices
Received an unsolicited link or QR codeDo not open or scan it; report the senderBlocks common credential-harvesting routes
Received a purported SafePal phone callHang up, record details and block the numberSafePal says employees do not initiate customer calls
Still controls all wallet credentialsDo not move assets solely because order data was exposedThe incident did not reach keys or wallet systems
Entered a seed phrase or private key after suspicious contactCreate a trusted new wallet and move remaining assets immediatelyThe old wallet must be treated as compromised

Affected customers were emailed from [email protected] on August 16. SafePal says the subject begins with “Important” and states that order information was affected. Users should still type the company address manually.

The company says official support will never request a recovery phrase, PIN or private key. It also says genuine staff will not demand an urgent firmware upgrade through a link.

Risks: SafePal’s conclusions remain company-reported, and the independent review is unfinished. Further affected records, partner exposure or financial losses could emerge as investigations continue.

The immediate danger is social engineering, not a broken cold wallet. Buyers should distrust any contact that proves knowledge of their order, then asks for a secret.

BEZ KABLI • EXTENDED COVERAGE

Further analysis

Who was affected by the SafePal incident?
SafePal says approximately 39,798 customers had order information accessed. The affected records concern orders placed from March 2, 2025 through April 11, 2026.
How can a customer check whether their data was exposed?
SafePal says it emailed affected customers from [email protected] on August 16. Customers can also check with their order number and shipping country. They should type SafePal’s address manually instead of following an unexpected link.
What information was accessed?
The exposed records included names, email addresses, shipping addresses, phone numbers and purchase details. SafePal says payment-card numbers, bank-account information and government identification numbers were not involved.
Were seed phrases, private keys or wallet funds compromised?
SafePal says no. It found no evidence that the order-tracking flaw reached wallet systems, seed phrases, private keys, passwords or funds. That conclusion remains company-reported while an independent security review is pending.
Should affected buyers replace their device or move their crypto?
Not solely because order data was exposed. SafePal says the hardware and firmware were unaffected. However, anyone who entered a seed phrase or private key after suspicious contact should create a trusted new wallet and move remaining assets immediately.
What scams should customers expect?
Attackers may use order details in fake refunds, support calls, firmware notices, text messages, letters or unexpected deliveries. SafePal says employees do not initiate customer calls and will never request a recovery phrase, PIN or private key.
Has SafePal fixed the problem?
SafePal says it fixed the authorization flaw, strengthened access controls and reduced relevant data retention to 90 days. It is engaging an independent security firm to validate the fix. No final audit result has been published.

Marcin Frąckiewicz

Marcin Frąckiewicz is the CEO of TS2 Space and a longtime technology entrepreneur focused on telecommunications, satellite communications and digital innovation. A graduate of the Warsaw School of Economics (SGH), he writes about space technology, artificial intelligence and publicly traded technology companies. His analysis covers major market trends, emerging technologies and the businesses shaping the future of the global economy.