Hardware wallet manufacturer SafePal has disclosed a security breach involving an authorization flaw that exposed the personal contact and shipping information of approximately 39,798 customers.
Key Points
- The breach exposed names, email addresses, phone numbers, and shipping details for orders placed between March 2, 2025, and April 11, 2026.
- SafePal confirmed that no wallet credentials, private keys, seed phrases, or financial payment information were compromised during the incident.
- A configuration error in a data-cleanup process inadvertently extended the period that older order records remained accessible in the system.
- The company has implemented a 90-day data retention policy and engaged a third-party security firm to audit its order-processing infrastructure.
- A dataset matching the affected customer count and order window has appeared on a cybercrime forum, prompting warnings about potential phishing and physical security risks.