SafePal says plug-in flaw exposed data of nearly 40,000 customers
The company said the breach did not compromise wallet credentials or financial information.
Crypto wallet provider SafePal said an issue with a third-party order-tracking plug-in resulted in unauthorized access to customer data and warned affected users to stay vigilant against phishing and impersonation attempts.
The breach, which was disclosed on Aug. 16, affected about 39,798 customers who made purchases between March 2, 2025 and April 11, 2026. Information that may have been exposed includes customers’ names, email addresses, phone numbers, shipping addresses and purchase details.
SafePal said there was no access to seed phrases, private keys, wallet passwords or other wallet credentials.
Dear community,
While your SafePal wallet, seed phrase, and private keys are secure; we identified a flaw in the order-tracking plug-in that led to unauthorized access to information of a subset of customers.
The issue has been fixed with additional security measures…
— SafePal – Crypto Wallet (@SafePal) August 16, 2026
The company added bank account information, payment card numbers and government-issued IDs were not exposed. SafePal has since fixed the underlying flaw and implemented additional security controls.
Affected customers have been notified by email and can use their order ID and shipping country to determine whether they were affected. The company is also urging users to watch for phishing or impersonation attempts, as attackers could potentially use the leaked customer information to make targeted scams appear legitimate.
The news moving money, markets, and the world—before your day starts.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
The incident is the latest customer-data breach involving a major hardware wallet brand, following Trezor’s disclosure of a breach at ShipMonk, its shipping provider.
Trezor said ShipMonk was hit by a data breach that exposed order information for 13,689 customers across the US, UK, Sweden, Colombia, Brazil, Italy and Portugal.
The affected customers received orders between May 10 and Aug. 8, 2026, with exposed information including names, email addresses, phone numbers and shipping details.