Skip to content
The Cybersecurity Focus
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
BreachPhishingVulnerability

SafePal Data Breach Crypto Wallet Customers Exposed

By ogwatermelon
August 17, 2026 4 Min Read
0
August 17, 2026

Cryptocurrency hardware wallet provider SafePal disclosed a data breach that exposed customer order information for approximately 39,798 users. The incident involves an authorization flaw in the company’s order-tracking system, and a threat actor is now selling the stolen data on a cybercrime forum.

SafePal confirmed that names, email addresses, shipping addresses, phone numbers, and purchase details were compromised. The company emphasized that wallet seed phrases, private keys, passwords, and payment card data were not affected. SafePal notified impacted customers on August 16, 2026.

What Happened: SafePal Breach Exposes 39,798 Customer Orders to Cybercrime Forum Sale

SafePal discovered that a threat actor exploited an authorization flaw in the order-tracking function of an e-commerce plug-in. This flaw allowed unauthorized access to customer order information. The company first received a report consistent with the incident in early May 2026. However, it treated the report as an isolated case at the time.

In July 2026, SafePal began a full review and rebuild of its order-processing system. During this process, investigators identified the authorization flaw and determined that a threat actor had exploited it to steal order information for approximately 39,798 customers. Furthermore, SafePal discovered a separate configuration error that caused a data-cleanup process to stop functioning between September 2025 and April 2026. Consequently, order data was retained as far back as March 2025.

A threat actor is now claiming to sell the stolen SafePal data on a cybercrime forum. The seller referenced the same affected order period and customer count disclosed by SafePal. For potential buyers, the actor is willing to share order ID and shipping country information as proof of legitimacy.

Technical Details of the SafePal Data Breach

The breach originated from an authorization flaw in the order-tracking function of a third-party e-commerce plug-in. This flaw allowed unauthorized parties to access another customer’s order information without proper authentication.

SafePal’s e-commerce system involves multiple interconnected components, external integrations, and third-party logistics partners. Therefore, the company could not immediately rule out several possible explanations when the first report arrived in May 2026. The investigation required a full review and rebuild of the order-processing system.

In addition to the authorization flaw, a configuration error caused a data-cleanup process to stop functioning correctly between September 2025 and April 2026. This error resulted in older order data being retained longer than intended. SafePal has since purged personal data from active e-commerce servers and retained an encrypted offline copy for potential law-enforcement investigations.

Attack Timeline and Initial Reports

  • March 2, 2025 – April 11, 2026: Order data was retained due to a configuration error.
  • Early May 2026: SafePal received its first report consistent with the incident.
  • July 2026: SafePal began a full review and rebuild of the order-processing system.
  • August 16, 2026: SafePal notified all impacted customers and published a security advisory.

Stolen Data for Sale on Cybercrime Forum

A threat actor is selling the stolen data on a cybercrime forum. The seller referenced the same affected order period and customer count disclosed by SafePal. Furthermore, the actor offered to share order ID and shipping country information as proof of legitimacy.

Business and Operational Impact

The SafePal breach carries significant consequences for affected customers and the broader cryptocurrency community. Although wallet credentials were not exposed, the stolen personal information enables targeted phishing and social engineering attacks.

  • Phishing Risk: Threat actors can craft convincing phishing emails using real order details, shipping addresses, and purchase history.
  • Social Engineering: Phone calls impersonating SafePal employees can trick users into revealing seed phrases or private keys.
  • Trust Damage: SafePal is a hardware wallet provider, and any breach undermines customer confidence in physical security devices.
  • Law Enforcement: SafePal is retaining an encrypted offline copy of the data for potential law-enforcement investigations.

Mitigation and Recommendations

SafePal has taken several steps to address the breach and protect customers. However, users must also take immediate action to protect themselves from targeted attacks.

Immediate Actions for Defenders

  1. Be wary of unsolicited emails or phone calls claiming to be from SafePal, especially those requesting firmware updates or wallet recovery actions.
  2. Never share wallet seed phrases or private keys in response to any communication.
  3. Use SafePal’s online verification tool to confirm whether your order information was compromised.
  4. If you already shared seed phrases or private keys, treat your wallet as compromised and transfer assets to a new wallet on a trusted SafePal device.

SafePal Response Measures

SafePal fixed the authorization flaw and implemented additional security measures. The company is also working with a third-party security firm to validate the fix and conduct a broader review. SafePal has already taken down more than 30 fraudulent websites and phishing links tied to this incident.

Bottom line: The SafePal breach demonstrates that even hardware wallet providers are vulnerable to e-commerce system flaws. Customers should remain vigilant against targeted phishing and never share wallet credentials in response to unsolicited communications.

Incident Summary

Incident: SafePal Data Breach
Affected Customers: Approximately 39,798
Affected Period: March 2, 2025 – April 11, 2026
Exposed Data: Names, email addresses, shipping addresses, phone numbers, purchase information
Not Exposed: Wallet seed phrases, private keys, passwords, payment card numbers, government IDs
Disclosure Date: August 16, 2026
Patch Status: Authorization flaw fixed; data purged from active servers
Threat Actor Activity: Stolen data offered for sale on cybercrime forum

References

  1. BleepingComputer, “SafePal data breach impacts 39,798 customers, stolen info for sale,” August 16, 2026. https://www.bleepingcomputer.com/news/security/safepal-data-breach-impacts-39-798-customers-stolen-info-for-sale/ (accessed August 17, 2026).
  2. SafePal, “Security Update: Data Incident Notification,” August 16, 2026. https://www.safepal.com/en/blog/security-update (accessed August 17, 2026).
  3. DarkWebInformer (X/Twitter), post regarding SafePal stolen data sale, August 2026. https://x.com/darkwebinformer/status/2089052501492236328 (accessed August 17, 2026).

Tags:

BreachPhishingVulnerability
Author

ogwatermelon

Follow Me
Other Articles
Previous

Threema DDoS Attack Disrupts Secure Messaging Service

Next

Lazarus Exploits Windows Zero-Day to Deploy Troy Backdoor

AI Botnet Breach CVE Exploit Hack Incident Infostealer Linux Mac Malware Network Phishing Ransomware RCE supply chain Vishing Vulnerability Windows World Zero Day

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026

Categories

  • AI
  • BotNet
  • Breach
  • CVE
  • exploit
  • Hack
  • Incident
  • Infostealer
  • Linux
  • Mac
  • Malware
  • Phishing
  • Ransomware
  • RCE
  • supply-chain
  • Uncategorized
  • Vishing
  • Vulnerability
  • Windows
  • World
  • Zero Day
Copyright 2026 — The Cybersecurity Focus. All rights reserved.