Skip to content
feed: live
>_0dayNews
threat intel
● Breaking

SafePal Breach: 39,798 Customers' Order Data for Sale

SafePal warns ~39,798 customers their order data was stolen via an exploited flaw. A threat actor is now selling the records. Hardware wallets unaffected.

SafePal Breach: 39,798 Customers' Order Data for Sale
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
airgapMorgan "airgap" Reyes·Published ·2 min read

Confirmed: SafePal, a cryptocurrency hardware wallet provider, is warning approximately 39,798 customers that their order information was stolen following exploitation of a flaw in company systems. A threat actor is actively claiming to sell the stolen data. Source: BleepingComputer, 2026-08-16.

Confirmed: ~39,798 customers affected. Order information stolen. SafePal has issued customer notifications. Stolen data now listed for sale by a threat actor.

Unconfirmed — treat accordingly: The specific vulnerability class exploited. The precise data fields in the stolen set beyond “order information.” Threat actor identity. When the breach occurred and how long unauthorized access persisted.

Critical distinction for SafePal device owners: This is not a wallet compromise. SafePal hardware wallets store private keys locally on the device — a breach of order and customer data systems does not expose those keys or on-chain funds. If you hold cryptocurrency in a SafePal hardware wallet, your on-chain assets are not at risk from this specific incident.

What’s exposed: Customer order records. The exact field set hasn’t been published; order databases typically contain names, shipping addresses, purchase history, and contact details. Intersection with credentials used elsewhere, or with other crypto service accounts, expands the risk surface.

For affected SafePal customers:

  • Watch for phishing targeting SafePal owners specifically — verified crypto hardware wallet buyers are a high-value phishing demographic.
  • Be alert to SIM-swap attempts if phone numbers are in the breached dataset.
  • If the same email and password were used for SafePal as for exchange accounts or other crypto services, rotate those credentials now.
  • SafePal’s official channels are the authoritative source on breach scope and remediation — do not rely on unofficial summaries.

Analysis (speculative — no attribution evidence at publication): Crypto hardware wallet company order databases are a recurring target. The payload is the customer list — verified crypto holders with physical shipping addresses and purchase history. A 39,798-record scope is modest by volume; data quality over quantity is the likely objective, consistent with commercially motivated actors. No evidence linking this to a known APT. Attribution unknown — treat accordingly.

This follows Trezor’s breach via shipping partner ShipMonk in August, which exposed 14,000 customers through a supply-chain compromise. The reported vector here appears direct rather than third-party — but specifics remain unconfirmed as of publication.

Found this useful? Share it.