Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
SafePal disclosed a data breach on August 16, 2026, exposing order details for 39,798 customers. The incident, caused by an authorization flaw in a shipping-tracking plugin combined with a data-retention configuration error, did not compromise seed phrases or funds. However, it exposed names, addresses, phone numbers, and purchase details — information that becomes a target for physical phishing and targeted extortion on cybercrime forums.
- SafePal confirmed the exposure of order data for 39,798 customers, for purchases made between March 2, 2025 and April 11, 2026.
- The cause was an authorization flaw in the order-tracking plugin, paired with a configuration error that extended data retention from September 2025 through April 2026.
- A threat actor is selling the data on a cybercrime forum, offering order IDs and shipping countries as proof; the post includes the direct quote "Not interested in low balls."
- Seed phrases, private keys, wallet passwords, banking data, and government IDs were not compromised; SafePal has taken down over 30 fraudulent sites and engaged a third-party security firm.
"This incident did not involve your seed phrase, private keys, wallet password, or other wallet credentials, bank account information, payment card numbers, or government-issued identification numbers" — SafePal, official security advisory
The Mechanism: IDOR-Like Flaw in a Tracking Plugin
SafePal's official advisory identifies the technical root cause: an authorization flaw in the order-tracking function of a plugin integrated into the e-commerce system. The vulnerability allowed unauthorized access to other customers' order data, presumably through manipulation of the order number — a pattern consistent with Insecure Direct Object Reference (IDOR), though SafePal does not explicitly use that classification.
The problem was compounded by a configuration error in the data-cleanup process. According to the primary source, the automated data-removal process "had stopped working correctly between September 2025 and April 2026." This extended the exposure window beyond the originally intended period, accumulating order data through April 11, 2026 instead of limiting it to orders before September 2025.
SafePal received the first report consistent with the incident in early May 2026, but "treated it as an isolated case at the time." The escalation to a formal security investigation came later, with the launch of a "full review and rebuild" of the order-processing system in July 2026. The imprecision in the timeline between initial detection and structured response emerges as a critical point in incident management.
From Forum to Sale: The Market for Physical Data
BleepingComputer reported the presence of a threat actor on a cybercrime forum selling the stolen data, offering order IDs and shipping countries as verification of possession. The post includes the direct quote: "Not interested in low balls, please come correct and with a good price or do not message me at all." The outlet did not independently verify the actual sale or the transaction value.
The value of this data exceeds that of generic dumps because it precisely identifies who owns a crypto hardware wallet and where they reside. The shipping address, combined with name, phone number, and purchase details, constitutes a high-resolution profile for social engineering attacks, personalized phishing, or, in extreme cases, physical extortion attempts. SafePal confirmed that customers received phishing emails and calls as early as May 2026, three months before the official disclosure.
The case fits a broader pattern: in the week preceding the SafePal notification, Trezor (via compromise of logistics provider ShipMonk) and Coldcard also suffered supply-chain incidents exposing customer order data. The hardware wallet sector, built on the promise of physical security and fund isolation, shows a systemic fragility in the commercial infrastructure surrounding the product.
The Take: The Hardware Security Paradox
SafePal's architecture is designed for air-gap: the device never connects to the internet, keys never leave the secure chip, transactions are signed offline. This technical robustness held — funds were not compromised. But product security did not protect the commercial perimeter, and the commercial perimeter revealed the very existence of the product in the user's hands.
The comparison with Ledger 2020 is stark. When that competitor suffered a breach exposing names, addresses, and phone numbers of 270,000 customers, the impact translated into waves of physical phishing and direct threats. Hardware wallet order data is not innocuous commercial metadata: it is tactical intelligence telling an attacker who has something to protect and where to find them.
SafePal responded by reducing the retention period to 90 days, taking down over 30 fraudulent sites, and engaging a third-party security firm to validate the fix and conduct a broader review. The name of the security firm has not been made public. It remains unspecified whether the flaw was discovered internally or via external report, nor the exact date of the first unauthorized access.
What to Do Now
- Check whether your account is affected using the official tool published by SafePal, verifying the site address to avoid phishing on the verification channels themselves.
- Treat any communication requesting wallet information, seed phrases, or software updates as suspicious, regardless of whether the message contains correct personal data.
- Report fraudulent sites and phishing attempts to SafePal through the official channels indicated in the advisory, to fuel the takedown of malicious domains.
- Consider using alternative shipping addresses (P.O. boxes, forwarding services) for future orders of security devices, reducing exposure of your residential address.
Why the Industry Cannot Ignore the E-Commerce Supply Chain
The third hardware wallet breach in a week is not coincidence: it is a symptom that the industry has underestimated the commercial attack surface. Vendors invest in chip certifications, secure elements, and firmware audits, but entrust shipping, tracking, and customer data to third-party ecosystems with less rigorous controls.
SafePal has fixed the flaw and reduced retention, but the question reverberates across the sector: how many other tracking plugins, payment gateways, and logistics integrations host similar authorization flaws? The wallet can be as air-gapped as you like; if buying the wallet exposes the user, product security remains incomplete.
The dossier does not specify whether the forum sale is ongoing or whether confirmed financial losses have been recorded for affected customers. The identity of the threat actor and the number of attackers involved remain unknown.
Information verified against cited sources and current as of publication.
Sources
- https://www.bleepingcomputer.com/news/security/safepal-data-breach-impacts-39-798-customers-stolen-info-for-sale/
- https://www.coindesk.com/tech/2026/08/16/crypto-wallet-safepal-reveals-a-data-breach-exposing-nearly-40-000-customers-order-info
- https://www.theblock.co/news/business/2026-08-16-wallet-provider-safepal-says-data-breach-exposed-personal-info-of-nearly-40000-customers-411934
- https://www.cryptotimes.io/2026/08/16/binance-backed-safepal-data-leak-sparks-phishing-fears-for-40k-buyers/
- https://www.hokanews.com/2026/08/safepal-data-breach-exposes-information.html
- https://wiz.io/lp/ai-threat-readiness-101?utm_source=bleepingcomputer&utm_medium=display&utm_campaign=FY27Q2_INB_FORM_AI-Threat-Readiness-Infographic&sfcid=701Vh00000delRcIAI&utm_term=FY27-bleepingcomputer-article-970x250-August&utm_content=AITR-Infographic
- https://www.safepal.com/en/blog/security-update
- https://www.safepal.com/en/scam-protection
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.