SafePal said a security flaw in its order-tracking system exposed the personal data of approximately 39,798 customers who made purchases between March 2, 2025 and April 11, 2026.
The leaked data included names, email addresses, phone numbers, shipping addresses and purchase details. SafePal said seed phrases, private keys, wallet passwords, payment card information and other wallet credentials were not affected, with no evidence that the breach directly compromised customer funds.
The company warned affected users to expect phishing attempts from scammers impersonating SafePal staff and offering fake firmware updates, refunds or replacement hardware wallets.
SafePal said it received the first potentially related report in early May but initially treated it as an isolated incident. Customers were publicly reporting highly targeted scam attempts by early July, while SafePal said it only recently confirmed the authorization flaw as the root cause.
The company has taken down more than 30 phishing websites and links associated with the campaign. The disclosure follows similar customer-data breaches affecting Trezor and Ledger, although in all three cases the companies said wallet private keys remained secure. $SFP