Crypto wallet SafePal hit with personal data breach, nearly 40,000 customers affected

Recently, multiple cryptocurrency wallet providers have reported data breach incidents. The crypto wallet provider SafePal, which was once invested in by Binance, confirmed in a public announcement yesterday (8/16) that a plug-in used to track customer orders had an authorization vulnerability, allowing unauthorized parties to access certain customers’ personal data.

According to an internal investigation, the affected parties were customers who placed orders on the SafePal official website during the period from March 2, 2025, to April 11, 2026. A total of 39,798 people had their names, email addresses, shipping addresses, phone numbers, and purchase details exposed.

SafePal emphasizes that this incident did not affect users’ seed phrases, private keys, wallet passwords, or card information. At present, there is also no evidence indicating that wallet funds were impacted. However, it also reminds users that if they have ever leaked private keys due to phishing emails or scam calls, they should immediately transfer their assets to a new encrypted wallet.

SafePal conducted a full system investigation in July and took down more than 30 phishing websites

Investigations show that SafePal had already received reports at the beginning of May this year suggesting related data might have been leaked. Initially, it was treated as a single case, until July, when it received reports from multiple users about being scammed by groups impersonating contacts. Only then did it launch a comprehensive system review and identify the vulnerability.

Previously, users on the social platforms Reddit and Trustpilot had already posted warnings, claiming they received phone calls from someone posing as a SafePal staff member. Not only could the caller accurately state the recipient’s name and order details, but they also guided the target to a fake website to replace the cold wallet. In response, blockchain analyst Specter had previously publicly questioned the risk of personal data leaks.

SafePal has already urgently patched the vulnerability, notified affected customers, and commissioned a third-party cybersecurity company to review the system. At the same time, it has taken down more than 30 scam websites and reduced the retention period for customer personal data to 90 days.

加密錢包SafePal爆個資外洩,近4萬客戶受影響Image source: SafePal announcement—encrypted wallet SafePal suffers a personal data leak; nearly 40,000 customers affected

Not only SafePal—Trezor and Ledger have leaked data one after another

Before SafePal exposed a data leak case, its peer Trezor also had an incident.

Last week, Trezor issued a公告 stating that on August 10, it received a notification from its logistics partner, ShipMonk, about an illegal access to its system. This resulted in the complete leakage of names, addresses, and phone numbers of 11,742 customers from countries including the U.S., the U.K., and Sweden between May and August 2026, with partial personal information of another 1,947 customers also exposed.

In addition, the well-known cold wallet brand Ledger also notified customers earlier this year in January, saying that a data breach incident occurred involving a third-party e-commerce service provider, Global-e.

Although Trezor and Ledger both emphasize that their devices and private keys are absolutely secure, customer personal data leaks can still become a breakthrough point for highly precise social engineering fraud.

  • Related report: The hack at a logistics company spread! Trezor cold wallet leaks personal data of 14,000 users—watch out for follow-up phishing attacks

Supply-chain vulnerabilities become the weak point—don’t put all your eggs in one basket

Looking at multiple recent incidents, the commonality among SafePal, Trezor, and Ledger is that: the encryption architecture and private keys of the encrypted wallet devices themselves have not been compromised. However, vulnerabilities in third-party e-commerce or logistics supply-chain personal data have become a powerful tool for hackers to carry out targeted phishing attacks.

These three incidents differ in nature from the earlier hacking event involving a Coldcard cold wallet that caused losses of more than $100 million in bitcoin, but they similarly expose potential risks in the surrounding ecosystem of cold wallets.

Cybersecurity experts remind that even though cold wallets are generally more secure than hot wallets, users should still be cautious about phishing communications impersonating official entities. They should also appropriately diversify and store encrypted assets across different tools to reduce the cybersecurity impact if a single component fails.

Further reading:
Ledger: Multiple Android MediaTek chips may be compromised in an instant—new threat to mobile encrypted wallets
 

“Plug-in authorization went wrong! Encrypted wallet SafePal suffers a personal data leak—addresses and phone numbers of nearly 40,000 customers exposed”—This article was first published on “Crypto City”