Cryptocurrency hardware wallet provider SafePal has issued a warning about a data breach affecting approximately 39,798 customers, after a vulnerability was exploited to steal customer order information. A threat actor is now reportedly selling the stolen data on a cybercriminal marketplace.
What Happened
SafePal disclosed that an attacker exploited a flaw in its systems to access and exfiltrate customer order data. The breach specifically targeted information related to product orders — including names, shipping addresses, and associated contact details — rather than private keys or wallet credentials. SafePal has notified affected customers and is investigating the full scope of the incident.
The stolen data has since appeared for sale on underground forums, with a threat actor claiming to possess the full dataset and offering it to other cybercriminals.
What Data Was Exposed
Based on SafePal's disclosure, the breach involved customer order information, which typically includes:
- Full names
- Shipping addresses
- Email addresses
- Phone numbers (if provided at checkout)
Critically, cryptocurrency wallet private keys and seed phrases are not stored by SafePal and were not part of the breach. However, the exposed PII creates significant secondary risks.
Why This Matters for Crypto Users
Even without private keys, the breach poses meaningful risks to affected SafePal customers:
- Targeted phishing attacks — Threat actors now know exactly who owns a crypto hardware wallet, making recipients high-value targets for spear-phishing campaigns impersonating SafePal or other wallet providers.
- SIM-swapping attempts — Exposed phone numbers can be leveraged for SIM-swap attacks to compromise exchange accounts tied to those numbers.
- Physical security risks — Home addresses linked to hardware wallet ownership raise personal safety concerns for high-net-worth crypto holders.
- Social engineering — Attackers can craft highly convincing fraud attempts using order details (product type, purchase date) as credibility bait.
Immediate Actions for Affected Customers
If you are a SafePal customer, take the following steps regardless of whether you have been individually notified:
- Watch for phishing emails impersonating SafePal support, requesting seed phrases or wallet access under any pretext. SafePal will never ask for your seed phrase.
- Enable two-factor authentication (2FA) on all linked email accounts and cryptocurrency exchanges — use an authenticator app, not SMS where possible.
- Be alert to SIM-swap attempts — contact your mobile carrier to add a PIN or account lock.
- Do not click links in unsolicited emails claiming to be from SafePal about this breach. Navigate to the official site directly.
- Monitor for credential stuffing — if you reused the email address or password from your SafePal account elsewhere, update those credentials immediately.
What SafePal Is Doing
SafePal has stated it is working to address the vulnerability that enabled the breach and has begun notifying affected customers. The company is coordinating with law enforcement as the investigation continues.
Broader Context
The breach underscores a recurring risk in the hardware wallet industry: while the devices themselves protect private keys offline, the e-commerce infrastructure surrounding their sale creates a PII exposure vector. Previous high-profile incidents — including the 2020 Ledger breach that exposed over 270,000 customer records — demonstrated how hardware wallet customer lists become lucrative targets for crypto-focused threat actors.
Data stolen in breaches of this type circulates on dark web markets for months or years, enabling sustained phishing campaigns long after the initial incident.
Source: BleepingComputer