Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2389+ Articles
158+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. SafePal Data Breach Impacts 39,798 Customers, Stolen Info for Sale
SafePal Data Breach Impacts 39,798 Customers, Stolen Info for Sale
NEWS

SafePal Data Breach Impacts 39,798 Customers, Stolen Info for Sale

Crypto hardware wallet maker SafePal warns of a breach exposing order data for 39,798 customers after a flaw was exploited, with stolen data now listed for sale.

Dylan H.

News Desk

August 16, 2026
3 min read

Cryptocurrency hardware wallet provider SafePal has issued a warning about a data breach affecting approximately 39,798 customers, after a vulnerability was exploited to steal customer order information. A threat actor is now reportedly selling the stolen data on a cybercriminal marketplace.

What Happened

SafePal disclosed that an attacker exploited a flaw in its systems to access and exfiltrate customer order data. The breach specifically targeted information related to product orders — including names, shipping addresses, and associated contact details — rather than private keys or wallet credentials. SafePal has notified affected customers and is investigating the full scope of the incident.

The stolen data has since appeared for sale on underground forums, with a threat actor claiming to possess the full dataset and offering it to other cybercriminals.

What Data Was Exposed

Based on SafePal's disclosure, the breach involved customer order information, which typically includes:

  • Full names
  • Shipping addresses
  • Email addresses
  • Phone numbers (if provided at checkout)

Critically, cryptocurrency wallet private keys and seed phrases are not stored by SafePal and were not part of the breach. However, the exposed PII creates significant secondary risks.

Why This Matters for Crypto Users

Even without private keys, the breach poses meaningful risks to affected SafePal customers:

  • Targeted phishing attacks — Threat actors now know exactly who owns a crypto hardware wallet, making recipients high-value targets for spear-phishing campaigns impersonating SafePal or other wallet providers.
  • SIM-swapping attempts — Exposed phone numbers can be leveraged for SIM-swap attacks to compromise exchange accounts tied to those numbers.
  • Physical security risks — Home addresses linked to hardware wallet ownership raise personal safety concerns for high-net-worth crypto holders.
  • Social engineering — Attackers can craft highly convincing fraud attempts using order details (product type, purchase date) as credibility bait.

Immediate Actions for Affected Customers

If you are a SafePal customer, take the following steps regardless of whether you have been individually notified:

  1. Watch for phishing emails impersonating SafePal support, requesting seed phrases or wallet access under any pretext. SafePal will never ask for your seed phrase.
  2. Enable two-factor authentication (2FA) on all linked email accounts and cryptocurrency exchanges — use an authenticator app, not SMS where possible.
  3. Be alert to SIM-swap attempts — contact your mobile carrier to add a PIN or account lock.
  4. Do not click links in unsolicited emails claiming to be from SafePal about this breach. Navigate to the official site directly.
  5. Monitor for credential stuffing — if you reused the email address or password from your SafePal account elsewhere, update those credentials immediately.

What SafePal Is Doing

SafePal has stated it is working to address the vulnerability that enabled the breach and has begun notifying affected customers. The company is coordinating with law enforcement as the investigation continues.

Broader Context

The breach underscores a recurring risk in the hardware wallet industry: while the devices themselves protect private keys offline, the e-commerce infrastructure surrounding their sale creates a PII exposure vector. Previous high-profile incidents — including the 2020 Ledger breach that exposed over 270,000 customer records — demonstrated how hardware wallet customer lists become lucrative targets for crypto-focused threat actors.

Data stolen in breaches of this type circulates on dark web markets for months or years, enabling sustained phishing campaigns long after the initial incident.


Source: BleepingComputer

#Data Breach#Cryptocurrency#SafePal#Dark Web#Supply Chain

Related Articles

14,000 Trezor Customers Impacted by Data Breach at ShipMonk

Hackers stole shipping data including names, addresses, emails, and phone numbers from 14,000 Trezor customers via a breach at logistics firm ShipMonk.

4 min read

Checkmarx Confirms GitHub Repository Data Posted on Dark

Checkmarx has confirmed that data from its GitHub repositories has been published on the dark web following an investigation into the March 23 supply...

4 min read

Scottish Government Suffers Potentially Widening Data Breach at Prosecutor's Office

A third-party breach at Scotland's Crown Office and Procurator Fiscal Service may extend to multiple government agencies that shared the same vendor.

3 min read
Back to all News