Skip to content
Active Currencies: 18,442
Market Cap: $2.265T
Bitcoin Dominance: 56.20%
24h Market Cap Change: $0.68

SafePal data breach exposes 39K users – Why phishing risks are rising

SafePal’s customer data breach adds to growing concerns over phishing and social-engineering risks facing hardware wallet users.

SafePal data breach exposes 39K users - Why phishing risks are rising

SafePal, a self-custody cryptocurrency wallet, was affected by an authorization vulnerability in its Order Tracking Plugin. This allowed unauthorized access to customer data for approximately 39,798 SafePal customers.

The breach contained customer orders placed between March 2025 and April 2026 and revealed customers’ personal information, including names, emails, shipping addresses, phone numbers, and purchase details.

However, on their official X page, SafePal confirmed that seed phrases, private keys, wallet passwords, payment information, identification documents, and customer funds remained secure.

Source: X

SafePal also stated that it has since sorted the issue and implemented additional safeguards to help prevent such breaches from occurring again.

Furthermore, SafePal notified each affected customer directly with a verification webpage utilizing order ID and shipping country. This helped them verify which of their customers’ information had been breached.

Hence, affected customers now face heightened impersonation risks despite their wallet credentials remaining uncompromised.

Hardware wallet security incidents raise fresh concerns

Recent hardware wallet breaches have heightened concerns that go far beyond SafePal. This indicates a larger trend of self-custody service breaches.

In a post on X, crypto sleuth ZachXBT pointed out this trend, stating that “all hardware wallets are complete garbage.” After his statement, three incidents followed within seventeen days.

COLDCARD faced the biggest hit, with an exploit reportedly linked to more than $111 million in stolen Bitcoin [BTC]. Trezor then disclosed a breach involving their shipper’s customer database where 13,689 customers’ personal identifiable data were exposed.

However, the breach did not expose any of the affected customers’ wallet credentials or private keys.

Source: X

SafePal followed with 39,798 users affected by a breach of their order tracking plugin. The breaches at both Trezor and SafePal were different from that experienced by ColdCard as they involved an exposure of customer data instead of private keys.

Nonetheless, these successive breaches heighten phishing risks for consumers. This is because they provide attackers with verifiable information on hardware wallet owners, which allows them to create more socially engineered attacks.

SafePal phishing risk grows

Looking forward, the next test for SafePal will be to determine if actual customer harm results from the release of exposed records. Already, over thirty fraudulent websites and phishing links have been identified as being removed.

Furthermore, there were reports of scammers referencing specific customer details prior to public disclosure. This suggests that some information had been circulating prior to the breach. However, despite these efforts, confirmed loss amounts remain unknown.

Therefore, rising support tickets and targeted impersonation reports among the 39,798 affected customers would provide clearer evidence that attackers are actively exploiting the leaked data.


Final Summary

  • SafePal exposed 39,798 customers, increasing phishing risks despite secure wallet credentials.
  • Recent hardware-wallet incidents show customer data becoming a growing social-engineering risk.

 

Disclaimer: AMBCrypto's content is meant to be informational in nature and should not be interpreted as investment advice. Trading, buying or selling cryptocurrencies should be considered a high-risk investment and every reader is advised to do their own research before making any decisions.

Muriuki Lazaro

Journalist

Muriuki Lazaro is a on-chain data analyst with a B.Sc. in Data Science. Muriuki specializes in dissecting complex on-chain data into clear and accurate insights for readers in the crypto ecosystem, with a particular focus on Bitcoin.

AMBCrypto was founded in 2018 with a mission to simplify and bring the latest blockchain and cryptocurrency news to our readers. We have quickly grown into the digital news source for an emerging generation of cryptocurrency enthusiasts, reaching more than a million readers on a monthly basis, across the globe.