A SafePal data breach affected nearly 40,000 customers and leaked contact and order details. Here’s what happened, what criminals may do next, and how you can better protect yourself online.
Table of Contents
What Happened in the SafePal Data Breach?
SafePal makes hardware wallets, which are devices designed to keep the keys used to access cryptocurrency offline.
Hackers used a weakness in an order-tracking feature to access customer information. The feature was part of a customer order plugin.
A plugin is an extra software component added to a website or system to provide a specific function.
The affected orders were placed between March 2, 2025, and April 11, 2026.
SafePal disclosed the breach on August 16, 2026. That same day, a threat actor advertised stolen SafePal data on a cybercrime forum.
The company started investigating after receiving a report in May. At first, SafePal treated the report as an isolated case.
Later, the company found that a system bug had kept order information for much longer than intended.
In July, SafePal began reviewing and rebuilding its order-processing system. The company has since fixed the weakness and shortened how long order information is stored.
Incidents like this are also a reminder that your personal information may have been leaked in other breaches without you realizing it.
If you are unsure whether your information has appeared in a data breach, automatic monitoring can help you spot problems earlier.
Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.
Who Was Affected and What SafePal Data Was Leaked?
SafePal said approximately 39,798 customers were affected.
The stolen information included:
- names
- home or shipping addresses
- email addresses
- phone numbers
- order details
SafePal said the breach did not involve seed phrases, private keys, wallet passwords, bank information, payment card numbers, or government IDs.
A seed phrase is a set of recovery words that can give someone control of a cryptocurrency wallet.
A private key is a secret digital code used to access and control cryptocurrency.
Still, contact and order information can help criminals make phishing messages look more convincing.
A message mentioning your name or recent SafePal purchase may seem legitimate because it contains details that only a real company should know.
Futureproof scans your data for leaks and shows exactly how to close security gaps — before scammers find them first.
Check my safetyHow Hackers Accessed SafePal Order Information
SafePal said hackers exploited a vulnerability in the order-tracking function of a customer order plugin.
The company has not publicly shared detailed technical information about how the hackers used that weakness.
However, SafePal confirmed that the problem allowed criminals to reach order-related customer information.
The company says it has now fixed the vulnerability and reviewed its order-processing system.
It also contacted partners to check whether the problem had spread elsewhere and hired an outside security firm to investigate.

At Futureproof, Kevin explains digital safety in simple words, with clear tips and zero fluff. He holds a degree in information technology and studies fraud trends to keep his tips up-to-date.
In his free time, Kevin plays with his cat, enjoys board-game nights, and hunts for New York’s best cinnamon rolls.
