SafePal Data Breach: 39,798 Customers Exposed With Names, Addresses and Phone Numbers
SafePal confirmed a data breach on August 16, 2026: the names, delivery addresses, phone numbers and order details of 39,798 customers were exposed. Seed phrases and private keys were not affected, but the phishing risk is substantial.

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
Hardware wallet maker SafePal acknowledged a data breach on August 16, 2026: the names, email addresses, delivery addresses, phone numbers and order details of 39,798 customers were exposed. Seed phrases, private keys and payment data were not affected, according to the company. Anyone who ordered a device between March 2, 2025 and April 11, 2026 should check now, because the combination of a home address and the knowledge that someone there "owns a hardware wallet" is precisely what makes targeted fraud possible.
The company has notified affected customers by email and published a lookup tool that establishes, from the order number, whether a given order sits in the leak. It is the second incident of its kind in the industry within two weeks.
What Exactly Happened in the SafePal Data Breach
The cause, according to SafePal, was an authorization flaw in a plugin used for order tracking. An authorization flaw means an application checks whether someone is logged in, but not whether that person is entitled to see the data being requested. Under certain conditions, another customer's order could be viewed through it.
A second, unrelated fault compounded the problem. According to research by BleepingComputer, a misconfiguration prevented old order records from being deleted on schedule between September 2025 and April 2026. Far more historical data therefore sat in the system than should have been there. Only that interplay explains why the order window reaches back into March 2025.
The sequence matters more to the assessment than the headline number. A first indication of the problem reached SafePal in early May 2026. In July the company began a full review and rebuild of its order processing and came across the vulnerability in the process. The public statement followed on August 16. A good three months therefore separate the first indication from the notification of those affected.
Which Data Leaked in the SafePal Breach and Which Did Not
SafePal sets out both sides explicitly in its security notice. Affected are names, email addresses, shipping addresses, phone numbers and purchase details. Not affected, the company says, are seed phrases, private keys, wallet passwords and other wallet credentials, along with bank details, card numbers and official identity numbers.
The seed phrase is the sequence of twelve or twenty-four words from which every key in a wallet can be restored. Anyone who knows it has full access to the balance, regardless of where the device happens to be. Its absence from the leak is the good news in this incident: the leaked data alone cannot move funds.
That is only half the picture. An attacker who knows a name, home address, phone number and order date does not need to steal the seed phrase. They can try to have it handed over. That is what separates an ordinary address leak from an address leak at a wallet manufacturer.
One further point belongs in an honest account. According to reports by BleepingComputer and the specialist service Help Net Security, an actor on a cybercrime forum is offering a data set that cites the same customer count and the same order window. Whether that offer is genuine remains unconfirmed. For your own caution it makes no difference, because the safe way to handle unexpected contact is the same either way.
Am I Affected by the SafePal Data Breach? How to Check Your Order
There are three routes, and they complement one another to give a reliable picture.
Order Window, Notification and the Lookup Tool
The first route is the calendar. Only orders placed between March 2, 2025 and April 11, 2026 are affected. Anyone who ordered earlier or later falls outside the leak, on the company's account of it. The second route is the inbox: SafePal notified affected customers by email on August 16 from the sender address security@safepal.com. The third route is the lookup tool, into which an order number and shipping country can be entered.
One detail about that tool is easy to miss and decisive. Open the site only through the address www.safepal.com typed in directly, and follow no link from an email. SafePal says it has already had more than 30 fake websites and phishing links taken down. Imitations of that kind live on appearing at the right moment, and the right moment is now.

Why a Delivery Address Is More Dangerous Than a Leaked Password
A leaked password can be changed in two minutes. A home address and a phone number cannot be changed, and the fact that someone living at that address holds crypto assets in self-custody does not go stale. That is the core of the problem and the reason address leaks at wallet makers form a category of their own.
Two risk paths follow from it. The first is targeted phishing. Phishing describes the attempt to obtain credentials behind a faked identity. An attacker who cites your name, your purchase date and your device model clears the usual hurdle: the contact does not read like a bulk mailing, but like a callback about a transaction that genuinely took place.
The second path is the more unpleasant one. The industry has adopted the term wrench attack for the physical assault on wallet owners: instead of breaking encryption, the owner is pressured into handing over their keys. A solid address list is the prerequisite. Cryptoticker described this connection on April 25, 2026 in the context of the series of kidnappings in France; that chain likewise began with exposed data.
Anyone who draws the conclusion that their custody setup needs a rethink will find the common devices and their purchase routes in the hardware wallet comparison. That is no substitute for responding to the leak; it only narrows the attack surface for the next one.
Hardware Wallets ComparedPhishing Calls Since May: the Data Has Been in Use for Months
The finding that sets this incident apart from a routine disclosure notice sits in the reports by BleepingComputer and Help Net Security. As early as May 2026, months before the official statement, customers reported phishing emails and phone calls concerning supposed firmware updates and security problems with their hardware wallet. One customer additionally reported a letter.
SafePal has not confirmed any direct link between those approaches and the leak, on Help Net Security's account. The timing and the callers' knowledge nonetheless point to an overlap in the specialist service's assessment. For you as a customer the practical meaning is clear: the assumption that the risk begins with publication does not hold. The attacks were already running.
A firmware update is an update to the device software of a hardware wallet. The user always initiates such an update themselves through the manufacturer's official application, and it is never announced by telephone. A call pressing for an update is therefore a warning sign independently of any data breach.
The Fake Replacement Device: the Scam SafePal Warns About Itself
One phrase the company has written into its recommendations is worth noting. Customers should treat every unexpected approach and every unexpected hardware delivery relating to their SafePal purchase as suspicious, whether it comes by phone, by post or in person.
There is a reason a manufacturer explicitly warns about parcels that appear to come from itself. A tampered device shipped with prepared instructions and a recovery phrase already supplied hands control of every holding later stored on it to the sender. The recipient notices nothing at first, because the device works to all appearances.
The rule against it is unspectacular and effective. A device you did not order yourself does not get set up. A recovery phrase that comes with a device is never genuine, because it is generated on the device and nowhere else. And a seed phrase is under no circumstances entered on a website, into a form or over the phone. How to store it instead is set out in our guide to storing your seed phrase.

Second Case in Two Weeks: What Trezor and SafePal Have in Common
On August 13, 2026, Cryptoticker reported a data breach at Trezor in which, on the information available then, 13,689 customers were affected with names, phone numbers and home addresses; there the data escaped through the logistics provider ShipMonk. The details are in our report on the Trezor data breach.
The technical causes of the two cases have nothing to do with each other. One lay with an external shipping provider, the other in a self-operated plugin. What they share is the location: in neither case was the device the target, nor the cryptography behind it, but the ordering process.
That is the real lesson of the pairing. The security architecture of a hardware wallet is built so that the private key never leaves the device, and it serves that purpose. The purchase that precedes it is an ordinary online shop with an address database, shipping workflow and third-party plugins, and it is run to the standards of an online shop. Two incidents in fourteen days are too small a number for a statistic, but they are enough to make that asymmetry visible.
In practice one question follows, and it can be asked before any purchase: which data does the merchant actually need, and how long does it keep them? SafePal has announced in response that it will delete purchase records after 90 days in future, where legal requirements do not demand otherwise. Shorter retention periods are the most effective remedy against precisely this kind of leak, because leaked data can only be as old as the records still held.
Regulated Crypto Exchanges ComparedWhat SafePal Customers Should Do in the Next Few Days
Responding to an address leak differs fundamentally from responding to a password leak. There is nothing to reset. What remains is preparing for the approaches that will come.
Five Points for the Coming Weeks
Check first, through the manufacturer's address typed in directly, whether your order sits in the leak, and look in your inbox for a notification. Then treat every incoming approach relating to your purchase, whatever the channel, as unverified until you have confirmed it yourself through an official route. Do not set up hardware you did not order. Do not enter your seed phrase under any circumstances, not even into a form that looks genuine. And reconsider the delivery address for future orders, for instance a parcel locker or an alternative delivery point.
What you do not have to do: replace the device or set the wallet up again. Since no wallet credentials are affected on the company's account, there is no reason for it. Anyone who nevertheless wants to move out of caution should do so through a self-controlled fresh setup with a newly generated seed phrase, and not through a device sent to them.
GDPR and Data Breaches: What Rights Customers in Germany Have
Even though SafePal is not based in the EU, the General Data Protection Regulation applies as soon as goods are delivered to people in the EU. Two practical claims follow for you. Under Article 15 GDPR you can request information about which data are stored about you. Under Article 34 GDPR a controller is obliged to notify data subjects without undue delay where a personal data breach is likely to result in a high risk to them.
Whether the notification in this case meets the standard of undue delay is an assessment for supervisory authorities, not for us. All that can be recorded is the chronology: first indication in early May, notification in mid-August. Anyone wanting to pursue the matter can turn to the data protection authority responsible for the provider; in Germany the relevant state data protection authority is the right place for a complaint.
Independently of that, documentation is worthwhile. Keep the notification email and the result of your check. Should damage arise later, evidence of when you knew what is the starting point for anything that follows.
Checking the SafePal Data Breach: What to Take Away
The incident affects a manageable group, but for that group it is serious, because the exposed details remain valid indefinitely. Three steps put you on solid ground within minutes.
- Check the order and classify the contacts. See whether your purchase falls between March 2, 2025 and April 11, 2026, and verify the result through the manufacturer's address typed in yourself. Treat every call and every message about your purchase as unverified until you have checked it. If you then rethink custody, the hardware wallet comparison is the sober place to start.
- Do not set up a device you did not order. That single rule covers the most dangerous variant of the scam in full. For amounts where postal delivery does not pay off anyway, the software wallet comparison is the obvious alternative.
- Make data economy a habit. Shorter retention periods and fewer details on file limit the damage of the next leak before it happens. That applies to merchants as much as to trading venues; which providers operate under European supervision is shown in the overview of regulated crypto exchanges.
(As of August 20, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- Trezor Data Breach: First 13,689 Customers, Then Roughly 67,000 More Exposed
- Crypto Phishing After a Data Breach: The Warning Signs in a Fake Exchange Email
- Crypto Wallet Provider Ledger Hacked: Data Leak Results in Phishing Scams
- Crypto Wallet Phishing by Letter: Why the QR Code From Your Postbox Wants Your Recovery Phrase
- Waltio Confirms Brevo Breach Touched Its User Emails: Here Is What To Do Now
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
September 10, 2026 9:13 AM

Trezor Hack Scare: That STM32 Entropy Email Is a Phishing Attack
Trezor users received a fake STM32 entropy warning sent from a real Trezor address. Here is what happened and what to do if you clicked.
September 4, 2026 10:15 PM

Trezor Data Breach: Am I Affected and What Should I Do Now?
Trezor widened the ShipMonk data breach on September 4, 2026: around 67,000 further people affected, just over 80,000 in total, from orders placed between November 2019 and August 2021. How to check in two minutes whether you are among them, and what an exposed home address means for self-custody.
August 22, 2019 9:55 AM

Here’s why you should skip Facebook’s Crypto: Instagram Data Breach
It’s practically similar to stating the sky is blue yet we have another Facebook Data Leak close by influencing a huge number of clients. This time around, it includes the contact data of in excess of 49 million Instagram Accounts […]
September 10, 2026 1:14 PM

Phishing Email From the Real Sender Address: How to Check a Wallet Security Warning
An alleged security warning to wallet customers travelled through the manufacturer's genuine sending channel and passed every technical authenticity check. The test that still holds costs you four minutes.
December 26, 2025 1:50 PM

Breaking: Trust Wallet Chrome Extension Hack Drains $7M, Full Reimbursements Promised
A supply-chain attack hit Trust Wallet’s Chrome extension, draining $7M from users. Binance’s CZ says all victims will be reimbursed.
August 11, 2026 1:32 PM

How to Store a Seed Phrase Safely: What Steel, a Passphrase and Multisig Do for Your Wallet Backup
The Coldcard case pushed the manufacturer question to the front, while barely touching on where the backup is kept. This guide places paper, steel, the passphrase and splitting methods against the BIP-39 and SLIP-0039 standards.
September 23, 2026 4:12 AM

How to Set Up a Crypto Wallet: Securing Your Coins in Seven Steps
Your own crypto wallet is set up in twenty minutes, yet a single step decides everything that follows. This guide takes you through wallet type, recovery words and the test amount, and sets out what BaFin and the tax office expect.
September 17, 2026 4:14 PM

D'CENT App Wallet: How to Tell If Your Recovery Phrase Has to Move Now
Manufacturer IoTrust reports suspicious asset transfers in the D'CENT app wallet and asks users to move their holdings. One question decides the matter: has your recovery phrase ever been entered into the app?
September 1, 2026 7:27 AM

Clipboard Attack: How Malware Swaps the Wallet Address You Copied
A clipper replaces the receiving address between copying and pasting with the attacker’s, and your wallet’s checksum notices nothing. What Microsoft and the Federal Office for Cybersecurity have documented, and which check really makes the attack come to nothing.
May 4, 2019 5:44 PM

Microsoft Hackers Stole Crypto Using Victims Emails
Another batch of crypto users have lost money recently through an unlikely breach. Recently, Microsoft services such as Hotmail, MSN, and Outlook have been hit by a breach. It was later learned that the breach was due to an employee’s […]
April 25, 2026 9:55 AM

France Crypto Kidnappings Crisis: Pavel Durov Blasts Data Leaks and New Surveillance Laws
Pavel Durov exposes a surge in crypto-related kidnappings in France, blaming tax data leaks and warning against new social media surveillance laws.
September 30, 2026 7:16 AM

Tangem Wallet: The Card Without a Seed Phrase vs the Classic Hardware Wallet
The Tangem Wallet secures crypto with two or three identical cards instead of 24 words. What the sets cost, what the EAL6+ chip delivers and why losing every card is final.
September 19, 2026 10:11 PM

North Korean Hackers Drain 7,000 Crypto Wallets: What to Check on Job Offers and Coding Tests
Seven agencies, among them Germany's BND and BfV, warn about the WaterPlum group: 30,000 infected machines, more than 7,000 drained wallets. The bait is a job offer, the trap a coding test.
August 23, 2026 4:36 PM

Operation ASTERIX: How a Fake Support Call Delivers a Counterfeit Wallet App
Security researchers analysed an open server on which a phone system, phishing interfaces and cloned wallet programs all came together. The largest list of numbers was the German one.
August 22, 2026 10:29 AM

Bitcoin Fork: What Happens to Your Coins When the Chain Splits
On October 31, 2026 a new chain called ECX splits off from Bitcoin, and every holder is credited automatically. Who actually receives the coins depends on the private keys, on voluntary replay protection and on a tax rule many overlook.
July 31, 2026 3:54 PM

594 BTC Gone in 25 Minutes: The Coldcard Flaw That Made Seed Phrases Guessable
A firmware bug from March 2021 let an attacker drain $38 million from around 500 Bitcoin wallets. Here is what broke, who is exposed and what to do now.
April 25, 2024 11:44 AM

Beware of New Ethereum Node Scam: USDT Fraud Exposed
Crypto Scammers exploit Ethereum nodes and USDT to deceive crypto users. How are they pulling it off and what essential tips can help you protect yourself against these crypto scams?
March 31, 2026 5:13 PM

Quantum Threat to Bitcoin? Google Research Sparks Urgent Crypto Security Debate
Google’s quantum breakthrough raises fears for Bitcoin security. Can crypto survive quantum attacks—or is an upgrade urgent?
August 24, 2026 1:22 PM

Phantom Wallet Ends Sui and Monad Support: What to Do Before the Deadlines
Phantom Wallet removes Monad from its app on August 26 and Sui on September 24. The balances are not lost, but only one of the two ways out leaves your tax position untouched.
August 31, 2026 7:20 AM

Browser Extensions as Wallet Thieves: How a Sports App Became a Seed Phrase Collector
In August 2026 the security firm Socket disclosed two separate campaigns: 40 confirmed malicious Firefox extensions and 19 for Chrome and Edge, all of them from the official marketplaces. Nine of them were harmless sports apps that only turned into wallet thieves through an update.
April 27, 2026 10:30 AM

Win $5,000 in BTC: Tangem Launches Exclusive 2026 Prize Draw
Tangem announces a massive prize draw with $5,000 in BTC and iPhone 17s up for grabs. Secure your crypto and enter today using our exclusive link.
November 19, 2018 12:11 PM

Brazilian Crypto Investment Platform Atlas Quantum Hacked, Data Of 264,000 Users Leaked
Atlas Quantum, Brazilian crypto investment platform has been hacked and the data of more than 264,000 of its customers has been leaked.
September 12, 2026 4:12 PM

Revolut Data Breach: Am I Affected, and What About My Bitcoin History?
After a forged government request, Revolut handed identity documents, account statements and complete Bitcoin transaction histories to an unauthorised party. Here is how to establish whether you are affected, and which protective measure actually achieves anything in this case.
September 28, 2026 10:26 AM

Phantom Wallet and Solscan: What a Solana Transfer Really Costs and Where It Fails
A transfer on Solana costs 0.000005 SOL, a new token account ties up 0.00148844 SOL once — both values measured on-chain by us today. This practical guide shows how to set up Phantom, how to get there from the exchange, how to read Solscan and what applies for tax in Germany.
September 15, 2026 10:14 PM

AI Crypto Crime: How Scams Are Getting More Convincing
AI is sharpening fake support, deepfakes and phishing across the crypto space. Why the data still needs a careful reading and which security routines protect a wallet.
September 4, 2026 10:17 AM

Cypher Shutdown on September 6: What Users Should Know Now the Withdrawal Deadline Has Passed
Recap as of September 27, 2026: Cypher had announced it would take its app, dApp and withdrawal window offline on September 6, 2026 and end the token protocol. This article describes the situation before the deadline, how the payout worked and what our own measurement showed at the time about what was left of the CYPR token.
August 18, 2026 7:23 PM

Inheriting Crypto: How Your Heirs Actually Get Access, and Why the Seed Does Not Belong in a Will
The German Federal Court of Justice made clear in 2018 that digital accounts are inherited like everything else. With self-custodied coins succession law still achieves nothing: no key, no access. And anyone who writes the seed into a will has a court send it to every party involved.
More from CryptoTicker
