The hardware wallet manufacturer stressed that unauthorized threat actors gained access to the data through a malfunctioning plugin used to track users’ orders. The incident, which transpired between March 2, 2025 and April 11, 2026, leaves users vulnerable to phishing attacks and fraudulent phone calls.
Key Takeaways
Safepal suffered a data breach exposing the personal details and shipping addresses of 39,798 users.While wallet keys remain safe, the leaked addresses leave users vulnerable to physical wrench attacks.Safepal secured the flaw but faces harsh criticism for delaying disclosure despite prior scam reports.Safepal, a wallet manufacturer headquartered in the Seychelles, is facing a security crisis involving a subset of its users.
The data breach involved customers’ orders between March 2, 2025, and April 11, 2026, exposing potentially critical information, including names, email addresses, shipping addresses, phone numbers, and purchase details, to the attackers.
The company ensured that seed phrase, private keys, wallet password, or other wallet credentials were not extracted during this incident.
Safepal acknowledged that the breach might lead to sophisticated phishing attempts, including “fraudulent phone calls, emails, text messages, letters, refund offers, firmware-update requests, fake customer-support communications, malicious websites, or other attempts to obtain your wallet credentials or additional personal information.”
Even so, Safepal claims it fixed the issue and implemented new security measures to prevent similar breaches, including tightening the data retention period to 90 days and taking down 30 fraudulent websites linked to scam schemes.
Specter, another blockchain investigator, stressed that the company had been receiving reports of phishing attempts as early as April but did not disclose it until now. Tay confirmed that several cases were reported during spring and summer that might be linked to this leak.
A customer allegedly involved in the breach pointed out that the company had deleted his data before this disclosure, criticizing Safepal’s data retention policies.


















