SafePal Data Breach Exposes 40,000 Customer Order Records

Crypto hardware wallet provider SafePal has disclosed a data breach affecting nearly 40,000 customers' order information, though the company confirms private keys and crypto assets remain secure.

Crypto hardware wallet provider SafePal has revealed a data breach that exposed the personal order information of nearly 40,000 customers, though the company maintains that all private keys, seed phrases, and cryptocurrency assets remain completely secure.

Scope of the Breach

According to SafePal’s disclosure, the breach affected customer order records including:

  • Names and email addresses
  • Shipping addresses
  • Order details and transaction histories
  • Phone numbers in some cases

The company emphasized that no private keys, seed phrases, or cryptocurrency holdings were compromised in the incident. SafePal’s hardware wallets store cryptographic keys offline, isolated from the systems that contain customer order data.

Company Response

SafePal stated that it immediately secured the affected systems upon discovering the breach and has begun notifying impacted customers. The company is working with cybersecurity experts to investigate the incident and has reported the breach to relevant data protection authorities.

The company recommended that affected customers remain vigilant against potential phishing attempts, as attackers could use the exposed information to craft more convincing fraudulent communications.

Security Implications

While SafePal’s core security architecture—offline storage of private keys—remained intact, the breach highlights broader security challenges facing crypto service providers:

  1. Social engineering risk: Exposed customer data increases the effectiveness of phishing and impersonation attacks
  2. Supply chain vulnerability: Order systems are often less hardened than wallet security infrastructure
  3. Customer trust impact: Data breaches can erode confidence even when crypto assets remain secure
  4. Regulatory compliance: Breaches involving customer data trigger reporting requirements and potential liability

Industry Context

The SafePal breach follows other recent security incidents in the crypto space, including:

  • Trezor wallet data exposure affecting similar numbers of users
  • Various exchange security incidents in 2026
  • Third-party service provider breaches affecting multiple crypto companies

These incidents underscore the importance of robust security practices across all systems, not just those directly handling cryptographic keys.

Customer Recommendations

Security experts recommend that customers of any crypto service take several protective measures:

  • Use unique, strong passwords for all crypto-related accounts
  • Enable two-factor authentication wherever available
  • Verify all communications through official channels
  • Monitor financial accounts for suspicious activity
  • Consider using privacy-focused payment methods when ordering hardware wallets
  • Store device shipping labels securely or destroy them after delivery

Long-term Security Considerations

The SafePal incident may accelerate industry discussions about data protection standards for crypto service providers. Some security advocates argue that crypto companies should adopt privacy-by-design principles that minimize the collection and storage of customer personal data.

Hardware wallet providers may also need to strengthen security around order management systems, potentially implementing:

  • Enhanced access controls and monitoring
  • Data encryption for stored customer information
  • Regular security audits and penetration testing
  • Bug bounty programs to identify vulnerabilities proactively

SafePal has not disclosed the timeline for implementing additional security measures following this breach.

For trust scores on wallet providers and security assessments, visit trustgrade.ai.

Start Building with TrustGrade

Get your free API key and score your first entity in minutes. 100 calls/day free.

Get Free API Key →