Crypto self-custody provider SafePal has publicly disclosed a significant customer data leak that compromised the purchase records of nearly 40,000 users worldwide. While the company confirmed that user funds, private keys, and seed phrases remain untouched, the incident has exposed thousands of crypto holders to elevated risks of targeted phishing, social engineering, and real-world privacy threats.
The incident highlights a persistent vulnerability across the Web3 hardware landscape: while cold storage devices offer military-grade cryptographic protection for digital assets, the conventional web platforms used to sell and ship them remain susceptible to traditional supply-chain cyberattacks.
Who Is SafePal?
Founded in 2018 by tech veteran Veronica Wong, SafePal is a prominent non-custodial cryptocurrency wallet suite known for making cold-storage security accessible and affordable. The company gained major industry traction after becoming the first hardware wallet portfolio backed by Binance Labs, later expanding its product ecosystem to include mobile software wallets, browser extensions, and its native utility token, SFP.
SafePal’s flagship product, the SafePal S1, is an air-gapped hardware wallet that operates without Bluetooth, Wi-Fi, or USB connections, relying instead on encrypted QR codes to sign transactions. Today, the platform serves tens of millions of users globally across more than 200 blockchains, positioning itself as a central player in the self-custody ecosystem.
Root Cause: The Third-Party Plug-In Flaw
According to SafePal’s official incident disclosure, the unauthorized breach originated within an e-commerce order-tracking plug-in integrated into its official web storefront. Attackers leveraged an authorization vulnerability within the third-party extension to access backend order databases.
The exploit affected customers who placed hardware orders between March 2, 2025, and April 11, 2026, compromising a total of 39,798 user profiles. Exposed records include full names, physical shipping addresses, email addresses, phone numbers, and specific hardware purchase histories.
SafePal stressed that payment card numbers and government IDs were not involved, as checkout transactions are routed through isolated external financial gateways. Most importantly, because SafePal’s hardware architecture generates and seals private keys locally inside an EAL5+ Secure Element chip, the integrity of the physical devices and on-chain funds was never compromised.
The Threat: Why Leaked Shipping Data Matters
Even when blockchain assets remain safe on-chain, leaking the physical addresses and contact details of hardware wallet owners creates serious security hurdles. Attackers frequently use these databases to launch hyper-targeted social engineering operations against individuals they now know hold cryptocurrency.
Historically, hardware wallet data breaches across the industry have led to wave after wave of fraudulent communications designed to trick users into revealing their recovery phrases.
SafePal customers who purchased devices during the affected window should stay alert to several critical threat vectors:
- Urgent Firmware Phishing: Disregard any email or text claiming your device has an “emergency software patch” linking to an external website. Updates should only be processed directly within the official SafePal app.
- Malicious Replacement Packages: Treat any unsolicited physical mail or “replacement” hardware with extreme suspicion. Scammers have previously mailed modified, compromised devices pretending to be official manufacturer recalls.
- Fake Technical Support Calls: Reject any inbound calls claiming to be from SafePal support. Legitimate hardware providers do not initiate phone calls to resolve account issues.
- Seed Phrase Requests: Never enter your 12-to-24-word recovery phrase into a website, computer, or phone form under any circumstance.
Remediation and Future Safeguards
SafePal announced that it removed the compromised tracking plug-in immediately upon discovery and engaged an external cybersecurity firm to audit its web infrastructure. The company has also tightened its customer data-retention policies, ensuring shipping records and contact details are automatically purged after 90 days to minimize future exposure.
In addition to technical remediation, SafePal’s security team has coordinated with cybercrime authorities to take down more than 30 spoofed websites and fraudulent domains established by bad actors in the wake of the leak.







