Logo Daily Crypto Briefs
Open menu

SafePal Says 39,798 Customer Orders Exposed as Dataset Sale Claims Emerge

6 min read
Breaking News
Large official navy SafePal wordmark and emblem on an off-white plaque beside a greyscale unbranded padded shipping parcel with a blank torn label.

TL;DR

  • SafePal said an authorization flaw in an order-tracking plug-in exposed names, emails, addresses, phone numbers and purchase details for about 39,798 customers.
  • In an Aug. 18 update, the hardware-wallet provider said it was aware of unverified claims that people possessed and were offering the customer dataset for sale.
  • SafePal says seed phrases, private keys, wallet passwords and funds were not affected, but exposed buyers face a heightened phishing and impersonation risk.

SINGAPORE, Aug. 20, 2026

SafePal said 39,798 customers had order information exposed through a flaw in a tracking plug-in, then said it was reviewing unverified claims that people were offering the dataset for sale, raising the risk of targeted phishing against hardware-wallet buyers even as Bitcoin traded near $72,546 on Aug. 20.

The hardware-wallet provider said the affected records cover orders placed from March 2, 2025 through April 11, 2026. It said names, email addresses, shipping addresses, phone numbers and purchase details were accessed without authorization.

SafePal’s Aug. 18 update is the material development. The company said it was aware of claims that individuals possessed the affected dataset and were offering it for sale, but said it could not verify their authenticity and was monitoring for evidence that data had been shared.

A dedicated loss-impact check found no confirmed on-chain theft, drained-wallet total, victim-loss estimate, affected-wallet count or transaction evidence tied to this incident as of 19:15 Casablanca time on Aug. 20. SafePal’s incident report says seed phrases, private keys, wallet passwords and other credentials were not in the affected order data, and it found no evidence the incident itself compromised wallets or funds.

Bitcoin’s market value was about $1.39 trillion and its reported 24-hour volume was about $43.99 billion at the latest Aug. 20 observation, according to CoinGecko’s historical market-data page. Those figures do not establish a market reaction to a customer-data breach, but they frame the scale of the asset base held by people who can be targeted through compromised purchase records.

Bitcoin

BTC
July 21 to Aug. 20, 2026 (UTC daily observations)
$72,546
+11.3%
Jul 21 - Aug 20 | High $72,546 Low $62,996

SafePal Says 39,798 Order Records Were Accessed

SafePal said an authorization flaw in the order-tracking function of a plug-in could, under certain conditions, give someone access to another customer’s order information. It says it fixed the flaw when discovered and added new security measures.

The company did not disclose when the flaw was introduced, when the records were first accessed or how many parties accessed them. It said it received a report consistent with the issue in early May, initially treated it as isolated, and started a broader review and rebuild of the order-processing pipeline in July.

Its records extended back to March 2025 partly because a scheduled cleanup process had stopped working correctly from September 2025 to April 2026, SafePal said. The company said that retention failure did not cause the unauthorized access, but it broadened the period of order data that remained in the environment.

The incident is distinct from a wallet or blockchain breach. SafePal said the plug-in was separate from its wallet systems, and the disclosure excludes seed phrases, private keys, bank-account information, payment-card numbers and government identification numbers.

That distinction does not make the data harmless. A real shipping address combined with proof of a hardware-wallet purchase can make an impersonation attempt far more credible, especially if it imitates a delivery company, a refund team or technical support.

Dataset Sale Claims Raise the Phishing Risk

In its update, SafePal said wider circulation of the order information could increase targeted phishing, impersonation and social-engineering attacks. It said it had contacted specialists to help remove malicious domains and had identified and taken down more than 30 fraudulent websites and phishing links tied to the activity.

The company said it notified affected customers by email from [email protected] on Aug. 16 and created an order-verification and scam-reporting page. It says customers should not trust a message merely because it mentions a legitimate purchase or mailing address.

SafePal’s response echoes the customer-data risk reported after Trezor’s shipping-provider exposure, where contact and delivery data, rather than a recovery phrase, created the immediate concern. In each case, the likely next step for an attacker is persuading the owner to surrender the secret that the dataset did not contain.

The risk can extend beyond email. SafePal’s guidance warns about fraudulent calls, text messages, letters, firmware-update requests and fake support sites. Someone receiving an unexpected contact should navigate to the company’s known website independently instead of clicking a link or scanning a QR code.

The company has engaged an independent security firm to validate its fix and review its order-processing systems. It did not say when that review would conclude or whether investigators had authenticated the reported sale claims.

No Wallet Theft Confirmed, but Buyers Need Guardrails

SafePal says an affected buyer does not need to replace a device or move assets solely because an order record was exposed. A wallet should instead be treated as compromised if its owner already entered a seed phrase or private key into a suspicious site, message or call, according to the company.

That is a different security path from the verified seed-generation weakness behind the Coldcard thefts, where observers traced actual Bitcoin drains. The SafePal disclosure is about customer information and the chance it creates for a later scam; it is not evidence that a hardware device or its cryptographic keys were broken.

The practical safeguard is simple but time-sensitive: never disclose recovery words, private keys or passwords, and verify any security message through a manually entered official address. A reported hardware issue, refund or delivery problem should not require a seed phrase, no matter how accurate the caller’s purchase details appear.

The Crypto Fear and Greed Index read 34, classified as Fear, in its latest reading. The broad market indicator does not measure SafePal’s incident, but it comes as security disclosures and phishing risks remain a central self-custody concern.

Fear & Greed Index

Aug. 20, 2026
34 Fear

The next evidence to watch is the independent review, whether SafePal verifies any sample of the claimed dataset and whether it reports confirmed fraud or wallet losses. As of its latest update, the supported facts are narrower: 39,798 order records were exposed, the dataset-sale claims are unverified, and no theft from SafePal wallets has been confirmed.

Stay up to date

Get the latest crypto insights delivered to your inbox

Fact-checked by: Daily Crypto Briefs Fact-Check Desk

Frequently Asked Questions

How many SafePal customers were affected by the order-data incident?

SafePal said approximately 39,798 customers who placed orders between March 2, 2025 and April 11, 2026 had order information accessed without authorization.

Were SafePal wallet seed phrases or private keys exposed?

SafePal says no. It said the incident did not involve seed phrases, private keys, wallet passwords or other wallet credentials, and that it found no evidence the incident compromised access to SafePal wallets or funds.

What customer data did the SafePal order-tracking flaw expose?

SafePal said the affected order information included names, email addresses, shipping addresses, phone numbers and purchase details. It said bank-account information, payment-card numbers, government IDs and wallet credentials were not involved.

What should an affected SafePal customer do?

Use SafePal's official incident page to verify an order, avoid links and QR codes in unexpected messages, and never disclose a seed phrase, private key or password. A user who already entered a seed phrase or private key into a suspicious site should treat that wallet as compromised.