Hardware wallet owners make a deliberate choice to keep crypto off the internet. Now the Binance-affiliated company behind SafePal has confirmed that a vulnerability in its e-commerce infrastructure exposed the names, home addresses, and phone numbers of nearly 39,798 customers — anyone who placed an order between March 2, 2025 and April 11, 2026. The wallets are fine. The seed phrases are fine. Your personal details, however, just became someone else’s files exposed asset.
What Actually Leaked – and What Didn’t
An authorization flaw in a third-party order-tracking plugin let unauthorized parties view another customer’s purchase information.
The exposed data includes:
- Names
- Email addresses
- Phone numbers
- Shipping addresses
- Purchase details
SafePal confirms that seed phrases, private keys, wallet passwords, payment card numbers, and government IDs were never part of the leak. The company patched the vulnerability, capped future data retention at 90 days, and took down more than 30 fraudulent sites connected to the incident. Affected customers received notification emails from [email protected] on August 16, and an official verification page lets you check your exposure status using your order number and shipping country.
“While your SafePal wallet, seed phrase, and private keys are secure; we identified a flaw in the order-tracking plug-in that led to unauthorized access to information of a subset of customers.” — SafePal, public disclosure
Consider what that leaked list actually represents. Roughly 40,000 people confirmed to own a hardware wallet — meaning confirmed to hold crypto worth protecting — with their physical addresses attached. That’s not just a data breach. That’s a Yelp review for criminals: it tells attackers exactly who has something worth stealing and where they live. Phishing messages can now reference your real order details, your actual device model, your correct address — making the generic “your account has been compromised” spam look almost charming by comparison. Per Forbes, pairing this with a simultaneous Trezor-related fraudulent letter campaign puts roughly 53,487 hardware wallet owners exposed across a four-day span.
The Response Timeline Deserves Scrutiny
SafePal received its first vulnerability report in early May — the public didn’t find out until August 16.
| Milestone | Timing |
|---|---|
| Initial vulnerability report received | Early May |
| Full investigation opened | July |
| Public disclosure | August 16 |
The company did eventually patch the flaw, notify affected users individually by email, and dismantle more than 30 phishing sites, which is worth acknowledging. But three months is a long time for a curated list of hardware wallet owners, complete with home addresses, to be quietly available to whoever found the flaw first — not unlike the scale of harm seen in any major database leak involving physical addresses.
As one consumer security blogger framed it: what’s affected is your privacy, not your cryptographic key — but privacy exposure is precisely how the key eventually gets threatened.
This Isn’t Just a SafePal Problem
Ledger faced a comparable third-party customer data incident earlier in 2026, revealing a sector-wide gap between cryptographic strength and data hygiene.
The pattern holds across the hardware wallet industry. Ledger dealt with a similar third-party breach earlier this year, reminiscent of how hackers steal password vaults through credential exploits. The so-called “$5 wrench attack” — crypto-community shorthand for physical coercion to extract keys — becomes significantly more viable when attackers know your address and know you own a hardware wallet. These companies build excellent cryptographic hardware. Their e-commerce infrastructure is, reportedly, another matter entirely.
The practical steps are straightforward:
- Never share your seed phrase regardless of how official the request looks — no legitimate SafePal communication will ever ask for it.
- Ignore unsolicited replacement devices, emergency firmware updates, or QR codes claiming to be from SafePal.
- Type URLs manually rather than following links in unexpected messages.
- If you’ve already entered your seed phrase somewhere suspicious, treat that wallet as compromised: create a new one on a trusted device and move your assets immediately.






























