SecurityAugust 18, 2026

SafePal breach: 39,798 customers, keys untouched

SafePal reports a flaw in its order system: names, addresses and phone numbers of 39,798 customers exposed. Seed phrases were not. Checked 18 Aug 2026.

Article image for: SafePal breach: 39,798 customers, keys untouched

SafePal disclosed a data breach on Sunday 17 August in which the names, email addresses, phone numbers and shipping addresses of 39,798 customers were exposed. Seed phrases, private keys and payment details were not involved; the leak concerned webshop order data. Anyone who ordered a wallet between 2 March 2025 and 11 April 2026 is in the file. The wallets themselves were not compromised.

What happened

The flaw sat in a plug-in that tracks orders. By changing the order number in the link, someone could pull up another customer's order — name, address, phone number, what they had bought. Somebody else's receipt, in effect, but tens of thousands of times over.

SafePal says it has patched the hole, brought in independent auditors, cut its retention period for order data to 90 days, and had more than thirty fraudulent websites and phishing links taken down. Affected customers were notified from security@safepal.com.

Why this is dangerous, even without stolen keys

"No keys were taken" sounds reassuring and is only half so. What did leak is a list of people confirmed to hold crypto, complete with home address and phone number. That is precisely the file two kinds of attacker are waiting for.

The first is phishing. A message that knows your first name, your wallet model and the month you ordered is far more convincing than the generic email everyone recognises. SafePal itself warns of calls, texts, refund offers and fake support. According to The Record, the data is already being advertised on dark web forums.

The second is physical. CertiK counted a third more so-called wrench attacks — robberies targeting people known to hold crypto — in the first half of 2026, accounting for $124 million in losses. A list of wallet buyers' addresses is usable material for that.

The third wallet brand in short order

SafePal is not alone. Trezor and Coinkite, the maker of the Coldcard, also had incidents in recent weeks. At Coldcard it went further than data: a firmware fault made seeds guessable, after which 1,367 bitcoin were stolen and the count later rose to 1,816 bitcoin.

The difference matters. At Coldcard the problem was in the device and money disappeared. At SafePal it was in the shop around it and information disappeared. Both belong in the same risk assessment: you trust a hardware wallet not only with your keys, but with your address details.

What to do now

  • Assume every message about your wallet order is fake until you have established otherwise. Never call or email back using details taken from the message itself.
  • Never enter your seed phrase anywhere. No manufacturer, retailer or support agent ever asks for it, and that is the only rule you need to remember.
  • If you have already entered your seed after an email or a call, treat the wallet as compromised and move your holdings to a new wallet with a fresh seed. That is SafePal's own advice too.
  • If you are ordering a new wallet, look at what data the retailer keeps and for how long. Hardware wallets at BTC Direct Shop sets eleven brands side by side.

What this does not fix: your address has already leaked, and you cannot take that back. The only lever you hold is how you respond when someone makes contact.

Frequently asked questions

Is my crypto gone if I am in the file? No. According to SafePal, no seed phrases, private keys, bank details, card numbers or government-issued IDs were accessed. Your holdings are unaffected.

How do I know whether I am affected? SafePal emailed affected customers from security@safepal.com. It concerns orders placed between 2 March 2025 and 11 April 2026. Do not click links in such an email; go to the site yourself.

Should I replace my wallet? Only if you have shared your seed phrase. The device itself was not compromised in this incident.

Why is an address leak worse than it looks? Because it confirms that you hold crypto, and where you live. That combination makes both targeted phishing and a robbery easier.

Sources and verification

Facts checked on 18 August 2026 against two independent sources: CoinDesk (16 August 2026, for the exact figure of 39,798 and the list of data not exposed) and The Record (17 August 2026, for the nature of the breach, the dark web listing and CertiK's wrench attack figures). Victim counts often rise in early reporting; we will update this article if SafePal revises its figure.

Investing in crypto carries risk. Values can fluctuate sharply and you may lose part or all of your investment. This article is information, not investment, tax or legal advice.

This page contains affiliate links. If you use them, CryptoCode may receive a commission. This costs you nothing extra and does not determine what appears here.

#safepal#datalek#hardware wallet#phishing#security