SafePal, a provider of cryptocurrency hardware wallets, has announced a data breach affecting nearly 40,000 customers. The breach exposed personal order information for customers who made purchases between March 2, 2025, and April 11, 2026. The company stated that the incident did not compromise sensitive wallet credentials like seed phrases or private keys.
The stolen data includes customer names, email addresses, shipping addresses, phone numbers, and purchase details. SafePal has warned that this information could be used by malicious actors for targeted phishing and social engineering attacks. Reports of phishing emails and phone calls related to SafePal have already surfaced as early as May.
A threat actor is reportedly selling the compromised SafePal customer data on a cybercrime forum. The seller's claims align with the details provided by SafePal regarding the number of affected customers and the order period. The actor is offering to share specific order IDs and shipping countries as proof of the data's legitimacy.
SafePal notified all impacted customers via email on August 16 and has launched an online verification tool. This tool allows customers to check if their order details were part of the breach by entering their order number and shipping country. The company first received a report consistent with the incident in early May 2026.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Cryptocurrency hardware wallet provider SafePal reported a data breach affecting approximately 39,798 customers, exposing names, email addresses, shipping addresses, phone numbers, and purchase information. A threat actor is now claiming to sell this stolen data on a cybercrime forum. This breach could lead to targeted phishing and social engineering attacks against affected customers.