A total of 39,798 customers of hardware wallet manufacturer SafePal are now facing threats from an unexpected source. On August 16, 2026, the company disclosed a user data leak caused by an authorization flaw in an order tracking plugin.
This security flaw opened access to customer data entered between March 2, 2025, and April 11, 2026. The information that fell into the hands of hackers includes full names, email addresses, physical shipping addresses, phone numbers, and purchase details. Nevertheless, user crypto assets are confirmed to be untouched. SafePal emphasized that crucial information such as seed phrases, private keys, wallet passwords, payment card numbers, and bank accounts remains safe from this leak.
Overlapping System Errors
The scale of the leak, which affected tens of thousands of users, was further exacerbated by another internal system failure. According to the company, their scheduled data deletion process had stopped working due to a configuration error spanning from September 2025 to April 2026.
Customer data that should have been regularly deleted instead accumulated in the order tracking system. This erroneous accumulation extended the timeframe and caught more victims when hackers exploited the plugin’s authorization flaw. In response to this vulnerability, SafePal has now cut the retention period for order data to a maximum of 90 days and hired an independent third-party security firm to validate their network fixes.
Reports Initially Ignored
A notable aspect of this data leak is the company’s slow response. SafePal had actually received initial reports from users regarding phishing attacks related to this incident since early May 2026. Instead of checking for system flaws, they initially dismissed these reports as isolated phishing cases experienced by the users themselves.
A formal internal investigation only began in July 2026. This step was taken after escalating user reports continued to grow, eventually leading to the confirmation of a critical flaw in the order tracking plugin.
Although SafePal has identified and taken down more than 30 phishing sites and fraudulent links related to this leak, the real threat still lingers. Armed with real names, home addresses, and accurate order history, attackers can launch far more convincing phishing attempts. For users who have already entered their seed phrase into any suspicious site recently, the warning is clear: treat that wallet as compromised and immediately transfer the remaining assets to a new wallet before it is too late.
Reported from crypto.news.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




