A flaw in SafePal's order system left thousands of customer records exposed, highlighting how hardware wallet users now face escalating threats from both data leaks and direct crypto theft
SafePal, a major hardware wallet provider, has disclosed a security incident that exposed personal information for nearly 40,000 customers. The breach, which stemmed from an authorization flaw in the company's e-commerce infrastructure, allowed unauthorized access to order records containing names, email addresses, shipping details, phone numbers, and purchase information. According to SafePal, the vulnerability affected purchases made between March 2, 2025, and April 11, 2026.
How the Breach Unfolded
The incident was not limited to a single technical failure. SafePal reported that a configuration error prevented its scheduled data cleanup process from running between September 2025 and April 2026. As a result, older order records remained in the system longer than intended, expanding the scope of the breach. This retention issue contradicted SafePal's previous privacy policy, which stated that customer data would be deleted 30 days after order fulfillment. The combination of the authorization flaw and the failed cleanup process meant that a larger pool of customer information was accessible to unauthorized parties.
Wallet Credentials Remain Unaffected
SafePal emphasized that no private keys, recovery phrases, wallet passwords, or payment card numbers were exposed in the breach. The company said it found no evidence that the vulnerability was used to compromise customer wallets or steal cryptocurrency. Still, the exposure of personal data-including home addresses and contact details-raises concerns about targeted phishing, impersonation, and even physical security risks for hardware wallet owners. SafePal stated it had already taken down more than 30 fraudulent websites and phishing links targeting its users in the wake of the incident.
Escalating Hardware Wallet Threats
This breach is the latest in a series of security incidents affecting hardware wallet providers and their customers. In recent months, Trezor reported a breach at its shipping partner that exposed information for nearly 14,000 users, while Ledger customers were impacted by an order-data leak involving a third-party payment processor. The most severe financial loss came from a Coldcard vulnerability, which enabled attackers to steal over $100 million in Bitcoin by exploiting a flaw in the wallet's key-generation process. These incidents have shifted the threat landscape for hardware wallet users from isolated data leaks to direct theft of digital assets.
Security experts warn that exposed personal data can be leveraged for phishing attacks, social engineering, and even physical threats. According to Chainalysis, so-called "wrench attacks"-where criminals use violence or coercion to force victims to transfer crypto-resulted in $30 million in reported thefts in the first half of 2026, with home invasions accounting for 37% of violent crypto attacks tracked that year. The growing sophistication of these attacks underscores the need for robust data protection and user vigilance.
Hardware wallet users are not the only ones facing pressure from security incidents. As EgonCoin previously reported, Riot Platforms recently sold Bitcoin reserves to fund a $9.1 billion AI data center lease, highlighting how operational and treasury risks can intersect with broader security and infrastructure challenges in the crypto sector. Riot's move reflects the complex environment in which both companies and users must navigate evolving threats and operational demands.
According to SafePal, the company is conducting an independent review of the incident and has updated its internal processes to prevent similar failures. The firm also reiterated that its hardware wallets themselves were not compromised, and that the breach was limited to e-commerce order data.
Based on available data, the Coldcard incident remains the largest confirmed hardware wallet-related theft to date, with over $100 million in Bitcoin stolen since late July 2026. In contrast, the SafePal, Trezor, and Ledger breaches have primarily resulted in the exposure of customer information rather than direct loss of funds. Security researchers continue to monitor for signs that stolen data is being used in targeted attacks against crypto holders.
Hardware wallet providers and their users now face a dual challenge: protecting sensitive customer data stored in e-commerce and support systems, and ensuring that wallet firmware and key-generation processes remain secure against evolving attack vectors. The recent wave of incidents demonstrates that self-custody, while critical for many crypto users, does not eliminate all risks-especially when personal information is retained or mishandled by service providers.
Hardware wallets are designed to keep private keys offline and out of reach from most digital threats. But as recent breaches show, the broader infrastructure supporting these devices-including order management, shipping, and customer support-can introduce new vulnerabilities. Users should remain alert to phishing attempts, fraudulent websites, and unsolicited communications, especially if their personal information has been exposed in a breach. Companies, meanwhile, face increasing pressure to minimize data retention, strengthen access controls, and respond quickly to emerging threats in order to protect both their customers and their reputations.