SafePal data breach exposes nearly 40,000 users' information — is a hardware wallet less secure than a spare iPhone?
- Key Takeaway: Hardware wallet manufacturer SafePal suffered a data breach affecting approximately 39,800 users' order information due to an authorization flaw in its order tracking plugin. Wallet private keys and assets were not compromised. The incident highlights data security risks in peripheral areas of the hardware wallet supply chain, such as order processing and logistics, which could lead to targeted social engineering attacks.
- Key Elements:
- SafePal disclosed the vulnerability on August 16, impacting 39,798 customers. Order information from March 2025 to April 2026 was exposed, including names, email addresses, phone numbers, and physical addresses. However, mnemonic phrases, private keys, and bank card data were not affected.
- According to the official investigation, a scheduled program designed to clean historical order data failed to run due to a configuration error between September 2025 and April 2026, causing some data that should have been deleted to remain in the system and expanding the scope of the breach. The company has since shortened the data retention period to 90 days and introduced third-party security audits.
- In 2020, SafePal emphasized its privacy protection measures of deleting order information after six months of retention. However, this incident occurred precisely because the cleanup process failed, highlighting vulnerabilities in the execution of established security mechanisms.
- Similar incidents are not isolated: On August 13, another hardware wallet manufacturer, Trezor, experienced a data breach through a third-party logistics service provider, affecting the names, email addresses, phone numbers, and physical addresses of 11,742 customers. Neither incident directly compromised the wallets themselves.
- The order data breach enables attackers to precisely identify cryptocurrency asset holders and combine that with real identity information to launch targeted phishing or scam campaigns. SafePal has identified and taken down over 30 related counterfeit websites.
Original by Odaily Planet Daily (@OdailyChina)
Author: Asher (@Asher_0210)

On August 16, hardware wallet manufacturer SafePal stated that a plugin used in its order tracking feature had an authorization flaw, which, under specific circumstances, allowed external parties to gain unauthorized access to other users' order information. The incident affected approximately 39,798 customers, involving certain orders placed between March 2, 2025, and April 11, 2026. The leaked data included names, email addresses, phone numbers, shipping addresses, and purchase details.
SafePal also emphasized that the incident did not involve users' seed phrases, private keys, or wallet passwords, nor did it include credit card numbers, bank account details, or identity document information. To date, there is no evidence suggesting that this vulnerability directly led to wallet intrusions or asset theft. In other words, SafePal's wallet itself was not compromised; the breach occurred in the order system outside the wallet.
Six Years Ago, Privacy Was Highlighted; Now the Problem Lies in Order Data
SafePal has long been aware of the specific risks associated with hardware wallet order information.
After the massive Ledger user data breach in 2020, SafePal published a dedicated article outlining its privacy protection measures, which mentioned that order information for completed deliveries would be retained for 6 months before being deleted from the online system. At the time, SafePal also stated that it would ideally prefer not to hold users' personal information long-term, but as physical products, hardware wallets inevitably require collecting names and addresses during the shipping process.

Six years later, the problem SafePal encountered was precisely in this area.
According to official documentation, during its investigation, SafePal discovered that the program originally designed to periodically purge historical order data failed to operate normally between September 2025 and April 2026 due to configuration errors, causing some old order information that should have been cleared to remain in the system. The vulnerability allowed external parties to access orders, and the fact that some data that should have been purged still existed further expanded the potential scope of the breach.
Following this incident, SafePal has reduced the retention period for personal information in its relevant order systems to 90 days and plans to engage an independent third-party security firm to further audit its order processing systems.

Additionally, SafePal stated that the team received the first user report matching the characteristics of this incident as early as early May this year, but it was initially treated as an isolated case. As similar reports gradually emerged, the investigation scope expanded, and in July, a more comprehensive review of the order processing workflow was initiated, ultimately confirming that the issue stemmed from an authorization flaw in the order tracking feature.
SafePal has also become alert to the downstream risks posed by the order information leak. To date, SafePal has identified and taken down more than 30 phishing websites and malicious links associated with related scam activities.
Beyond SafePal, Trezor Also Experienced a User Data Leak
SafePal is not the only hardware wallet manufacturer to encounter such issues recently.
On August 13, just three days before SafePal disclosed its user information breach, another hardware wallet manufacturer, Trezor, suffered a similar data security incident. Trezor reported that a data breach at its third-party logistics service provider affected 11,742 customers, with names, email addresses, phone numbers, and full shipping addresses compromised, while partial information of another 1,947 customers was also exposed.
SafePal's issue originated from its order tracking feature, while Trezor's problem lay in the third-party logistics link. Neither incident directly touched private keys, yet both exposed users' names, contact details, shipping addresses, and other personal information. For hardware wallet users, once this information falls into the hands of attackers, it is not merely a privacy concern.
Hackers Didn't Breach the Wallet—They Bypassed It
The design logic of hardware wallets is essentially to add a layer of physical isolation to private keys. As long as users do not voluntarily surrender their seed phrases, attackers typically find it extremely difficult to steal assets from a hardware wallet through a single email or a malicious website alone.
However, social engineering attacks precisely circumvent this issue: If the technology cannot be cracked, the approach becomes finding ways to make users hand over the keys themselves. In the past, the biggest problem with such attacks was the lack of a trust foundation. Scammers did not know which wallet users held, nor whether users actually owned crypto assets, so they could only send phishing emails en masse, waiting for a few victims to take the bait.
After order and logistics data leaks, such attacks can become far more targeted. A hardware wallet purchase record is, in itself, a form of user screening. Attackers no longer need to guess "who owns crypto assets"—they directly obtain a pool of users who, at the very least, had self-custody needs, along with their real names, phone numbers, shipping addresses, and even specific purchase details.
This also gives crude phishing tactics far more room for sophistication. Compared to a generic message like "Your wallet has a security issue, please verify immediately," the credibility level is entirely different if the attacker can accurately state when you purchased a SafePal, which model you bought, which address the order was shipped to, and even know your phone number—then contact you with pretexts such as "your device has a risk and needs an upgrade" or "order refund."
Buying a Hardware Wallet Does Not Mean Buying Absolute Security
In this security incident, although the SafePal hardware wallet itself was not breached, for a hardware wallet manufacturer whose core selling point is "security," a user data leak alone is enough to damage customer trust.
Users purchase hardware wallets precisely to reduce reliance on third parties such as centralized exchanges and online wallets, and to truly hold their private keys in their own hands. However, as physical products, hardware wallets still depend on traditional service systems like e-commerce and logistics—from purchase and delivery to after-sales—making it difficult to completely avoid leaving behind information that can identify users.
Hardware wallet manufacturers like SafePal and Trezor can shorten data retention periods and strengthen order system security, and they can require partners to raise protection standards. Yet the risks in peripheral areas such as ordering and logistics are difficult to eliminate entirely. And when such incidents do occur, the trouble for users is that this information cannot simply be changed like a password. Email addresses can be re-registered, wallets can be regenerated, but real names and home addresses are hard to "reset."
On-chain investigator ZachXBT previously even stated bluntly on Telegram that all hardware wallets are "garbage" and that using a spare iPhone would be better. Such a judgment is clearly somewhat extreme, but the recent string of security incidents does raise the question once again: If users still need to identify phishing emails, guard against fake customer service, and protect their real identities after purchasing a hardware wallet, then what exactly does the hardware wallet solve?

Hardware wallets address the risk layer of private key custody, not all security issues. For hardware wallet manufacturers, future competition may no longer be just about how strong the secure chip is or whether the private key ever leaves the device, but also about how much user data is collected, how long it is retained, and whether they can regain user trust after an incident. For users, a hardware wallet is not an all-encompassing insurance policy; heightened awareness of risk prevention is equally essential.


