SafePal Discloses Data Breach Affecting Nearly 40,000 Hardware Wallet Customers
Singapore-based crypto wallet maker SafePal confirmed on August 16 that an authorization flaw in a third-party order-tracking plugin exposed the personal information of 39,798 customers over a 13-month period, raising fresh concerns about data security across the hardware wallet industry.
Founded by Veronica Wong and incubated by Binance Labs, SafePal has grown into one of the most widely used hardware and software wallet providers in the Binance ecosystem, with particular reach in emerging markets across Asia and Africa.
The exposed data includes customer names, physical shipping addresses, and contact details from orders placed between March 2, 2025 and April 11, 2026. SafePal stated that no seed phrases, private keys, passwords, financial account information, or crypto funds were accessed. "All private keys, seed phrases, and crypto assets remain completely safe," the company said in its official disclosure. SafePal did not provide a named spokesperson for the announcement.
What Went Wrong
The vulnerability was classified as an IDOR-style flaw, short for Insecure Direct Object Reference.
In plain terms: a plugin SafePal used to manage customer order tracking failed to verify whether a logged-in user was authorized to view a specific order. By changing the order number in a web request, an attacker could pull up another customer's order details entirely. Think of it as a parcel-tracking system that lets any user view anyone else's receipt by typing in a different tracking number.
SafePal said it has since patched the flaw, engaged an independent third-party security auditor, and committed to limiting data retention in its order systems to a maximum of 90 days going forward. The company also identified and removed more than 30 fraudulent websites and phishing links connected to the incident, a detail that suggests attackers had already begun operationalizing the stolen data before the public disclosure.
Affected users can verify their status through a check tool SafePal has published on its website. The specific URL for the check tool was not confirmed at time of publication.
Why Affected Users Face Real Risk
The absence of financial data in the breach does not eliminate danger. SafePal itself warned affected customers that they face "heightened phishing and impersonation risks." Physical address exposure is the central concern. Hardware wallet buyers represent a self-selecting group of users who hold crypto assets in self-custody, meaning attackers now have a list of people likely to hold significant crypto, along with their home addresses.
The company advised anyone who may have shared seed phrases or private keys through suspicious communications to treat their wallet as compromised and move assets to a new wallet immediately.
A Concentrated Risk in Emerging Markets
SafePal serves more than 30 million users across 200-plus countries and regions, and its user base skews heavily toward non-Western markets.
The company's products, particularly the S1 hardware wallet priced under $50, have found traction in South Asia and Africa as an accessible self-custody option. India ranks first globally on the Chainalysis 2025 Crypto Adoption Index and has over 100 million active crypto users. Pakistan ranks third. Nigeria ranks sixth and leads Africa in crypto activity. Kenya is among Africa's fastest-growing crypto markets, with SafePal mobile app downloads rising across East Africa. All of these markets have documented phishing and social engineering infrastructure targeting crypto holders, including SMS-based scams and WhatsApp impersonation schemes, according to the TRM Labs 2026 Crypto Crime Report.
Physical address exposure carries additional weight in some of these regions. Coverage of a separate Trezor breach, confirmed on August 14 when Trezor disclosed that its logistics partner ShipMonk had exposed data for more than 13,000 customers, cited documented cases of home invasions and kidnappings targeting identified hardware wallet owners in France and the United States.
In urban centers such as Lagos and Nairobi, where crypto-targeted physical crime has been recorded, the stakes of address exposure extend beyond fraud to personal safety.
SafePal notified affected users via email. That channel may prove insufficient for users in markets where email engagement is low. In-app alerts and local-language communications would represent stronger practice in future incidents, a view that reflects broader commentary on digital security communication in high-growth emerging crypto markets. Regulatory bodies in affected markets, including Nigeria's Securities and Exchange Commission and South Africa's Financial Sector Conduct Authority, may also take an interest in the incident given both countries' expanding crypto oversight frameworks.
Part of a Broader Pattern
The SafePal disclosure arrives days after that Trezor incident. Trezor confirmed on August 14 that the breach at its logistics partner ShipMonk exposed personal data for more than 13,000 customers, the first time in Trezor's 13-year history that physical addresses and phone numbers were leaked. The affected customers were spread across seven countries: the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal.
In January 2026, Ledger disclosed that its e-commerce partner Global-e had exposed customer names and contact details.
The most severe incident this year remains a firmware bug in Coldcard wallets, traced back to March 2021, which weakened seed randomness and allowed attackers to drain approximately 1,816 BTC (about $116 million) from more than 5,200 addresses.
July 2026 saw an estimated $247 million stolen across all crypto incidents, the second-worst month on record this year.
For SafePal, the 39,798 affected accounts represent just 0.13 percent of its total user base. But that group is concentrated among hardware wallet purchasers, a cohort that is by definition more likely to hold significant crypto assets.
SafePal has not confirmed whether the stolen data has appeared on dark web markets, and the identity of the attacker remains unknown. Those are the key open questions as the story develops. Verse Press will continue to follow this story as new details emerge.
Token Market Context
SafePal's native token, SFP, is a BEP-20 asset on BNB Smart Chain used for governance, ecosystem incentives, and transaction fee discounts within the ecosystem. SafePal's early backing by Binance Labs helps explain why SFP's primary trading pair is hosted on Binance and why BNB Smart Chain serves as its native chain.
As of the disclosure date, SFP was trading at approximately $0.21, with a circulating market cap near $117.6 million and a CoinGecko rank of around 228. Trading volume on the primary SFP/USDT pair on Binance sat at roughly $81,600 in the prior 24 hours.
No material price movement was recorded following the announcement, consistent with the breach not involving any loss of crypto funds.