VERSE PRESS

Crypto News, Global First.

SafePal Discloses Data Breach Affecting Nearly 40,000 Customers

Hardware wallet provider says funds and private keys were not touched, but names and shipping addresses of tens of thousands of buyers are now exposed.

|

Crypto hardware and software wallet company SafePal disclosed on Sunday, August 16, that a security flaw in a third-party order-tracking plugin exposed the personal data of 39,798 customers who placed orders between March 2, 2025 and April 11, 2026. The exposed records include full names, physical shipping addresses, contact details, and purchase and order information. No cryptocurrency funds, private keys, seed phrases, payment card information, bank details, or government IDs were compromised.

The vulnerability functioned like a gap in a parcel-tracking system: a flaw in the plugin's authorization logic allowed any user to view another customer's order record simply by changing the order number in a request. This class of flaw is known in security as an Insecure Direct Object Reference (IDOR), where an application fails to verify that the person requesting a record actually owns it. SafePal says it has patched the vulnerability, engaged an independent third-party security auditor, and taken down more than 30 fraudulent websites and phishing links connected to the incident.

The company notified affected customers by email from security@safepal.com on the day of disclosure and launched a verification tool on its official website so users can confirm whether their data was included. SafePal also announced a new data retention policy: going forward, personal data in its order-processing system will be held for no more than 90 days from the date of collection. According to reporting by CoinDesk and Crypto World Headline, the company acknowledged the elevated risk facing affected users, noting that "exposed users face heightened phishing and impersonation risks," while also reassuring customers that "the core safety of its wallets stays intact." It advised anyone who may have shared seed phrases or private keys in response to a suspicious communication to treat their wallet as compromised and move assets to a new wallet immediately.

The company's SFP utility token, which is used for governance and transaction fee discounts within the SafePal ecosystem, was trading at roughly $0.21 with a market cap of approximately $117.6 million as of late July 2026, approximately two to three weeks before the disclosure. Post-disclosure price movement had not been tracked at the time of publication. The fully diluted supply of 500 million tokens is already in circulation. SafePal serves between 7 million and 20 million users across 127 countries and has shipped more than 500,000 hardware wallet units as of 2025. The company was founded in 2018 by CEO Veronica Wong and received the first hardware wallet investment from Binance Labs the same year.

The breach carries particular weight for users in South Asia and Africa, two regions where SafePal has meaningful penetration and where the consequences of physical address exposure can be severe. The Asia-Pacific region accounts for 42.3% of global cold wallet revenue, and India ranks among the top markets for hardware wallet adoption. Indian authorities recorded hundreds of crores of rupees in crypto fraud losses in 2025, overwhelmingly driven by phishing, impersonation, and social engineering rather than exchange hacks. A database of home addresses linked to hardware wallet purchases provides precisely the kind of targeting information that enables these schemes. In Africa, where roughly 75 million users hold crypto wallets and consumer data protection enforcement is limited, the risks are compounded further. Hardware wallet ownership in both regions often signals above-average asset holdings, which raises the value of each exposed record to a would-be attacker. SafePal's operational roots in Asia, reinforced by its Binance Labs incubation and CEO Veronica Wong's prominent presence at regional industry conferences, suggest a significant concentration of its user base across Southeast Asia as well. Coverage of the breach as breaking news by Indonesia's Pluang platform is a marker of meaningful SafePal penetration in that market.

The incident sits within a bruising stretch for hardware wallet vendors. In July 2026, a five-year-old firmware vulnerability in Coldcard wallets was exploited to drain approximately 1,367 BTC, making it the third-largest crypto hack of 2026. In January 2026, a payments partner for Ledger leaked customer names and contact details in a separate third-party breach. According to the Jameson Lopp database of known physical attacks on cryptocurrency holders, which tracks home invasions, robbery, and coercion events, such attacks increased by 75% globally between 2023 and 2025. Verified home addresses tied to hardware wallet ownership are precisely the kind of targeting data that enables those crimes, and the SafePal breach adds tens of thousands of such records to the pool of potentially exploitable information. The pattern that emerges across these incidents is consistent: the hardware itself may be secure, but the surrounding e-commerce infrastructure, the plugins, logistics systems, and payment processors, often is not.

SafePal has not disclosed the geographic breakdown of affected users, a transparency gap that matters for users trying to assess their own exposure. Developers and project operators integrating SafePal products, including projects participating in its $3 million Solana ecosystem grant program announced in February 2026, should now factor the company's vendor security posture into their ongoing due diligence. Analysts and investors tracking SFP should monitor price movement in the sessions following disclosure for any market reaction. SafePal has not yet published a full post-incident report.