SafePal Discloses 13-Month Data Breach Affecting Nearly 40,000 Hardware Wallet Customers
Hardware wallet company SafePal revealed on August 16 that an authorization flaw in a third-party plugin exposed the personal and shipping data of 39,798 customers over a period stretching from March 2025 to April 2026, more than a year before the company detected the intrusion.
The breach did not touch on-chain funds. Seed phrases, private keys, wallet passwords, payment card numbers, bank account information, and government ID data were not stored by SafePal and were not exposed. What was compromised is the type of information that hardware wallet buyers must hand over to receive a physical product: full names, email addresses, shipping addresses, phone numbers, and order details. That combination makes the incident a serious phishing and physical security risk for affected users, even though their crypto holdings remain intact.
SafePal said the root cause was a broken authorization control inside a third-party order-tracking plugin connected to its e-commerce system. The flaw, known in security research as Broken Object Level Authorization (BOLA) and also widely referenced as Insecure Direct Object Reference (IDOR), allowed one logged-in user to pull up order records belonging to a different customer. Attackers exploited this access externally. The company said it has since removed the plugin, hired an independent security firm to audit the fix, and reduced its personal data retention window to 90 days. It also identified and had more than 30 fraudulent websites and phishing links taken down.
Affected customers are receiving individual emails from security@safepal.com with the subject line: "[Important] Your SafePal Order Information Has Been Affected." SafePal has also deployed a self-check tool for users who want to verify whether their accounts were included. In its communications to affected customers, as summarized by CoinDesk, the company was direct about the residual risk: users "face heightened phishing and impersonation risks due to the availability of their personal information."
Regional Risk: South Asia and Africa
SafePal markets its products across 196 countries and has positioned its hardware wallet as an affordable option in markets where competitors like Ledger and Trezor price out many users. The SafePal S1 launched at roughly $49, well below the entry point for most rival devices. That affordability strategy has driven adoption across South Asia and sub-Saharan Africa, and it is users in those regions who now face some of the sharpest downstream risks.
In India, the Digital Personal Data Protection Act (DPDPA), which has been coming into force since 2023, requires data fiduciaries processing Indian residents' data to notify both users and regulators of breaches in a timely manner. A 13-month detection gap may draw scrutiny from India's Data Protection Board once its enforcement mechanisms are fully operational. Beyond regulatory exposure, Indian users whose shipping addresses are now accessible to bad actors face elevated physical risk. Targeted robberies and coercive attacks against known crypto holders, sometimes called "wrench attacks," have been documented in urban centres across India.
In Africa, the picture is comparably serious. South Africa accounts for roughly 92% of ransomware detections on the continent and approximately 70% of business email compromise incidents, according to Interpol. Separately, IT-Online reported in August 2026 that phishing represents approximately 45% of all cyberattacks recorded within South Africa, while Interpol data attributes approximately 40% of all African phishing detections to South Africa. For Nigerian, Kenyan, and South African SafePal customers, the combination of a confirmed name, a phone number, a shipping address, and the implicit signal that the person owns crypto hardware represents a ready-made targeting package. Phone number exposure in particular creates immediate SIM-swap risk, a well-documented attack method across East and West African mobile networks.
Token Markets
SafePal's native token, SFP, trades at roughly $0.23 with a market capitalization of approximately $115 million. The token's maximum supply of 500 million units is fully in circulation. No immediate price reaction to the breach disclosure was visible in available data, consistent with how crypto markets have historically treated data-only incidents that stop short of on-chain fund loss.
A Pattern Across the Hardware Wallet Industry
The SafePal disclosure arrives during an especially bruising stretch for hardware wallet security. In July and August 2026, a firmware flaw in Coldcard's version 4.0.1 (first released in March 2021, leaving affected devices exposed for approximately five years) enabled attackers to drain approximately 1,816 BTC, worth roughly $116 million, across more than 5,200 addresses in four waves starting July 30, 2026. The vulnerability caused devices to generate wallet seeds using weak software randomness rather than hardware entropy, reducing cryptographic strength from 128 bits to as little as 40 bits. Attackers then derived or cracked those weakened seeds to access funds. That exploit contributed to an estimated $247 million in total crypto theft during July alone. Ledger has faced its own data exposure incidents, notably in 2020 and again in January 2026 when a breach at third-party payments partner Global-e exposed customer data, with each incident followed by multi-year phishing campaigns against customers whose details were leaked. The 2020 Ledger breach alone exposed data linked to approximately 272,000 customers, with a Shopify employee separately leaking records from approximately 292,000 additional customers, providing a large and durable dataset that bad actors continued to exploit for years.
TRM Labs, analyzing the Coldcard incident, noted that "self-custody relocates risk rather than eliminating it." SafePal's breach reinforces that point from a different angle: the on-chain layer held, but the logistics layer did not.
The Ledger precedent suggests that the risk to SafePal users will not dissipate quickly. Data from the 2020 Ledger breach was still being used in targeted phishing campaigns years after initial exposure. Users in high-phishing-risk markets should treat all unsolicited contact referencing their SafePal order as suspicious, regardless of how convincing the sender's details appear.