The hardware wallet provider SafePal has officially disclosed a security breach involving its order tracking plugin, which resulted in the exposure of personal information belonging to nearly 40,000 customers. The incident, which occurred over a span of more than a year, highlights the ongoing challenges of securing the e-commerce infrastructure surrounding cold storage solutions. While personal contact details were compromised, the company has confirmed that the underlying security of the digital assets held on their devices remains intact.
Scope of the Data Breach and Vulnerability Details
According to the official report, the vulnerability allowed unauthorized access to the purchase records of 39,798 users who placed orders between March 2, 2025, and April 11, 2026. The leak was localized to a specific plugin used for logistics and order tracking rather than the core wallet firmware or the SafePal App. The exposed data includes:
- Full names and email addresses
- Physical shipping addresses
- Phone numbers
- Purchase history and order details
SafePal technicians identified the flaw and have since implemented a permanent fix, alongside additional security layers to prevent future exploits of their web-based plugins. The company has emphasized that the breach was restricted to administrative order data and did not involve any interaction with the blockchain itself or the internal hardware security modules of the S1 or X1 wallet models.
Asset Security and User Recommendations
Despite the leak of logistical information, SafePal maintains that the core security of user funds was never at risk. The company clarified that the most sensitive cryptographic data remains secure.
Sensitive information such as seed phrases, private keys, wallet passwords, and bank accounts were not affected by this incident. Assets stored on the devices are completely safe.
SafePal has initiated a notification campaign, contacting all impacted individuals via email. Furthermore, the firm has launched a verification tool on its official website, allowing users to check their status by entering their order number and country of delivery. The primary concern for affected users now shifts toward phishing attempts and social engineering, as malicious actors may use the leaked contact information to impersonate support staff.
Conclusion
The resolution of this vulnerability marks a critical step in restoring trust for SafePal users, though the incident serves as a reminder of the risks associated with the physical supply chain of cryptocurrency hardware. Users are urged to remain vigilant, ignore unsolicited communications requesting security credentials, and strictly adhere to the rule of never sharing a mnemonic phrase or private key with any third party. As the industry matures, the security of auxiliary services like order tracking will remain just as vital as the security of the blockchain protocols themselves.
Frequently Asked Questions
Quick answers to the most common questions about this topic.