Hardware Wallet Maker SafePal Leaks Private Buyer Details for Nearly 40,000 Customers

Crypto wallet maker SafePal discloses a software glitch that exposed shipping addresses and contact details for 39,798 buyers.
SafePal Delivery

SafePal fixes an order tracking software bug that exposed names and shipping addresses for nearly 40,000 customers.

Popular cryptocurrency hardware wallet maker SafePal has revealed a serious data leak that exposed the personal contact details and delivery addresses of 39,798 customers.

A software error in an order tracking tool used on the company’s online shop allowed unauthorized visitors to view private buyer records.

The leaked information includes real buyer names, home delivery addresses, email addresses, phone numbers, and purchase histories.

While no secret recovery phrases or digital coins were stolen, security experts warn that having home addresses linked to crypto purchases creates serious risks for targeted scam calls, fake mail, and phishing attacks.

The official security update was disclosed on August 18, 2026, after the company completed an internal audit and began emailing affected buyers directly.

The exposed records belong to customers who purchased physical storage devices from the company between March 2, 2025, and April 11, 2026.

Shortly after the company discovered the bug, a cybercriminal posted on an online hacker forum offering to sell the stolen buyer database to the highest bidder.

The primary cause of the incident was a coding flaw in an external software plug-in used to track package shipping updates.

Under specific conditions, the broken tool failed to verify who was looking at order pages, allowing an outside user to view another customer’s private order receipts.

Additionally, a technical error in the company’s automated file cleaning routine caused older order records to stay on active servers much longer than intended, expanding the number of affected customers.

Reassuring users that their digital money remains safe, SafePal stated, “This incident did not involve your seed phrase, private keys, wallet password, or other wallet credentials, bank account information, payment card numbers, or government-issued identification numbers”.

See Also: US Cyber Agency Flags Danger in Popular AI Tool Ray After Hackers Attack

Emphasizing that digital funds were not compromised, the hardware maker added, “SafePal never requests, collects, processes, or stores such information from customers. No evidence has been found that the incident itself compromised access to SafePal wallets or funds”.

Warning affected users to be on high alert for fake messages and impersonators, the company cautioned that “affected order information may be used for targeted phishing and impersonation attempts, and we strongly encourage customers to remain vigilant”.

Advising users on what actions to take, the company clarified that you should not need to move your assets solely because your order information was affected. However, if you have already shared or entered your seed phrase or private key in response to a suspicious message, website, phone call, or letter, treat that wallet as compromised”.

To protect users moving forward, SafePal has fixed the broken software, removed older customer records from its main internet servers, and hired an independent security firm to inspect its order systems.

The company has also shortened how long it stores customer shipping details to 90 days, helping prevent similar order leaks from putting crypto owners at risk in the future.

About the Author

Jennifer Sakmufuwo Baba

Jennifer Sakmufuwo Baba is a tech analyst, senior staff, and writer covering artificial intelligence, cybersecurity , and emerging technologies at TechRegard. Based in Nigeria, she's passionate about translating complex tech developments into compelling, accessible stories for diverse audiences. Her work focuses on how technology shapes innovation across Africa and globally.