The hardware wallet maker SafePal said on Sunday (16) that an authorization flaw in its e-commerce infrastructure exposed personal data of about 40,000 customers. The issue affected the order tracking system and reached purchase records made between March 2, 2025, and April 11, 2026.
The company said the exposed data includes names, emails, delivery addresses, phone numbers and purchase details. The firm said private keys, recovery phrases, wallet passwords, card numbers and access to wallets were not among the leaked data and that it found no evidence that the flaw was used to compromise wallets or steal crypto assets.
The manufacturer attributed the leak to two factors: an authorization flaw allowed unauthorized access to customer records; a configuration error prevented the scheduled data cleanup process from running between September 2025 and April 2026. The retention error kept old records in the system for longer and expanded the set of accessible data.
The data retention contradicts the policy SafePal itself disclosed in 2020, which provided for keeping information on delivered orders for 30 days and monthly destruction of records.
The company said it has already removed more than 30 fake websites and phishing links targeting customers and warned of risks of phishing, social engineering and physical security.
Series of incidents
The SafePal case comes after other incidents involving hardware wallet makers. Trezor disclosed that a breach at its carrier exposed data from nearly 14,000 customers. Ledger had order data exposed through payment processor Global-e.
The Coldcard incident caused the largest financial loss. A flaw in the key generation process allowed attackers to drain more than US$ 100 million in Bitcoin, in multiple attack waves that began in late July.
The co-founder of Binance, Changpeng Zhao, said leaks with names, phone numbers, emails and delivery addresses can increase risks of phishing, social engineering and physical attacks. Chainalysis recorded an increase in so-called attacks involving physical violence, including kidnappings and home invasions to force the transfer of crypto assets. In the first half of 2026, the thefts totaled about US$ 30 million, after the record US$ 58 million in 2025.
Chainalysis data also show that home invasions accounted for 37% of violent attacks on cryptocurrency holders in 2026. Kidnappings accounted for more than half of the recorded incidents.
The recent cases indicate that hardware wallets do not work as a single line of defense. Beyond protecting private keys, users remain exposed to firmware flaws, database leaks and problems in the self-custody infrastructure.



