Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

u+1u+1reddit+1SafePal, the hardware wallet maker backed by Binance Labs, has confirmed a security incident that exposed the personal order data of approximately 39,798 customers, raising fresh concerns about physical security risks facing crypto hardware wallet owners.
The breach stemmed from a vulnerability in SafePal's order-tracking plug-in, which allowed unauthorized access to information belonging to customers who placed orders between March 2, 2025, and April 11, 2026. Exposed data includes customer names, email addresses, shipping addresses, phone numbers, and purchase details.u+2
SafePal said it has fixed the defect and notified all affected customers individually by email. The company confirmed that hardware wallets, private keys, seed phrases, wallet passwords, bank account details, payment card numbers, and government-issued identification numbers were not compromised.facebook+1
The incident first surfaced on Reddit in May 2026, when SafePal S1 owners began reporting that scammers were contacting them with specific details about their orders — including device models, quantities, delivery addresses, and payment methods used at checkout. At the time, SafePal initially deflected responsibility, stating it does not retain personal data indefinitely and deletes purchase records on a regular cycle.cryptobriefing+2
The formal disclosure, which named approximately 39,798 affected customers, appears to have followed months of user complaints and external pressure. The breach draws comparisons to the 2020 Ledger data leak, which exposed information on hundreds of thousands of customers and led to years of targeted phishing campaigns. It also comes days after rival hardware wallet maker Trezor confirmed a breach at one of its shipping partners that exposed data on 13,689 customers.beincrypto+2
SafePal warned that exposed order details could fuel sophisticated phishing attempts, including fraudulent phone calls, fake firmware-update requests, and bogus customer-support communications. The company stressed it will never ask users for their 12- or 24-word recovery phrases, PINs, or private keys under any circumstances.u
Because the SafePal S1 operates as a fully air-gapped device without Bluetooth, WiFi, NFC, or USB connectivity, the wallet hardware itself remains secure. But for the roughly 40,000 customers whose names, addresses, and purchase histories are now in the hands of bad actors, the risk of social engineering attacks is immediate and ongoing.cryptobriefing