The crypto wallet sector is facing a new data leak. SafePal confirmed on Saturday that a flaw affecting an order tracking plugin had allowed unauthorized access to information of 39,798 custo
The crypto wallet sector is facing a new data leak. SafePal confirmed on Saturday that a flaw affecting an order tracking plugin had allowed unauthorized access to information of 39,798 customers. The data concerns orders placed over more than one year and includes several personal details. However, no wallet identifiers, funds, recovery phrases or private keys were compromised, according to details provided by the company in its official announcement published on Saturday.
In brief
- A data leak affected 39,798 SafePal customers who placed an order between March 2025 and April 2026.
- Exposed information includes names, emails, delivery addresses, phone numbers and purchase details.
- Private keys, recovery phrases, passwords and crypto funds were not compromised according to SafePal.
- The incident follows leaks at Trezor and Ledger, while physical attacks on cryptocurrency holders are increasing.
A flaw in the order tracking system
In a statement published on X , SafePal declares that the breach concerns customers who made an order between March 2, 2025 and April 11, 2026. The attackers were able to view their names, email addresses, delivery addresses, phone numbers and purchase details. However, data directly related to the security of wallets remain outside the identified scope. Recovery phrases, private keys, passwords and wallet identifiers were not affected.
Similarly, SafePal specifies that bank details, card numbers and official identity documents remain protected. The company claims to have fixed the flaw and contacted the affected customers by email. It has also created a page allowing users to check if their data is among the exposed information. Finally, the company plans to publish new information on its blog during the ongoing investigation.
SafePal faces physical targeting risk after data leak
Even without direct theft of cryptocurrencies, this leak raises a particular question for Bitcoin holders. The association between an identity, an address and a crypto purchase can provide useful clues to criminals. The risk takes on a more concrete dimension with the increase of physical attacks directly targeting holders. These assaults seek to obtain digital assets under threat or coercion.
Secure your cryptos with SafePalThis link uses an affiliate program.Chainalysis recorded 46 violent incidents in the first half of 2026, with more than 30 million dollars stolen. According to available data, home burglaries are becoming more frequent than kidnappings. In this context, SafePal joins several manufacturers whose users have already suffered the consequences of a leak. A few days before this case, Trezor reported a compromise affecting about 13,700 customers after a flaw at its delivery partner ShipMonk.
A growing pattern of data leaks across the hardware wallet sector
Ledger’s precedent remains more significant in its scope. Its 2020 data leak affected about 272,000 customers and caused a phishing wave. Some users also received ransom demands accompanied by threats of violence. More recently, the exploit affecting Coldcard further heightened concerns about the security of hardware wallets and self-custodied funds.
SafePal therefore intervenes in a period already marked by several incidents affecting crypto users. The company apologized to its community after discovering this exposure. It now states it wants to communicate new updates as its investigation continues.
This communication also aims to specify the limits of the incident and to distinguish commercial data from elements necessary to access cryptocurrencies. Users thus have a clearer framework to assess their immediate exposure. The next steps will depend notably on technical conclusions and additional information that the manufacturer will publish. The affected customers will need to follow SafePal’s next communications to know the precise development of the case.