Crypto hardware wallet provider SafePal has disclosed a security incident affecting approximately 39,798 customers whose orders were placed between March 2 and April 11, 2026.
According to the company, an access-control weakness in its order-processing system allowed an unauthorized person, under certain conditions, to view information associated with other customers' orders.
SafePal said it has since fixed the vulnerability and introduced additional security controls to the affected system. Customers identified as potentially impacted have also received direct email notifications.
Importantly, the company stressed that the breach did not expose cryptocurrency wallet credentials or financial information.
SafePal also said bank account details, payment card numbers and government-issued identification numbers were not involved. The company noted that it does not request, process or store customers' seed phrases or private keys.
Phishing Attacks Are the Main Risk
Although wallet credentials were not compromised, exposed order information could still provide scammers with valuable material for highly convincing phishing attacks.
Attackers could potentially reference genuine purchase information when contacting customers, making fraudulent communications appear more credible.
SafePal warned users to watch for fake support calls, phishing emails, text messages, fraudulent refunds and bogus software or firmware updates. Attackers could also direct victims toward websites designed to resemble legitimate SafePal services.
Physical approaches are another concern. Customers could potentially receive unexpected letters, packages or hardware deliveries referencing their previous SafePal purchases.
SafePal also acknowledged that the compromised order records could eventually circulate on public online forums, potentially extending the phishing risk beyond the immediate aftermath of the breach.
Customers Don't Need to Move Crypto
SafePal said affected customers do not need to transfer their cryptocurrency to another wallet solely because their order information was exposed.
Because seed phrases and private keys were not part of the compromised data, the incident itself does not provide an attacker with direct access to funds stored through a customer's wallet.
However, the situation changes if a customer has already entered a recovery phrase or private key into a suspicious website or disclosed it through an email, text message, phone call or letter.
In those circumstances, SafePal recommends treating the wallet credentials as compromised rather than assuming the funds remain protected.
The distinction highlights why the secondary phishing threat may be more dangerous than the original breach. Genuine customer information can make fraudulent communications significantly harder to identify.
SafePal Changes Its Data Retention Policy
Following the incident, SafePal has taken several steps to strengthen its security procedures.
The company is bringing in an independent cybersecurity firm to verify that the vulnerability has been properly fixed. The external review will also examine SafePal's wider order-processing infrastructure for additional weaknesses.
SafePal has additionally reduced the retention period for personal customer information to 90 days within the affected order-processing system, except where longer storage is legally required.
The company said it has identified the customers whose information was accessed and contacted those individuals directly with further details.
SafePal has also asked external companies involved in order fulfillment and delivery to review their own systems for similar vulnerabilities, expanding the investigation beyond its internal infrastructure.
For affected users, the immediate danger is therefore less about attackers directly accessing their crypto and more about criminals using legitimate purchase information to impersonate SafePal and trick customers into revealing the credentials that actually control their wallets.



