cleartext

Independent, sourced crypto news. No paid placements.

safepal

SafePal says 39,798 customers' names and addresses were exposed by an order-tracking flaw

Hardware wallet maker SafePal says an authorization flaw in an order-tracking plug-in exposed names, addresses and contact details for 39,798 customers who ordered between March 2025 and April 2026.

SafePal, which sells hardware wallets, disclosed on Sunday that an authorization flaw in a plug-in used to track customer orders exposed the names, physical addresses and contact details of 39,798 customers, according to CoinDesk, which reported the disclosure on 16 August. The flaw, CoinDesk wrote, likely let one customer view another customer's order record — the parcel-tracking equivalent of changing a number in a URL.

The exposure window runs from 2 March 2025 to 11 April 2026: roughly thirteen months of order data.

SafePal said no crypto funds, seed phrases, private keys, bank account details, payment card numbers or government-issued IDs were involved, and that the wallets themselves were not compromised. It said it has patched the flaw, added unspecified further controls, emailed every affected customer from security@safepal.com on Sunday, engaged an unnamed third-party security firm to audit the fix and review its order-processing systems, and taken down more than 30 fraudulent sites and phishing links tied to the incident. A checker tool on its site lets customers see whether they were caught. Going forward, the company said, order data will be retained for 90 days from collection.

SafePal also told customers who have already handed over a seed phrase or private key to a phishing email, call or letter to treat the wallet as compromised and move the assets.

Key facts

  • 39,798 customers affected; data exposed was names, physical addresses and contact details — SafePal, via CoinDesk (16 Aug 2026).
  • Order window: 2 March 2025 – 11 April 2026 — SafePal, via CoinDesk.
  • Cause: an "authorization flaw" in an order-tracking plug-in — SafePal's wording, via CoinDesk.
  • Remediation claimed: patch, third-party audit, customer emails, 30+ phishing sites removed, 90-day data retention — SafePal, via CoinDesk.
  • Context cited by CoinDesk: a recent Coldcard hardware-wallet hack in which an attacker "reportedly" took at least $120 million in bitcoin. CoinDesk did not name whose estimate that is.

The real-world read

The 90-day retention pledge is an admission wearing a fix's clothing: the only reason 39,798 records were sitting there to leak is that SafePal held thirteen months of them. The remedy concedes the design error.

"No funds, no keys" is the company's own framing, and CoinDesk's deck repeats it ("remain completely safe"). It is true and it is not the point. For a company whose customers are, by definition, confirmed holders of self-custodied crypto, a list of verified buyers with home addresses is close to the worst non-key data to lose. SafePal's own advice — assume compromise if you were phished — implicitly concedes the risk it just increased.

What isn't said is as loud: which plug-in and whose code, when the flaw was introduced, when it was discovered versus disclosed, whether it was actually exploited or merely exploitable ("likely allowed" is doing work), which audit firm was hired, and whether any data-protection regulator was notified. Cleartext has not seen SafePal's own advisory; this account rests on CoinDesk's reporting of it.

Opinion, and whose

CoinDesk's own framing: the SafePal and Coldcard incidents don't "necessarily point to a systemic weakness in hardware wallets" but do "validate calls" to diversify holdings and wallets. That's the outlet's editorial read, not a finding, and it sits next to an unattributed $120 million loss figure.

Sources

  • CoinDesk (16 Aug 2026), "Crypto wallet SafePal reveals a data breach exposing nearly 40,000 customers' order info" — the sole account here of SafePal's disclosure: victim count, date window, cause, remediation steps, and the Coldcard comparison. Secondary reporting; its figures and quotes come from SafePal itself, an interested party describing its own breach. No independent confirmation of the numbers was published with it. Not marketing or sponsored, though its subheadline adopts SafePal's reassurance framing verbatim.

Nothing here is financial advice.