← Blog · · df00tech

SafePal Discloses Breach Exposing Order Data for Nearly 40,000 Customers

security-news breach

Cryptocurrency hardware wallet maker SafePal has disclosed a data breach affecting approximately 39,798 customers, according to a report from BleepingComputer. The company said a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data.

Why It Matters

SafePal customers are, by definition, cryptocurrency holders who purchased hardware wallets — a profile that makes stolen order data especially attractive to attackers. Order records for this type of product can include names, shipping addresses, and email addresses, which is enough to fuel highly targeted phishing, SIM-swap attempts, and physical-security ('wrench attack') schemes against individuals known to own crypto hardware. The exact scope of data fields exposed has not been confirmed beyond what is described as "customer order information."

What Defenders Should Watch For

  • Organizations and individuals who purchased SafePal products should treat any unsolicited contact referencing their order, shipping details, or wallet purchase as a potential social-engineering attempt.
  • Security teams supporting crypto-industry customers or high-net-worth individuals should watch for phishing campaigns and fraudulent "support" or "replacement device" outreach that leverages this leak as pretext.
  • Threat intel and brand-protection teams should monitor dark web marketplaces and breach forums for the advertised SafePal dataset to assess scope and validate whether it includes sensitive fields beyond order metadata.
  • Email security controls should be tuned to flag messages impersonating SafePal or referencing wallet orders, given the likely follow-on phishing risk.

Developing Story

This is a net-new disclosure and details are still emerging, including full confirmation of the exposed data fields and the vector used to exploit the flaw. We will monitor for updates. Read the original report at BleepingComputer.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.