• SafePal says a flaw in an order-tracking plug-in exposed personal order information belonging to 39,798 customers. , and crypto holdings were not affected.
  • The stolen records are now being advertised for sale on a cybercrime forum. Customers were posting about phishing attempts as early as July.
  • A separate leak at Trezor lands in the same window, taking the combined total to around 54,000 wallet owners by Cointelegraph’s count.

Nothing was taken out of anyone’s wallet here. What went missing was the paperwork around it: order information for close to 40,000 SafePal customers, along with the one detail that makes the rest of it valuable, which is that every person on that list bought a device for storing cryptocurrency.

A leak like this doesn’t move anybody’s money. It tells whoever has it who owns crypto, what they bought to keep it in, and how to get in touch. That is most of what a convincing fake support message needs, and it works just as well six months from now as it does today. The file is now being offered for sale on a cybercrime forum, which means the risk no longer depends on what one person chooses to do with it.

It is also the kind of information you can’t reset. A password can be changed in a minute. A name, a phone number and a delivery address can’t be, which is why an order-data leak keeps mattering long after the incident itself is closed.

What was in the leak

A male and female courier organizing packages in a delivery truck for efficient shipment.
Couriers loading parcels for delivery: the leaked SafePal records were order and shipping details, the information that gets a hardware wallet from a warehouse to someone’s front door. Photo by Artem Podrez on Pexels.

SafePal makes hardware wallets: small physical devices, roughly the size of a car key or a phone, that hold the private key to your crypto and keep it off any internet-connected computer. The private key is the long secret number that proves the coins are yours and lets them be moved. Whoever holds it controls the money, which is why keeping it offline is the whole point of the product.

The breach did not touch that. What it touched was the shop side of the business, the records created when someone orders a device and it gets sent to them. In its disclosure on 16 August the company put the cause down to a flaw in an order-tracking plug-in, and the number of affected customers at 39,798.

The company’s own statement stops short of a field-by-field list, but the material now circulating fills that in. According to The Defiant, the file being offered for sale pairs home addresses with phone numbers, attached to proof that the person on each line bought a hardware wallet. That is a more useful package to a scammer than an email list, and it is worth knowing when you judge how much caution the situation calls for.

“Private keys are safe” is true, and not the end of it

Both CoinDesk and The Block record the same reassurance from SafePal, and there is no reason to doubt it: keys, seed phrases and assets were not exposed. That is genuinely the most important sentence in the disclosure.

It is not, though, the same as saying nobody is now at risk. The most common way crypto is taken from ordinary holders is not a technical break-in. It is somebody being persuaded to hand over their recovery phrase, or to type it into a page that looks exactly like a firmware update.

What makes that persuasion work is specificity. A generic scam email is easy to bin. An email that knows your name, knows which wallet you own, and refers to an order you actually placed is a different proposition, and that is precisely what a customer list of this kind provides. So the assets being safe today and the list being dangerous tomorrow are both true at once.

The sale changes the shape of that. A stolen database sitting with the person who took it is one problem; the same database advertised on a forum is a different one, because anyone willing to pay can have a copy, and copies don’t get recalled. Listings like this are also usually resold and passed around long after the original advert comes down.

Practically, that means the people on this list should expect the approaches to keep coming, and to keep sounding well-informed, for a good while yet. The incident is closed at SafePal’s end. The file has a life of its own.

The month in between

The timeline is the part that deserves scrutiny. SafePal identified the plug-in flaw and published its account of it in mid-August. Customers were reporting targeted phishing attempts, according to The Block, as early as July.

Working out how a breach happened takes time, and there is nothing unusual in a company needing weeks to do it. But identifying the cause and warning people that their details are circulating are two separate jobs, and only the first one requires a full investigation. During that gap, people receiving unusually well-informed emails had no way of knowing why, and no reason to treat them as anything other than a coincidence. The company had the power to close that gap sooner and didn’t, and the records have since reached open sale.

The second wallet maker in the same fortnight

SafePal is not on its own. Trezor, one of the oldest names in hardware wallets, confirmed a separate leak of customer data in the same period. Cointelegraph puts the combined figure across the two companies at roughly 54,000 people now facing a higher chance of being targeted.

Two unrelated companies, two separate incidents, one shared weakness. The device itself can be excellent at protecting a key and still leave a paper trail somewhere else in the business, in a support system, a shipping record or a retail database. That is a supply chain problem rather than a cryptography one, and it applies to every company that ships a physical product to a named person at a real address.

What to check, and where to report it

No legitimate wallet company will ever ask for a seed phrase or recovery words, by email, by phone or in a form. There is no exception to that, and it is the single check that defeats almost every version of this scam.

Beyond that: treat any unsolicited contact about a wallet you own as unverified, however much it appears to know about you. Because the file includes phone numbers, that applies to calls and texts as much as to email. Don’t follow links in messages about firmware or security alerts, go to the company’s site yourself. Suspicious emails can be forwarded to report@phishing.gov.uk and suspicious texts to 7726. If money has been lost or an approach has been made, that goes to Action Fraud on 0300 123 2040 or Police Scotland on 101. Complaints about how a company handled personal data go to the Information Commissioner’s Office.

What to watch

Two things. Whether SafePal contacts the 39,798 people individually now that the records are on sale, rather than leaving it to a public statement, because plenty of them will have no idea their address is in a file somebody is advertising. And whether the attempts move offline. A list of confirmed crypto owners with home addresses and phone numbers is the raw material for approaches that don’t arrive by email at all, and if that starts happening it becomes a considerably more serious story than a database leak.

Update, 18 August 2026: SafePal has since put the cause down to a flaw in an order-tracking plug-in and the number of affected customers at 39,798. The stolen records are now being advertised for sale on a cybercrime forum, pairing home addresses and phone numbers with proof that each person bought a hardware wallet.