Intelligence
highVulnerabilityActive

SafePal hardware wallet breach exposes 39,798 customers via exploited flaw; data actively marketed for sale

SafePal cryptocurrency hardware wallet provider suffered a data breach affecting approximately 39,798 customers after an unpatched flaw was exploited to steal order information. Threat actors are actively attempting to sell the stolen dataset.

S
Sebastion

Affected

SafePal

SafePal, a provider of cryptocurrency hardware wallets, has disclosed a data breach impacting approximately 39,798 customers. According to the vendor's disclosure, a flaw in their systems was exploited to exfiltrate customer order information, and the stolen data is now being marketed for sale by threat actors. The breach represents a significant trust violation for a company whose primary value proposition is secure asset custody.

The technical scope of the breach remains partially unclear from the available details. The source confirms that order information was stolen through an exploited flaw, but does not specify whether the vulnerability was in the web application, API, or backend infrastructure. Similarly, the exact nature of the information compromised is described only as order data, leaving open questions about whether customer personal identifiable information, email addresses, payment records, or wallet-related metadata were included. The lack of a disclosed CVE identifier suggests either that the vulnerability has not yet been formally registered or that the vendor is withholding technical details pending remediation.

The active marketing of stolen data by threat actors indicates that the breach has progressed beyond discovery and containment to monetisation. This timeline suggests either a delayed incident response or that attackers maintained access for an extended period before the compromise was detected. For customers of hardware wallet providers, the risk profile is distinct from breaches at exchanges or custodians: hardware wallets themselves store private keys offline, so the stolen order data alone does not directly compromise cryptocurrency holdings. However, the information could facilitate secondary attacks such as phishing, account takeover, or social engineering targeting wallet owners.

Defenders and SafePal customers should prioritise identifying what categories of personal and transactional data were included in the exfiltration. If email addresses or phone numbers are present, customers should expect targeted phishing campaigns. If order records include shipping addresses or device serial numbers, attackers may attempt to intercept shipments of replacement devices or conduct reconnaissance for targeted attacks. Organisations should monitor for appearance of the dataset on underground markets and conduct forensic analysis to determine the vulnerability's root cause and whether other customer records or sensitive systems were accessible.

This incident underscores a persistent gap in security posture for hardware wallet manufacturers: the device itself may be cryptographically robust, but the surrounding infrastructure, web platforms, and order management systems often lag behind in security maturity. The breach demonstrates that attackers do not need to compromise the wallet firmware to extract value from a hardware wallet company's customers.