SafePal said an order-tracking flaw exposed customer data tied to 39,798 people, in a disclosure the hardware-wallet maker framed as a data-exposure incident rather than a compromise of user funds.
What SafePal said about the order-tracking flaw
The account comes from SafePal’s own security update, which attributed the exposure to a flaw in its order-tracking system. For related coverage, see XRP Bridge Exploit Update: 198,715.88 XRP Stolen in Relayer Flaw.
The company put the number of affected customers at 39,798, a figure that centers on order records rather than any loss of wallet assets. For related coverage, see Fake Crypto Startup Fooled North Korean IT Workers, Cointelegraph Says.
SafePal described the issue as tied to order tracking, and the disclosure did not indicate that private keys or wallet balances were involved. For related coverage, see OCC Chief Says Crypto Firms Can Pursue U.S. Bank Charters.
What data was exposed and who was affected
The exposure was scoped to the group of customers linked to the order-tracking system, according to SafePal’s disclosure and follow-up reporting. For related coverage, see Coreum XRPL Bridge Loses Nearly 200,000 XRP After Relayer Flaw.
Because the incident stems from order records, the affected information is order-related customer data rather than the on-device secrets a hardware wallet is designed to protect. SafePal’s statement did not confirm a wider breach beyond that system.
Readers whose main concern is whether their personal details were involved should treat SafePal’s own notice as the authoritative scope, since the company has not detailed additional exposed fields beyond what its disclosure states.
Why the incident matters for SafePal and its customers
SafePal publicly acknowledged the flaw and issued its notice through its security update page, the step that made the customer count public in the first place.
A data-exposure event still carries weight even when funds are not directly at risk, because leaked order and contact data can feed phishing and targeting of wallet holders. The same dynamic surfaced when Israeli broker Bits of Gold investigated a third-party customer data breach, where the concern was exposed personal records rather than stolen crypto.
For a hardware-wallet brand, the reputational stakes are heightened because the product’s entire value proposition is custody and security, so any disclosure touching customer data tests user trust directly.
The incident lands amid escalating pressure on wallet users, from data leaks through to physical wrench attacks that exploit knowledge of who holds crypto. That backdrop is part of why exposed customer records, and not just stolen keys, now shape how the sector weighs a breach.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.