
Hardware wallet maker SafePal disclosed a customer data incident affecting nearly 40,000 users, attributing the exposure to a malfunctioning plugin used for order tracking. The company said unauthorized actors accessed data between March 2, 2025, and April 11, 2026, increasing the risk of phishing attempts and fraudulent phone calls targeting affected customers.
Incident Overview
According to SafePal, threat actors exploited a faulty plugin integrated into its order-tracking process. The issue enabled unauthorized access to customer data over a 13-month period. The company did not detail the specific data fields involved but warned that exposed order-related information could be used to impersonate support staff or trick users into divulging sensitive details.
Risks to Customers
SafePal cautioned that the incident may lead to an uptick in social engineering, including:
- Phishing emails or messages that appear to come from legitimate support channels.
- Fraudulent phone calls requesting account details or recovery information.
- Links directing users to fake websites designed to harvest credentials.
Recommended Precautions
- Be skeptical of unsolicited emails, DMs, or phone calls requesting personal or wallet information.
- Do not share recovery phrases, private keys, or verification codes with anyone.
- Verify communications through SafePal’s official website or app before responding.
- Manually navigate to official domains rather than clicking links in unsolicited messages.
- Report suspicious outreach to SafePal’s support channels and monitor accounts for unusual activity.
Why It Matters
Customer data incidents at crypto firms can fuel targeted social engineering, even when on-device wallet security is not directly affected. Attackers frequently use contact and order information to impersonate company representatives, making vigilance essential for users.