Circuit Wire — a daily news update from the Circuit.

Cryptocurrency hardware wallet maker SafePal has confirmed a data breach affecting 39,798 customers, and a threat actor now claims to be selling the stolen records on a cybercrime forum, BleepingComputer reported on Saturday, August 16. The company published its security advisory on Sunday and emailed every affected customer the same day.

The breach covers customers who placed orders between March 2, 2025, and April 11, 2026. The stolen data includes names, email addresses, shipping addresses, phone numbers, and purchase details. SafePal said seed phrases, private keys, passwords, payment card numbers, and government ID numbers were not exposed. It also said it found no evidence that wallets or funds were compromised.

The flaw sat in the order-tracking function of a plug-in used by SafePal's online store. The authorization error allowed one customer's order lookup to return another customer's details, CoinDesk reported. SafePal received a report consistent with the incident in early May and treated it as an isolated case before opening a formal investigation. A full review and rebuild of the order-processing system, begun in July, surfaced the vulnerability. A separate configuration error had also stopped a data-cleanup process between September 2025 and April 2026, leaving order records on the servers dating back to March 2025.

The seller's forum post references the same order window and the same customer count SafePal disclosed. The seller is offering order IDs and shipping countries from stolen records as proof, details that buyers can check against SafePal's own online verification tool. BleepingComputer said it has not independently verified that the threat actor holds the data.

The phishing campaign appears to have started well before the disclosure. Customers reported SafePal phishing emails and phone calls as early as May, including a fake warning that the X1 hardware wallet needed a firmware update. The company says it has taken down more than 30 fraudulent websites and phishing links tied to the incident. Its advisory tells anyone who has shared a seed phrase or private key in response to an email, call, or letter to treat the wallet as compromised and move assets to a new one.

The disclosure lands weeks after a hack of Coldcard hardware wallets, in which the attacker reportedly stole at least $120 million in bitcoin. The SafePal records carry a different kind of weight. They tie names, home addresses, and phone numbers to nearly 40,000 people who bought hardware built for storing cryptocurrency.

Want a weekly roundup of the major stories shaping the security industry? The On The Circuit newsletter is read by more than 12,000 protection professionals.

Spotted something we should cover? Send tips and feedback via circuit-magazine.com.