SafePal, which sells hardware wallets for storing digital assets offline, has told customers that a data breach exposed order information belonging to roughly 40,000 buyers.
The company said the exposure involved records associated with purchases rather than the devices themselves, and that private keys, recovery phrases and customer funds were not affected. Hardware wallets are designed so that the secret material never leaves the device, which limits what an attacker can do with a merchant's order database.
That distinction offers less comfort than it sounds. Purchase records typically pair a name, an email address and a shipping address with the fact that the person owns a self-custody wallet — a combination that has repeatedly been used to target holders with tailored phishing messages, fake replacement-device shipments and, in the worst cases, physical coercion.
Security researchers advising affected users recommend treating any unsolicited message referencing a wallet order as hostile, never entering a recovery phrase into a website or support chat, and refusing devices that arrive unexpectedly by post.
Similar leaks at other wallet and exchange vendors have been followed by phishing waves weeks or months later, once the data has circulated. SafePal said it is notifying affected customers directly and reviewing how order data is retained.
