SafePal disclosed on Aug. 16 that a flaw in an order-tracking plug-in exposed the personal data of 39,798 customers, and a threat actor is already advertising the records for sale on a cybercrime forum.
The file pairs home addresses and phone numbers with proof of hardware wallet ownership, which makes it a targeting list for phishing and for physical robbery. It is the second hardware wallet customer database exposed in three days.
SafePal, the Binance-backed wallet maker, said in its incident report that it found “an authorization flaw in the order-tracking function for a plug-in associated with customer order information.” Orders placed between March 2, 2025, and April 11, 2026 were affected, exposing names, email addresses, shipping addresses, phone numbers and purchase details. Seed phrases, private keys, wallet passwords, bank account information and payment card numbers were not compromised, the company said, and it found no evidence the incident gave anyone access to wallets or funds.
BleepingComputer reported that a seller on a cybercrime forum is offering the data and vouching for it by sharing order IDs and shipping countries that buyers can check against SafePal’s own lookup tool.










