Back to Blog
high severity August 18, 2026 · 4 min read

Did SafePal leak my home address? What the 2026 breach actually means

If you have an account with Did SafePal, here’s what’s now in circulation.

SafePal confirmed that a flaw in its order-tracking tool exposed the names, emails, shipping addresses, phone numbers and order details of about 39,798 customers who ordered between 2 March 2025 and 11 April 2026. Wallet keys, passwords and funds were not involved. Affected customers were emailed on 16 August 2026.

Did SafePal leak my home address? What the 2026 breach actually means

SafePal confirmed on 16 August 2026 that a flaw in an order-tracking tool let outsiders view other customers' order records. The exposed records cover orders placed between 2 March 2025 and 11 April 2026. About 39,798 customers were affected. SafePal says every one of them was emailed that same day from [email withheld].

Already exposed?
You can’t unleak a breach. You can take away what it’s worth.
Deep Sweep shows you every leak tied to you and exactly what to change. Then it strips your name, address and family off the look-up sites that turn a leaked record into somebody knocking on your door — $29 one-time, includes 30 days of Protection. We write to 582 companies. No subscription to start.
Scan free, then Deep Sweep — $29 →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

What leaked, according to the company: names, email addresses, shipping addresses, phone numbers, and purchase details. What did not: seed phrases, private keys, wallet passwords, or funds. SafePal says it has fixed the flaw, shortened how long it keeps order data, told its shipping partners, taken down more than 30 related phishing sites, and hired an outside firm to review what happened. An 18 August update noted unconfirmed claims that the same records are being offered for sale.

No keys were taken. That is not the part that should reassure you.

Every write-up of this incident leads with the same line: private keys were not involved. That is true. It is also the least useful fact if you are one of the people on the list.

What was actually taken is a named list of people, at known home addresses, documented as having bought a hardware wallet. That is a targeting list. Someone who wants to impersonate SafePal, talk you into typing a recovery phrase into a fake site, or simply know that crypto hardware was shipped to your door now has your name, your phone, your email, and the address on the order.

The company itself has already taken down more than 30 phishing sites tied to this. That is how the data is being used in practice: not to empty wallets remotely, but to pose as SafePal and persuade people to hand over the keys that were never leaked. “Your crypto is safe” and “someone has a list of hardware-wallet owners at home addresses” are the same facts. They do not mean the same thing to you.

What to actually expect

  • Emails, texts, or websites that look like SafePal and ask you to “verify,” “secure,” or “re-register” your wallet. Anyone asking for a seed phrase, private key, or wallet password is lying. Those were never in this leak. The real company already emailed affected customers on 16 August 2026 from [email withheld].
  • If you ordered between 2 March 2025 and 11 April 2026, look for that email, including in spam and promotions. That is the only notice SafePal says it sent. There is no public list and no scan that can tell you whether you were among the 39,798. A clean result on any checker does not mean you were not on it.
  • Calls or messages that already know your name, your order, or your shipping address. Treat that knowledge as stolen, not as proof the person on the other end is legitimate. SafePal also told its shipping partners, so “problem with your delivery” is a likely script.
  • Claims that the 39,798 records are for sale. SafePal says it cannot verify those claims. Whether a sale is real or not, the records were accessed. Treat them as loose.

What you can and cannot fix

The names, email addresses, shipping addresses, phone numbers, and order details that were exposed cannot be pulled back. They are out. No company, no removal service, and no scan can recall them.

What still helps, in this order:

  • Do not enter a seed phrase, private key, or wallet password in response to any message about this incident. Those were never exposed. Anyone asking already knows that and is counting on you to panic.
  • Treat unexpected knowledge of your SafePal order as a warning, not a credential. Hang up. Do not confirm an address, an order number, or a phone number to a caller who brought it up first.
  • Remove yourself from people-search and data-broker listings. A bare leaked order record becomes far more useful to a stranger when it is joined to public pages that add relatives, extra phone numbers, employers, and previous addresses. Those listings, unlike the leaked data, can actually be taken down. That is the lever that still exists.
  • Tell the people who live at the shipping address, briefly and calmly, that your name and that address are now tied in someone else’s hands to a hardware-wallet purchase. They are the ones most likely to take a convincing follow-up call or a “courier” message at face value.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove. That’s what a Deep Sweep buys.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample582 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Check your exposure
Did SafePal is one breach. Your email is probably in others.
We can’t confirm any single incident against the sources we search, so we won’t pretend to. What we can show you is your own exposure — your email against 13.1B+ leaked records and the sites that publish your address. About 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High
Disclosed August 18, 2026
Affected Unconfirmed
Data exposed Full namesEmail addressesShipping addressesPhone numbersPurchase/order details
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email