Skip to content
Back to Blog
high severity August 22, 2026 · 4 min read

Was I in the SafePal data breach? What they took and what they didn't

If you received a notice from Was I in the SafePal, here’s what the filing says was exposed, and what to do about it.

Was I in the SafePal is reported to have suffered a high-severity data breach. Full verified details will be added here as they are confirmed.

Was I in the SafePal data breach? What they took and what they didn't

On 16 August 2026, SafePal published a notice saying it had found an authorization flaw in the order-tracking function of one of its own plug-ins. Under certain conditions, that flaw let someone on the outside look at another customer's order records. SafePal says orders placed between 2 March 2025 and 11 April 2026 were affected, and that the records belonged to about 39,798 customers. What sat in those records: names, email addresses, shipping addresses, phone numbers and purchase details.

The company says seed phrases, private keys, wallet passwords, bank-account information, payment-card numbers and government-issued identification numbers were not involved, and it found no evidence that wallets or funds were compromised. It says the flaw was fixed when it was found, that it emailed every affected customer from [email withheld] on 16 August 2026, and that it checked logistics partners and saw no sign the problem had spread there. It is aware of claims that the dataset is being offered for sale, and says it cannot verify those claims.

Your keys were not taken. Your name and home address may have been.

Almost every account of this incident leads with what was not stolen. That part is true, and it is not reassurance. A SafePal order record is a document that says: this named person, at this address, with this phone number and this email, bought a crypto wallet or another SafePal product. Nobody needs a seed phrase to use that.

Someone holding that list can write to you as if they already know your order. They can call. They can treat the shipping address as a house that is more worth visiting, watching, or pressuring than the house next door. For people who keep hardware wallets at home, the dangerous part of a shipping leak has always been the address book, not the device in the box.

Two things should stay in view so this does not get oversold. First, SafePal and independent reporters have not confirmed that anyone actually copied the records and put them up for sale; the company only says it cannot verify those claims. Second, this was a flaw in SafePal's own order-tracking plug-in, not a break-in at a courier. The honest read is still the same: if you ordered in that window, assume the order record could be in someone else's hands, and plan around the address and the fact of the purchase, not around a drained account.

What to actually expect

  • If you placed an order between 2 March 2025 and 11 April 2026, look for an email dated 16 August 2026 from [email withheld], including in spam. That is the real notice. Mail that is not from that address, or that asks you to click a link, connect a wallet, or type a seed phrase, is not SafePal following up.
  • In the coming weeks, the most likely nuisance is a convincing fake. It will use your real name and talk about a real-looking order, because that is what was in the file. The aim is to get you to "secure" a wallet that does not need securing.
  • Nothing in this incident gives anyone the ability to move your coins. If a balance changes, that is a separate problem, not this leak completing itself.
  • You may also hear nothing. The sale claims are unverified. Silence is not proof you were spared, and a clean result in a public breach search is not proof either — this kind of order file is rarely in those searches.

What you can and cannot fix

If your order sat in that system, the record cannot be called back. A name, an email address, a shipping address, a phone number and a list of what you bought cannot be un-leaked. Anyone offering to wipe it from "the dark web" for a fee cannot do that.

  • Treat the August notice as the only legitimate company contact about this. Do not send seed phrases, passwords, photos of ID, or wallet screenshots to anyone who mentions the breach.
  • At the email address and phone number that were on the order, expect more junk and more tailored scams. Change those contact details where you still can; you cannot change the copies already taken.
  • Be slower to trust unexpected deliveries, "support" visits, or urgent stories that reference a SafePal order at your home. The new fact, if the file is out, is that a stranger may know a crypto product was shipped to that door.
  • Cut down the rest of what is for sale about you on people-search and data-broker sites. A leaked order line is a name, an address and one fact: you bought a wallet. Those sites add relatives, extra phone numbers, employers and previous addresses. Joined together, that is a map of a household. The leaked SafePal record cannot be removed. Those listings can, and that is the lever that is actually still in your hands.

Report details & sourcing

Severity High
Disclosed August 22, 2026
Affected Unconfirmed
Data exposed Full namesEmail addressesShipping addressesPhone numbersPurchase details
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email