Skip to content
Back to Blog
medium severity August 17, 2026 · 3 min read Unverified claim — what this is

Was I in the SafePal data breach? What was leaked in August 2026

If you are a customer of Was I in the SafePal, here’s what is being claimed, and what it would mean for you.

SafePal confirmed that an order-tracking flaw let outsiders view records for about 39,798 customers who ordered between 2 March 2025 and 11 April 2026. Names, emails, phone numbers, shipping addresses and purchase details were accessed. Wallet keys, seed phrases, passwords and payment cards were not.

— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Was I in the SafePal data breach? What was leaked in August 2026

On 16 August 2026, SafePal said it had found a flaw in the order-tracking tool tied to customer purchases. In some cases, that flaw let someone see another customer's order, not just their own. SafePal says order records for people who bought between 2 March 2025 and 11 April 2026 were viewed from outside the company without permission. About 39,798 customers are involved.

Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →

Watch Was I in the SafePal

Get alerted the next time Was I in the SafePal files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.

We’ll email you only about Was I in the SafePal’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.

Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.

Those records included name, email address, shipping address, phone number, and what was purchased. SafePal says the incident did not include seed phrases, private keys, wallet passwords, bank or payment-card data, or government IDs. It says it fixed the flaw, emailed affected customers on 16 August, cut how long it keeps this kind of data to 90 days, and took down more than 30 related phishing sites. It says there is no evidence that wallets or funds were taken through this incident.

The keys were not taken. Your name and address were.

Most coverage will lead with the line that no private keys were allegedly stolen. That is true. It is also the least useful part of the story if you actually ordered a device.

Exposure Pack · one payment
The full list, and what to lock in ten minutes.
  • Every indexed leak tied to your address — all of them, named and dated
  • A deeper search of collected breach data — the kinds of your information it holds, where it finds you
  • What this kind of incident typically exposes
  • A ten-minute lock list written for this kind of organisation
One payment. Nothing renews, and no account is created. Emailed to you within a minute.

What an unauthorized party may now have is not a way into the wallet. It is a list that ties a real name to a home address, a phone number, an email, and the fact that a hardware wallet was shipped there. People buy these devices because they hold crypto they do not want sitting on an exchange. Attached to a front door and a phone number, that fact is a targeting list. The headlines that sound like reassurance are describing the same records a scammer would most want.

The honest read is not that this hole emptied anyone's wallet — SafePal says it did not, and the leaked fields cannot do that on their own. The honest read is that tens of thousands of households have been marked, by name and address, as hardware-wallet owners. Anything that follows will look like a call, a text, or an email that already knows too much about you.

What to actually expect

  • If SafePal believes you are among the 39,798, it says it emailed you on 16 August 2026. Check spam and promotions. No email is not proof you were left out. The better test is whether you placed an order between 2 March 2025 and 11 April 2026.
  • Emails, texts and lookalike websites using your real name or order details, asking you to “verify,” “migrate,” or “secure” a wallet. SafePal says it has already taken down more than 30 related phishing sites. New ones will keep appearing.
  • Calls or messages to the phone number that was on the order, from people who already know a device was bought.
  • A longer run of targeted scams over the coming months that treat you as a known hardware-wallet owner at a known address.

What you can and cannot fix

The copy of those order records that left SafePal cannot be pulled back. If your name, shipping address, email, phone number and purchase details were in the affected set, they are out. That does not change, and no service can recall it.

  • Never give anyone the recovery words, private key, or wallet password because they contacted you about this. SafePal does not need them to “fix” anything. That is the main attack this leak sets up.
  • Ignore unexpected SafePal links. If you need to check something, type the company's site yourself. Do not use a link from an email or a text.
  • Put a new, unique password on the email account you used for the order, and turn on two-step login. That inbox is now a known way to reach someone who bought a wallet.
  • Remove yourself from people-search and data-broker listings that publish your address, relatives, extra phone numbers and past addresses. A bare leaked order file becomes much more useful when it can be joined to those listings — and unlike the breach data, those listings can actually be taken down.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove — and removing them is what we do.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample580 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Check your exposure
Was I in the SafePal is one listing. Your email is probably in others.
We can’t confirm any single incident against the sources we search, so we won’t pretend to. What we can show you is your own exposure — your email against 13.1B+ leaked records and the sites that publish your address. About 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity Medium contact details only, none of them permanent
Disclosed August 17, 2026
Last reviewed August 17, 2026
Affected Unconfirmed
Data exposed Full namesEmail addressesShipping addressesPhone numbersPurchase details
Unverified claim — what this report is
This page documents a public listing on a ransomware/extortion group’s leak site, tracked via public threat-intelligence sources. A listing is the attacker’s claim. GalaxyWarden aggregates and reports such claims; we have not independently verified that a breach occurred, what data (if any) was taken, or the accuracy of anything the group asserts, and the named organisation has not necessarily confirmed the incident. Sections above describe what the listing shows and the group’s documented history — not verified findings about the named organisation. If you represent this organisation and believe anything here is inaccurate, tell us and we’ll review it promptly.
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email