SafePal reportedly exposed data of nearly 40,000 customers

3 hours ago 23

SafePal, the hardware wallet maker backed by Binance Labs, is dealing with an uncomfortable revelation: customer order data for roughly 40,000 users was exposed, leaving personal information in the hands of scammers.

The incident first surfaced on Reddit in May 2026, when SafePal S1 device owners began reporting something unsettling. Scammers were contacting them with details they had no business knowing: full names, shipping addresses, device models, quantities ordered, delivery locations, and the payment methods used at checkout.

What got exposed and what didn’t

The good news, such as it is, sits at the wallet level. Investigations conducted through mid-August 2026 found no evidence that seed phrases or private keys were compromised.

The SafePal S1 is marketed as a fully air-gapped device, meaning it operates without Bluetooth, WiFi, NFC, or USB connectivity. On that front, the wall held.

SafePal responded to the initial reports by stating that it does not retain payment information or personal data indefinitely, with purchase records deleted on a 12-month cycle. The company also noted it does not require KYC verification or account registration to use its services.

As of the time of reporting, SafePal had not issued a formal breach disclosure naming a specific number of affected users. The figure of approximately 40,000 impacted customers emerged from external estimates rather than official company communications.

A familiar story in the hardware wallet industry

The crypto community has been through this before, almost exactly. In 2020, Ledger, SafePal’s most prominent competitor, suffered a database breach that exposed the personal information of over a million customers. Ledger’s users subsequently received phishing emails, threatening letters, and in some cases physical threats tied to their home addresses being made public.

SafePal has maintained a clean record on the wallet security side since its founding in 2018, with no known wallet hacks reported in that span. The company’s partnership with Binance Labs gave it significant industry credibility and distribution reach.

What affected users and the broader market should watch

For the roughly 40,000 customers whose information may have been caught up in this incident, the immediate risk is targeted phishing and social engineering. Scammers who know you own a SafePal S1, know your address, and know how you paid for it have a fairly detailed picture to work with.

The standard defensive playbook applies: be skeptical of any unsolicited contact claiming to be from SafePal or related services, do not click links in emails or messages you didn’t expect, and treat any request for wallet information or seed phrases as an automatic red flag regardless of how legitimate the sender appears.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article