On August 16, hardware crypto wallet manufacturer SafePal disclosed a data breach affecting approximately 39,798 users. The incident exposed names, delivery addresses, phone numbers, email addresses, and order details to third parties.

The breach did not affect seed phrases, private keys, passwords, bank details, card numbers, or identification documents, as SafePal does not collect or store such information. The project team found no evidence that attackers gained access to users' wallets or funds.

The developers warned that the leaked information could be used for targeted attacks, including phone calls, messages, or emails impersonating support, offering refunds, requesting firmware updates, or directing users to phishing websites. SafePal is currently monitoring fake resources and working to have them blocked.