Originals

SafePal Breach: Outlets Split on Whether a 39,798-User Disclosure Was Ever Formalized

SafePal Breach: Outlets Split on Whether a 39,798-User Disclosure Was Ever Formalized

SafePal is at the center of a data exposure incident affecting customer order information — but the two outlets that covered it this week describe strikingly different pictures of how, and whether, the company formally disclosed it. Crypto Briefing described SafePal as a hardware wallet maker backed by Binance Labs.

CoinDesk reported that SafePal disclosed the breach on Sunday, identifying an “authorization flaw” in a plug-in used to track customer orders. According to CoinDesk, the flaw exposed personal details — including customer names, home addresses and contact information — for 39,798 people who had placed orders in the window running from March 2, 2025 to April 11, 2026. Crypto Briefing, publishing about 21 minutes earlier that same day, described a longer-running episode: the incident first surfaced on Reddit in May 2026, when SafePal S1 device owners reported that scammers were contacting them with order details, including full names, shipping addresses, device models and payment methods. Crypto Briefing reported that SafePal had not, at the time of its story, issued any formal breach notice specifying a number of affected users, and said the widely cited estimate of about 40,000 people originated with outside analysts rather than the company itself. Given the two stories ran within minutes of each other on the day CoinDesk says the disclosure happened, one plausible reading is that Crypto Briefing’s account reflects the state of play just before SafePal’s notice went out, rather than a permanent gap between the two outlets’ facts. That reading does not resolve the other discrepancies below.

Where the two accounts agree

Both outlets agree on the core reassurance from SafePal: wallet security itself was not breached. CoinDesk reported that seed phrases, private keys, bank details, payment card numbers and government-issued IDs were not affected. Crypto Briefing similarly reported that, as of its mid-August 2026 reporting, no evidence had turned up showing seed phrases or private keys had been exposed, and noted that the SafePal S1 is marketed as a fully air-gapped device with no Bluetooth, WiFi, NFC or USB connectivity. Both outlets also describe the exposed order data — names, addresses and contact details — as creating elevated phishing and impersonation risk for affected customers. CoinDesk reported that SafePal itself warned users to be alert to phishing and impersonation attempts; Crypto Briefing went further, laying out its own “standard defensive playbook” urging skepticism toward unsolicited contact and any request for wallet information or seed phrases.

Where the two accounts diverge

The sharpest disagreement is over disclosure itself. CoinDesk’s account describes a company-issued, numbered disclosure: SafePal said it identified the flaw, patched it, notified all affected customers by email from security@safepal.com, hired an independent third-party security firm to audit the fix, and removed more than 30 fraudulent websites and phishing links tied to the breach. Crypto Briefing’s account describes the opposite: no formal breach disclosure naming a specific number of affected users, with the roughly 40,000 figure attributed to external estimates rather than official company communications.

The two reports also give different numbers for how long SafePal retains customer data. CoinDesk reported that, going forward, SafePal will keep customer data inside its order-processing system for no more than 90 days after it is collected. Crypto Briefing reported that SafePal had previously stated it deletes purchase records on a 12-month cycle. It is unresolved whether this reflects a policy change made in response to the breach or a genuine discrepancy between the two reports.

Each outlet also reached for a different historical comparison. CoinDesk linked the SafePal incident to a recent Coldcard hardware wallet hack in which an attacker reportedly stole at least $120 million in bitcoin, framing both as reminders that no crypto-storage solution is entirely risk-free. Crypto Briefing instead compared the incident to Ledger’s 2020 database breach, which exposed the personal information of over a million customers and led to phishing emails, threatening letters and, in some cases, physical threats tied to leaked home addresses.

What remains unresolved

No customer accounts of financial loss or phishing success tied specifically to this SafePal incident appear in either report. Also unresolved: whether SafePal will publish further detail reconciling the 39,798 figure CoinDesk reported with the earlier community estimates Crypto Briefing described, whether the Reddit reports from May 2026 and the Sunday disclosure CoinDesk describes refer to the same underlying flaw or a delayed response to it, and what the third-party security audit CoinDesk mentioned ultimately finds.

Sources

Every fact above is attributed to one of these reports. Where they disagree, the article says so.