SafePal latest crypto hardware wallet maker affected by breach, with nearly 40,000 impacted
SafePal confirmed nearly 40,000 customers' order data was stolen, the third hardware wallet maker breached in a month after Trezor and Coinkite.
SafePal confirmed a breach exposing names, emails, shipping addresses, phone numbers, and purchase details of customers who ordered between March 2, 2025 and April 11, 2026, caused by a flaw in an order-tracking plugin. The company stressed wallets, seed phrases, and private keys remain secure, and all impacted customers were notified by email. A hacker advertised the stolen data on a dark web forum, and SafePal warned of targeted phishing via fake support calls and refund offers. CertiK data cited in the report shows 52 wrench attacks worldwide in H1 2026 with $124 million in losses, up 33% year-over-year.
SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers
SafePal disclosed an order-tracking plug-in authorization flaw exposing names, emails, addresses and purchase details of 39,798 hardware wallet customers; no wallet credentials affected.
Hardware wallet maker SafePal disclosed that an authorization flaw in an order-tracking plug-in exposed names, email addresses, shipping addresses, phone numbers and purchase details of approximately 39,798 customers. No seed phrases, private keys, wallet credentials or financial information were exposed, and SafePal found no evidence of wallet or fund compromise. A separate configuration error left a data-cleanup process broken between September 2025 and April 2026, extending the affected order window back to March 2025. A threat actor has advertised a matching dataset on a cybercrime forum, and the company has fixed the flaw, cut data retention to 90 days, purged affected records, engaged third-party validators and taken down over 30 phishing sites.
SafePal Says 39,798 Customers Hit by Data Breach
Crypto wallet maker SafePal disclosed a breach exposing order data of 39,798 customers via a plugin authorization flaw; keys and seed phrases unaffected.
SafePal, a Singapore-based cryptocurrency security company, said an authorization flaw in an order-tracking plugin let attackers access order records placed between March 2, 2025 and April 11, 2026. Exposed data includes names, emails, addresses, phone numbers, and purchase details for about 39,798 customers, while seed phrases, private keys, wallet passwords, and payment data were not exposed. A threat actor advertised the same dataset on a cybercrime forum, and affected customers were notified by email on August 16. The company patched the flaw, reduced data retention to 90 days, and removed over 30 fraudulent phishing websites.
Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs
Week in review: Medusa ransomware hit 500+ orgs per CISA, millions of Azure tenant records allegedly stolen, SafePal and French tax authority breaches disclosed.
Help Net Security's weekly roundup covers the FBI, CISA, and HHS joint advisory update reporting Medusa ransomware has breached more than 500 organizations since June 2021, and threat actor TheHatman's claim of millions of employee records stolen from Azure tenants of Fortune 500 firms including McDonald's, Vodafone, Kyndryl, and Tata Consultancy Services, per Hudson Rock. It also covers the SafePal breach affecting 39,798 customers, France's DGFiP breach exposing data on 678,000 individuals, and UT San delaying its fall semester after a cyberattack. Security items include critical unauthenticated GitLab flaw CVE-2026-19478, an actively exploited patched macOS Screen Sharing flaw deploying a cryptominer, US charges against 17 Mabna Institute Iranian hackers over 31TB of stolen academic data, and Google Mandiant's AI agents finding 100+ high-severity vulnerabilities.
CenterPoint Energy Confirms Data Breach Exposing Customers’ Personal Information
CenterPoint Energy confirmed an unauthorized third party accessed customer personal data via an external system, disclosed in an SEC Form 8-K filing.
CenterPoint Energy disclosed in a September 14, 2026 Form 8-K that an unauthorized third party obtained personal information of some customers through one of the company's external systems. The company learned of the incident after an online post claimed possession of a customer dataset, then activated incident-response protocols and engaged external forensic specialists. Electric and gas delivery operations were unaffected and the company does not expect a material financial impact, though response, notification, and compliance costs are being incurred. The number of affected customers, data types, and threat actor remain undisclosed as the investigation continues.
SafePal breach affects 39,798 customers, data allegedly for sale
SafePal disclosed a breach exposing order data of 39,798 customers via an order-tracking plug-in flaw; the data appears for sale online.
Cryptocurrency wallet maker SafePal exposed names, phone numbers, addresses and purchase details for 39,798 orders placed between March 2, 2025 and April 11, 2026, due to an authorization flaw in an order-tracking plug-in. Seed phrases, private keys, wallet passwords, payment cards and government IDs were not exposed, and no wallet or fund compromise was found. A threat actor is selling data on a cybercrime forum citing the same order window and count, and SafePal has taken down more than 30 phishing sites and notified customers on August 16.