SafePal has become the latest hardware-wallet provider to disclose a security incident, after an authorization flaw exposed personal information from about 40,000 customers.
The Aug. 16 disclosure extends a run of security problems involving hardware-wallet companies and their users, including recent incidents affecting Trezor, Ledger and Coldcard.
How the breach occurred
SafePal said the breach originated in the company's e-commerce infrastructure. According to the firm, an authorization flaw in its order-tracking system allowed unauthorized access to customer records covering purchases made between March 2, 2025, and April 11, 2025.




