Key points

  • The incident reported on 16 August 2026 involved personal and order information affecting nearly 40,000 customers.
  • A customer-data leak is not the same as a compromised wallet. Recovery phrases and private keys were not part of the reported order data.
  • The main risk is targeted phishing: a scammer can use real purchase details to sound credible.
  • No legitimate support agent should ever ask for a recovery phrase, private key, PIN or password.

SafePal disclosed a customer-data incident involving personal and order information. For hardware wallet owners, the most important question is not only what data was exposed, but how that information could be used next.

Does this mean SafePal wallets were hacked?

No. Customer records such as a name, email address, phone number, delivery address or order details are separate from the recovery phrase and private key that control a wallet. The reported breach does not by itself mean an attacker can access funds or recreate a user's wallet.

It does, however, give criminals better material for social engineering. A caller who knows the exact product you bought can sound like genuine support, even when the call is fraudulent.

What should SafePal users watch for?

Be suspicious of unexpected calls, emails or messages claiming that your device must be replaced, reactivated or urgently updated. Common warning signs include requests to:

  • enter a recovery phrase on a website;
  • install software or firmware from a link in a message;
  • allow remote access to a phone or computer;
  • connect the wallet while following instructions from an unsolicited caller;
  • share a PIN, password, private key or recovery phrase.

Knowing your order number or device model does not prove that the sender represents SafePal.

What to do if someone contacts you

  1. Stop the conversation if it was unexpected.
  2. Do not open links or files sent by the person.
  3. Do not install remote-access software.
  4. Contact SafePal through a channel you find independently on its official website.
  5. If you already disclosed a recovery phrase, treat it as compromised and move assets to a newly created wallet using a trusted device and process.

Do you need to replace the device?

Not solely because customer data was exposed. Replacing a hardware wallet does not remove leaked contact or order information. The immediate priority is recognising targeted phishing and keeping recovery information offline and private.

What SIAMBC customers should know

According to SIAMBC's store records and statement, customers who purchased SafePal through SIAMBC were not part of orders placed directly with SafePal. SIAMBC does not request or store customers' recovery phrases or private keys; those are generated by the customer's own device during setup.

If any message claims to represent SafePal or SIAMBC and asks for a recovery phrase, seed phrase, private key, PIN or password, do not provide it. End the interaction and contact the company through its published channels.

Frequently asked questions

Can leaked order details unlock a hardware wallet?

No. Order information is not a recovery phrase or private key. Its danger is that it helps a scammer create a more believable story.

Should I change my PIN?

A customer-data leak does not reveal the device PIN. Changing it may be reasonable if you believe someone has seen it, but it does not solve the phishing risk created by exposed contact details.

Where should a recovery phrase be stored?

Keep it offline, private and protected from loss or physical damage. Never photograph it, upload it to cloud storage or type it into a website.

Conclusion

A reported SafePal customer data breach affected nearly 40,000 people. It did not expose recovery phrases, but it can make targeted phishing more convincing.

Latest Stories

View all

Does Trezor Support USDT? How to Choose the Right Network

Trezor supports USDT on Ethereum, Tron, Solana and other networks. Learn how to choose the right network, receive funds safely and avoid costly transfer mistakes.

Read moreabout Does Trezor Support USDT? How to Choose the Right Network

Ledger Op3n 2026 with Ledger Stax, Ledger Flex and Ledger Nano Gen5 in Paris

Ledger Op3n 2026: What to Watch as AI, Blockchain and Quantum Converge

Ledger Op3n 2026 comes to Paris on October 15 with AI, blockchain and quantum security at the centre. Here is what hardware wallet users should watch.

Read moreabout Ledger Op3n 2026: What to Watch as AI, Blockchain and Quantum Converge

FTX logo and an analytical network linking Ren, Alameda and 3AC in a Thai parliamentary inquiry

Taiyang Zhang, Ren, Alameda, FTX and 3AC: What Is Known and What Still Needs Proof

A clear account of the questions surrounding Taiyang Zhang, Ren, Alameda, FTX and 3AC, separating public business history from allegations that remain unproven.

Read moreabout Taiyang Zhang, Ren, Alameda, FTX and 3AC: What Is Known and What Still Needs Proof