SafePal has disclosed a security incident that exposed order information for customers who bought products through its store, adding another reminder that hardware wallet users can face risks even when funds and private keys remain untouched.

The company said the incident affected customers who placed orders between March 2, 2025 and April 11, 2026. The exposed data included names, email addresses, shipping addresses, phone numbers, and purchase details. SafePal put the affected population at approximately 39,798 customers.

SafePal said the incident did not involve seed phrases, private keys, wallet passwords, bank account information, payment card numbers, or government-issued identification numbers. It also said it had found no evidence that the breach itself compromised access to SafePal wallets or funds.

That distinction is important, but it does not make the exposure harmless. Order records tied to hardware wallet purchases can be useful for targeted phishing, fake support messages, malicious delivery notices, or physical intimidation attempts. SafePal advised customers to be wary of unsolicited communications and to avoid sharing recovery phrases or private keys.

The breach is a narrow but meaningful security story for self-custody. Hardware wallets reduce one class of risk by keeping signing keys offline, but the surrounding commerce, support, and notification systems can still leak information that attackers may use to reach users directly.