Smartphone displaying the SafePal crypto wallet app listing with logo, ratings, downloads, and install button.
TECHNOLOGY

SafePal Data Breach Exposes Details of Nearly 40,000 Users

Image credit: Shutterstock

Crypto wallet provider SafePal has disclosed a data breach that exposed personal order information belonging to approximately 39,798 customers. The affected records cover purchases made between March 2, 2025, and April 11, 2026.

Names, email addresses, shipping addresses, phone numbers and purchase details were accessed without authorization. SafePal said seed phrases, private keys, wallet passwords, bank account information, payment card numbers and government-issued identification numbers were not exposed, and it found no evidence that wallets or customer funds were compromised.

Order-Tracking Flaw Exposed 39,798 Customer Records

SafePal traced the breach to an authorization flaw in a plug-in used for order tracking. Under certain conditions, the defect allowed unauthorized access to another customer’s order information.

The company first received a phishing report consistent with the issue in early May. SafePal initially treated it as an isolated case before escalating its investigation and beginning a full review and rebuild of its order-processing pipeline in July, when it confirmed the underlying flaw.

A separate configuration error also prevented a scheduled data-cleanup process from working properly between September 2025 and April 2026. SafePal said that problem did not cause the unauthorized access but left older customer records stored longer than intended.

Exposed Shipping Details Raise Targeted Phishing Risk

SafePal warned that the leaked order data could help scammers create more convincing phishing and impersonation attempts using customers’ names, addresses, and purchase details. Possible tactics include fake support calls, refund offers, firmware-update requests and physical letters containing malicious instructions.

The company has identified and taken down more than 30 fraudulent websites and phishing links tied to scam activity around the incident. Affected customers were notified individually by email on August 16.

SafePal Cuts Sensitive Order-Data Retention to 90 Days

SafePal said it fixed the authorization flaw and strengthened access controls around its order-processing systems. It is also engaging an independent security firm to validate the fix and conduct a wider review.

The company shortened retention of sensitive order information to 90 days and contacted logistics and fulfillment partners to determine whether their systems were impacted. SafePal said it has found no evidence that the incident extended into those external systems.

Affected customers do not need to replace their hardware wallets or move their assets solely because of the breach. SafePal said anyone who has already disclosed a seed phrase or private key to a suspected scammer should treat that wallet as compromised and move remaining assets to a newly created wallet.

More For You

Explore More News