SafePal Confirms Data Breach Exposing Order Information for Nearly 40,000 Customers
Cryptocurrency wallet provider SafePal has confirmed a data breach affecting nearly 40,000 customers, exposing names, emails, and shipping addresses due to a flaw in an order-tracking plug-in.

Cryptocurrency wallet provider SafePal has confirmed a security incident where unauthorized parties gained access to customer order information, impacting approximately 39,798 users. The breach, which occurred between March 2, 2025, and April 11, 2026, exposed sensitive details such as customer names, email addresses, shipping addresses, and phone numbers. While wallet credentials, private keys, and cryptocurrency assets remained secure, the exposed data poses a significant phishing risk to affected individuals.
The vulnerability stemmed from an authorization flaw within a plug-in used for tracking customer orders. This flaw, under specific conditions, allowed unauthorized access to another customer's order details. SafePal stated that it has since rectified the vulnerability and implemented additional security measures to prevent recurrence. The company reiterated that it does not collect or store critical user data like seed phrases, private keys, or wallet passwords, and confirmed no evidence suggests access to SafePal wallets or theft of digital assets.
Despite the non-compromise of financial assets, the exposed personal information presents a substantial threat. Attackers could leverage the accurate purchase and shipping details to craft highly convincing phishing messages, potentially tricking users into revealing wallet credentials or clicking malicious links. These fraudulent communications might mimic official support emails, delivery notifications, or urgent requests for firmware updates.
SafePal has begun notifying affected customers via email from [email protected], with the subject line "Important Your SafePal Order Information Has Been Affected." The company strongly advises customers to independently verify any communication by visiting the official SafePal website rather than relying on links provided in suspicious messages. A dedicated support channel has been established for those impacted by the incident.
In response to the breach, SafePal has taken several proactive steps. The company is collaborating with relevant logistics and fulfillment partners to ascertain the extent of the exposure across other systems. Furthermore, SafePal has successfully identified and taken down over 30 fraudulent websites and phishing links associated with scam activities related to the breach.
To enhance data security, SafePal has reduced the data retention period for personal information within the affected order-processing environment to 90 days, adhering to legal requirements. The company is also engaging an independent third-party security firm to conduct a thorough review of its order-processing systems and validate the implemented remediation measures.
SafePal urges its customers to remain vigilant and never share their seed phrase, private key, or wallet password with anyone claiming to represent the company. They emphasize that SafePal will never request such sensitive information through email, phone, text, or social media. Users should exercise caution with unexpected messages, avoid clicking on links or scanning QR codes, and manually navigate to the official SafePal website for account or support information. Customers who may have already entered sensitive information into a suspicious website are advised to treat their wallet as compromised and immediately create a new wallet, transferring any remaining assets to it.
The article provides further details on the SafePal data breach, specifying that the attackers exploited a vulnerability in the order-tracking function of a customer order information plugin. It also clarifies that the compromised data includes names, addresses, email addresses, phone numbers, and order details, but explicitly excludes sensitive wallet credentials, payment card numbers, or government identification.
The new article reveals that the compromised data includes names, email and shipping addresses, phone numbers, and purchase details for customers who placed orders between March 2, 2025, and April 11, 2026. It also clarifies that the breach did not compromise seed phrases, private keys, wallet passwords, or other wallet credentials, nor did it affect bank account information, payment card numbers, or government-issued identification. SafePal has taken down over 30 fraudulent websites and phishing links associated with the incident.
A threat actor has surfaced on a cybercrime forum claiming to be selling data exfiltrated from the SafePal breach, mirroring the customer count and order window disclosed by the company. The seller is offering order IDs and shipping countries for verification before purchase, though the authenticity of the data remains unconfirmed. SafePal continues to monitor for and take down fraudulent sites associated with the incident.
The latest report confirms that nearly 40,000 SafePal customers were impacted by the breach, with user information being stolen. While the exact method of intrusion and the full scope of exfiltrated data remain undisclosed, the incident underscores the persistent security challenges faced by hardware wallet providers and their user base.
The new article reveals that a threat actor has advertised a dataset on a cybercrime forum matching the customer count and order window of this breach, indicating potential sale of the compromised data. SafePal has not yet publicly commented on this listing. Additionally, the article details SafePal's implemented security measures, including reducing personal information retention to 90 days, purging affected records, engaging a third-party firm for validation, and taking down over 30 fraudulent websites and phishing links.