SafePal data breach exposes personal information of nearly 40,000 customers.

SafePal data breach leaks 40,000 customers

SafePal has disclosed a security breach that exposed personal and purchase information belonging to approximately 39,798 customers.

The cryptocurrency wallet company said an authorisation flaw in its order-tracking plug-in allowed unauthorised access to information belonging to a subset of customers.

The incident affected customers who placed orders between March 2, 2025 and April 11, 2026. The exposed information includes names, email addresses, shipping addresses, phone numbers and purchase details.

SafePal said the vulnerability has been fixed and that additional security measures have been introduced.

The company stressed that the incident did not expose customers’ seed phrases, private keys or wallet passwords. Bank account information, payment card numbers and government-issued identification numbers were also not involved.

This means the incident was focused on customer and order information rather than the cryptocurrency stored in SafePal wallets.

SafePal is a non-custodial wallet provider, meaning users retain control of their private keys and recovery phrases rather than SafePal holding them on their behalf.

However, the exposure of personal information can still create security risks, particularly for cryptocurrency users who may become targets of phishing and impersonation attacks.

SafePal said it has contacted all affected customers individually by email.The company has also published a page where customers can check whether they were affected using their order ID and shipping country.

The company warned users to remain cautious about phishing attempts and impersonators, particularly anyone claiming to represent SafePal and asking for sensitive wallet information.

SafePal said users should never share their seed phrase, private key or wallet password with anyone.

How the breach happened

The issue was linked specifically to SafePal’s order-tracking system. An authorisation flaw in the plug-in meant that information connected to customer orders could be accessed without the proper permission.

That is different from an attacker gaining direct access to the underlying cryptocurrency wallets.

The incident shows why security risks for crypto companies extend beyond the technology protecting users’ funds. Customer databases, e-commerce systems and third-party services can also contain information that can be used to target users.

In this case, the exposed records included physical shipping addresses and phone numbers alongside information about customers’ SafePal purchases.

Although according to them no seed phrases or private keys were exposed, the leaked information could still be valuable to scammers.

However, a criminal who knows a person’s name, phone number, home address and that they purchased a crypto hardware wallet has more information to create a convincing impersonation attempt.

For example, an attacker could contact an affected customer claiming that their SafePal device needs a security update or replacement and then try to convince the person to provide their recovery phrase or visit a malicious website.

SafePal has therefore urged affected users to be particularly careful with unexpected calls, emails and messages.The company said it will continue publishing updates as it works through the incident.

The breach is another reminder that protecting crypto assets involves more than securing a wallet’s private keys. Personal information connected to a crypto purchase can also become a target, and users need to treat unexpected requests for wallet credentials with the same level of caution as any other attempt to access their funds.

Read also: Asset Chain: The Layer 1 protocol for tokenised real-world economy

Leave a Reply