SafePal Breach Data Stolen from 39,798 Customers
SafePal warns of phishing risk after order data for nearly 40,000 customers is exposed in a breach.
SafePal, maker of a popular cryptocurrency hardware wallet, is warning tens of thousands of customers to watch for phishing attempts after a data breach exposed order information. The incident, disclosed in an update on August 16, affects 39,798 customers who placed orders between March 2, 2025 and April 11, 2026.
What data was exposed
The stolen records include names, email addresses, shipping addresses, phone numbers, and purchase details, according to SafePal. The company stressed that the breach did not touch wallet credentials or financial data.
"This incident did not involve your seed phrase, private keys, wallet password, or other wallet credentials, bank account information, payment card numbers, or government-issued identification numbers," SafePal clarified. "SafePal never requests, collects, processes or stores such information from customers. No evidence has been found that the incident itself compromised access to SafePal wallets or funds."
Root cause: flawed order-tracking
The breach reportedly stemmed from a vulnerability in the company's order-tracking function for a plug-in. SafePal said that under certain conditions, the flaw allowed unauthorized access to another customer's order information. The firm says it remediated the issue upon discovery and introduced additional security measures.
Phishing risk and fraudulent sites
SafePal warned customers to expect "fraudulent phone calls, emails, text messages, letters, refund offers, firmware-update requests, fake customer-support communications" and other attempts to obtain wallet credentials or additional personal information. The company said it has already taken down over 30 fraudulent websites and phishing links associated with the incident.
According to screenshots posted to X, an individual has put the stolen data up for sale, although their claims have not been verified.
How customers can protect themselves
SafePal has published a dedicated page for reporting scams and a support channel for affected customers. The firm issued the following advice:
- Never share your seed phrase, private key, or password with anyone, even if they claim to be a SafePal employee.
- Don't click links or scan QR codes in unsolicited emails, text messages, or letters claiming to be from SafePal.
- Type the SafePal web address manually into the browser rather than following a redirected link, including any link that appears to come from this notice.
- Be on the lookout for any suspicious communication or impersonation, whether by phone, post or in person.
- Report anything suspicious, including messages, calls, letters or websites.
Why this matters
The breach is a reminder that even when a hardware wallet company keeps private keys secure, customer data can still be at risk. The exposed personal information could be used in targeted phishing campaigns aimed at gaining access to wallets or funds, so affected customers should be vigilant about unsolicited communications. The incident also suggests that supply chain or plugin vulnerabilities can be a weak point for crypto firms, potentially affecting user trust.
Sources
- Infosecurity Magazine Original source
- page Also reporting
Continue Reading
MCP Servers: A New Secret-Leak Vector
Model Context Protocol servers can expose enterprise secrets via plaintext configs, over-permissioning, and prompt injection, often undetected.
VoLTE Attack Chain Threatens Android Kernel Security
A two-stage exploit chain can achieve full Android kernel access on Unisoc devices via VoLTE video call, with no patch.
AI Safety Firm Reveals How a Name Mix-Up Led to Real-World Attacks
Irregular details an incident where AI models escaped a test environment and attacked a real company due to a naming error.