Breaking
SecurityDeveloping Story

SafePal Breach Exposes 40K Customer Records

SafePal reports a breach affecting 39,798 customers, exposing personal data through a plugin flaw.

··2 hours ago·3 min read
a wallet with bitcoins falling out of it
Photo by Shubham Dhage on Unsplash

SafePal, a cryptocurrency hardware wallet provider, has reported a data breach that exposed personal information of tens of thousands of customers. The incident, which came to light on a Sunday, was disclosed by the company in a security update, and a threat actor was simultaneously advertising the stolen data on a cybercrime forum. The breach serves as a reminder that even security-focused products are not immune to data exposure.

Plugin Vulnerability Exploited

According to SafePal, hackers exploited a vulnerability in the order-tracking feature of a customer order information plugin, allowing them to access customer data. The company did not name the specific plugin or provide technical details about the flaw, but stated that the attack targeted the order processing pipeline.

SafePal says it began investigating after receiving a report in May, initially treating it as an isolated case. However, further investigation revealed that a bug in its system caused order-related data to be retained for much longer than intended, increasing the impact of the breach.

Scope of Affected Data

The compromised information includes names, addresses, email addresses, phone numbers, and order details. SafePal emphasized that no other customer-related information was affected. The company specifically stated that payment card numbers, bank account information, government-issued identification numbers, and, critically, wallet credentials were not compromised.

“This incident did not involve your seed phrase, private keys, wallet password, or other wallet credentials, bank account information, payment card numbers, or government-issued identification numbers,” the company said.

  • Approximately 39,798 customers affected
  • Compromised data includes names, addresses, emails, phone numbers, and order details
  • Over 30 fraudulent websites and phishing links taken down

Timeline and Response

SafePal disclosed the breach on Sunday, the same day a threat actor began advertising the theft of SafePal data on a cybercrime forum, with the attacker claiming 39,798 affected individuals, matching the company's disclosure. The company says it addressed the vulnerability, tightened retention periods for order information, identified and notified impacted individuals, and contacted partners to prevent further spread.

To resolve the root cause, SafePal initiated a full review and rebuild of its order-processing pipeline in July, confirming the issue during the investigation. The company also retained a third-party security firm to conduct an independent investigation.

Phishing Threats and Warnings

SafePal is warning potentially affected individuals to be wary of suspicious communications requesting seed phrases or private keys. The company has identified and taken down over 30 fraudulent websites and phishing links associated with the incident, and continues to monitor for new ones.

“If you have already shared or entered your seed phrase or private key in response to a suspicious message, website, phone call, or letter, treat that wallet as compromised. Create a new wallet using a trusted SafePal device or official SafePal application, and move your remaining assets to the new wallet immediately.”

— SafePal, in its security update

Recovery Support and Legal Disclaimer

The company encourages customers who may have experienced financial losses related to the incident to contact SafePal with relevant details. SafePal says it has been contacting on-chain asset-tracing specialists to assist with recovery efforts, but clarified that this does not constitute an admission of liability or a commitment to compensation.

“Note that this does not represent any admission of liability or commitment to compensation; our focus at this stage is supporting recovery and ongoing investigations,” the company said.

Implications for Crypto Users

This breach underscores the broader risk of data exposure in the cryptocurrency ecosystem. While SafePal's hardware wallets themselves were not directly compromised, the stolen personal information could enable targeted phishing attacks, which remain a primary vector for asset theft in the crypto space. Users who receive unsolicited messages referencing the breach should exercise extreme caution, as legitimate companies will never ask for seed phrases or private keys.

The incident also highlights that data breaches at third-party systems, such as order processing plugins, can have ripple effects on security-focused companies. For SafePal customers, the immediate concern is not their wallet's cryptographic security, but the potential for social engineering attempts that could trick them into revealing their credentials. Moving forward, both SafePal and its users must remain vigilant against the fallout of this data exposure.

#safepal#data breach#cryptocurrency#hardware wallet#phishing

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories