SafePal Data Breach Exposes Order Details of Nearly 40,000 Crypto Wallet Customers

· · Views: 2,050 · 3 min time to read

Crypto wallet provider SafePal has disclosed a security breach affecting nearly 40,000 customers after a flaw in its order-tracking system allowed unauthorized access to personal and purchase information for more than a year.

Order-Tracking Flaw Remained Exposed for More Than a Year

The incident did not involve attackers breaking directly into customers’ cryptocurrency wallets. Instead, the weakness affected SafePal’s system for tracking product orders.

Reuters reported that an authorization flaw allowed one customer’s order information to be accessed by another between March 2, 2025, and April 11, 2026.

Binance Square similarly described the incident as stemming from a security vulnerability in SafePal’s order-tracking plugin, rather than from the core technology protecting cryptocurrency assets.

SafePal offers hardware wallets as well as mobile and browser-based wallets for storing and managing digital assets.

Seed Phrases and Private Keys Were Not Exposed

For cryptocurrency users, the most important distinction is what the attackers did not obtain.

The compromised information did not include seed phrases, private keys, wallet passwords, bank-account details, payment-card information or government-issued identification numbers.

Seed phrases, private keys, wallet passwords and bank-card information were not part of the exposed dataset.

That distinction matters because private keys and seed phrases provide access to cryptocurrency stored in a non-custodial wallet. The breach therefore exposed customer information associated with purchasing SafePal products rather than the secret credentials controlling users’ crypto holdings.

Personal Data Could Fuel Targeted Phishing

The absence of private keys does not make the incident harmless.

Reuters said SafePal warned that the stolen order information could be used for targeted phishing and impersonation attempts against affected customers.

That risk can be particularly significant for hardware-wallet owners because order information can potentially tell criminals that a specific person purchased a device intended to hold cryptocurrency. Names, addresses and purchase histories could therefore make fraudulent messages appear more convincing.

Binance Square’s reporting emphasized that users’ wallet credentials remained safe even though personal and order information had been exposed.

SafePal Takes Down More Than 30 Fraudulent Sites

SafePal says it has already responded to both the original vulnerability and scams connected with the incident.

SafePal fixed the flaw, introduced additional security measures and changed its policy so customers’ personal information remains in its order-processing system for only 90 days.

The company identified and removed more than 30 fraudulent websites and phishing links associated with the breach.

The incident demonstrates that protecting cryptocurrency involves more than securing the blockchain credentials themselves. SafePal says the keys controlling users’ wallets were untouched, but customer information surrounding the purchase of those wallets still carried enough value to create a separate security problem.

For nearly 40,000 affected users, the immediate threat is therefore less about someone directly emptying a wallet and more about criminals using authentic personal details to make the next phishing email, fake support message or impersonation attempt considerably harder to recognize.

Share
f 𝕏 in
Copied