SafePal Confirms Data Breach Exposing Customer Order Information
Key Takeaways SafePal confirmed a data breach impacting nearly 40,000 customers. The breach exposed personal order details, including names, emails, shipping addresses, and phone numbers. The...
Key Takeaways
- SafePal confirmed a data breach impacting nearly 40,000 customers.
- The breach exposed personal order details, including names, emails, shipping addresses, and phone numbers.
- The incident stemmed from an authorization flaw in a third-party order-tracking plugin.
- No cryptocurrency assets, seed phrases, or private keys were directly compromised.
- Affected customers face increased risk of phishing and social engineering attacks.
SafePal Confirms Customer Data Breach
SafePal, a prominent cryptocurrency hardware wallet provider, has disclosed a security incident that resulted in unauthorized access to customer order information. The breach originated from a vulnerability within a plugin used for order tracking, allowing malicious actors to view sensitive data.
Table Of Content
The company stated that approximately 39,798 customers who placed orders between March 2, 2025, and April 11, 2026, were affected. The compromised data includes customer names, email addresses, physical shipping addresses, phone numbers, and specific purchase details.
Crucially, SafePal affirmed that the breach did not expose critical cryptocurrency security elements such as seed phrases, private keys, or wallet passwords. Financial data like bank account details, payment card numbers, or government-issued identification documents were also not compromised. The company attributed the incident to an authorization flaw in the order-tracking plugin, which under specific circumstances, permitted one party to access another customer’s order information without proper authentication. SafePal confirmed the vulnerability has since been patched, and additional security measures have been implemented.
Breach Details and Mitigation Efforts
SafePal reiterated that it does not store seed phrases, private keys, wallet passwords, banking information, payment card data, or identity documents, underscoring that these critical assets were not at risk. The company also found no evidence suggesting that the breach enabled attackers to access SafePal wallets directly or steal cryptocurrency holdings.
Despite no direct theft of cryptocurrency, the exposure of personal order details poses a substantial phishing risk. Threat actors could leverage this authentic purchase and shipping information to craft highly convincing fraudulent communications. Affected customers might receive deceptive emails, phone calls, text messages, fake refund offers, bogus firmware update requests, fabricated delivery notifications, or malicious links designed to trick them into revealing wallet credentials.
SafePal began notifying affected customers via email on August 16 from the address [email protected], using the subject line: “[Important] Your SafePal Order Information Has Been Affected.” The company urged customers to verify any communication independently through its official website, rather than clicking on links embedded in messages. A dedicated support channel has also been established for those impacted by the incident.
In its ongoing response, SafePal has engaged with logistics and fulfillment partners to ascertain if the data exposure extended to other systems. The company also reported successfully taking down over 30 fraudulent websites and phishing links associated with scam activities. Furthermore, SafePal has reduced the data retention period for personal information within the affected order-processing environment to 90 days, adhering to legal requirements. An independent third-party security firm has been engaged to validate the remediation efforts and conduct a comprehensive review of its broader order-processing systems.
What You Should Do
- Be Vigilant Against Phishing: Exercise extreme caution with any unsolicited communications, especially those claiming to be from SafePal.
- Verify Communications Independently: Do not click on links in emails or messages. Instead, manually type SafePal’s official website address into your browser to verify information or access support. SafePal warned about lookalike domains, including those that substitute the lowercase “l” with an uppercase “I”.
- Never Share Sensitive Credentials: SafePal will never ask for your seed phrase, private key, or wallet password via email, phone, text, or social media. Never disclose these to anyone.
- Beware of QR Codes: Avoid scanning QR codes from unexpected sources, as they can lead to malicious websites.
- Compromised Wallet Protocol: If you have entered your seed phrase or private key into a suspicious website, immediately consider that wallet compromised. Create a new wallet using an official SafePal device or application and transfer all remaining assets without delay.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.