SafePal Discloses Data Breach Affecting Nearly 40,000 Customers
SafePal says an authorization flaw exposed order information belonging to about 39,798 customers. Wallet credentials and funds were not affected, but the data could enable targeted phishing and impersonation.
Xcademia Team
Xcademia Research Team

SafePal Discloses Data Breach Affecting Nearly 40,000 Customers
Crypto wallet provider SafePal has disclosed a security incident involving unauthorized access to customer order information.
According to SafePal, an authorization flaw in an order-tracking function associated with customer order information allowed unauthorized access to another customer's order information under certain conditions. The affected information relates to customers who placed orders between March 2, 2025 and April 11, 2026.
SafePal said approximately 39,798 customers were affected.
The company said the incident did not involve seed phrases, private keys, wallet passwords or other wallet credentials. It also said bank account information, payment card numbers and government-issued identification numbers were not involved. SafePal said it found no evidence that the incident itself compromised access to wallets or funds.
However, the exposed order information creates a different security concern: attackers could use legitimate-looking customer details to make phishing and impersonation attempts more convincing.
What Happened in the SafePal Incident?
SafePal said it identified an authorization flaw in the order-tracking function for a plug-in associated with customer order information.
Under certain conditions, the flaw allowed unauthorized access to another customer's order information. SafePal said it remediated the issue after discovery and introduced additional security measures.
The affected information may have included:
Customer names
Email addresses
Shipping addresses
Phone numbers
Purchase details
Other order information
SafePal said the affected data involved approximately 39,798 customers whose orders fell within the specified period.
Reuters independently reported the same core details, citing SafePal's disclosure and describing the incident as unauthorized access to customer order information.

What Was Not Exposed?
One of the most important distinctions in the incident is between customer order information and wallet access credentials.
SafePal said the incident did not involve:
Seed phrases
Private keys
Wallet passwords
Other wallet credentials
Bank account information
Payment card numbers
Government-issued identification numbers
SafePal also said there was no evidence that the incident itself compromised access to customer wallets or funds.
Reuters reported the same distinction, noting that the breach did not involve seed phrases, private keys, wallet passwords, bank account information, payment card information or government-issued identification numbers.
This means the disclosed incident is primarily a customer information and phishing risk, rather than a reported direct compromise of wallet credentials.
Why the Exposed Order Information Matters
The information involved may appear less sensitive than a private key or seed phrase, but it can still be valuable to attackers.
A combination of a customer's name, contact information, shipping address and purchase details can provide enough context for a scammer to create a highly targeted impersonation attempt.
SafePal specifically warned that affected customers could receive fraudulent:
Phone calls
Emails
Text messages
Letters
Refund offers
Firmware-update requests
Fake customer-support communications
Malicious website links
The objective could be to persuade users to provide wallet credentials or other personal information.
The key risk is social engineering
The incident demonstrates an important cybersecurity distinction.
A breach does not necessarily need to expose passwords or cryptographic keys to create downstream security risks.
Information about a customer's purchase can give attackers additional context for impersonation.
For example, a fraudulent message that references a legitimate purchase may appear more credible than a generic phishing message.
This is an analysis based on the disclosed data and the phishing risks described by SafePal, not a claim that any particular customer has been targeted.

SafePal Says It Has Fixed the Issue
SafePal said it has already taken several steps following the incident.
The company said it has:
Fixed the authorization issue.
Implemented additional security measures.
Engaged an independent third-party security firm to validate the fix and conduct a broader review of its order-processing systems.
Reduced the retention period for personal information in the relevant order-processing environment to 90 days, subject to applicable legal requirements.
Established a dedicated support channel for the incident.
Notified affected customers individually where possible.
Contacted relevant logistics and fulfillment partners to investigate whether the issue had spread further within their systems.
Identified and taken down more than 30 fraudulent websites and phishing links associated with scam activity.
SafePal said it is continuing to monitor reports and scam activity and will provide further updates through its official channels.
What SafePal Is Advising Customers
SafePal is urging customers to be especially cautious about unsolicited communications.
The company recommends that customers:
Never share wallet credentials
SafePal says customers should never share their seed phrase, private key or password, including with someone claiming to be SafePal support.
Be careful with unexpected messages
Customers should avoid clicking links or scanning QR codes in unsolicited emails, text messages or letters claiming to come from SafePal.
Be suspicious of purchase-related communications
SafePal specifically advises customers to treat unexpected outreach or hardware deliveries referencing a SafePal purchase as suspicious, whether the contact arrives by phone, post or in person.
Verify websites independently
SafePal recommends manually entering its web address rather than following redirected links. The company also warned that fraudulent websites had previously attempted to imitate its domain.
Report suspicious activity
SafePal has established a dedicated reporting and support channel for the incident. The company advises customers not to contact it through social media for this matter because of privacy concerns.

What If a Customer Already Shared a Seed Phrase?
SafePal makes an important distinction for customers who may have already responded to a scam.
The company says that if someone has already shared or entered their seed phrase or private key in response to a suspicious message, website, phone call or letter, the affected wallet should be treated as compromised.
SafePal recommends creating a new wallet using a trusted SafePal device or official application and moving the remaining assets to the new wallet immediately.
For customers whose order information was affected but who have not disclosed their wallet credentials, SafePal says they should not need to move their assets solely because their order information was affected.
The Broader Cybersecurity Lesson
The SafePal incident highlights a broader issue in cybersecurity: personal information can become a security enabler for attackers even when critical credentials remain protected.
Names, addresses, phone numbers and purchase information can help attackers construct more believable social-engineering scenarios.
For crypto users, that risk can be particularly important because legitimate-looking communications about hardware wallets, firmware updates, account support or purchases may be used to create urgency.
The incident therefore reinforces a basic security principle: never treat a message as trustworthy simply because it contains accurate information about a previous purchase.
That information may have come from compromised customer data.
What Happens Next?
SafePal says its remediation work is ongoing.
The company is continuing to work with an independent security firm on validation of the fix and a broader review of its order-processing systems. It is also monitoring reports of scam activity and working to take down fraudulent websites and domains.
Additional findings or updates will depend on the company's continuing investigation.
Additional details were not disclosed in the announcement.
Source: SafePal
About the Author