SafePal Cryptocurrency Wallet Suffers Massive Data Breach, 40,000 Customers Impacted
A massive data breach has left around 40,000 customers of SafePal, a popular cryptocurrency hardware wallet, vulnerable to potential financial loss. The attackers exploited a vulnerability in the order-tracking function of a customer order information plugin, gaining access to sensitive personal and order details.
The compromised data includes names, addresses, email addresses, phone numbers, and order details, leaving those affected at risk of phishing scams or other malicious activities targeting their seed phrases or private keys. SafePal has assured customers that no other sensitive information, such as wallet passwords, bank account details, or government-issued identification numbers, was accessed during the breach.
The incident is believed to have occurred between March 2, 2025, and April 11, 2026, with SafePal first becoming aware of the issue in May. However, it wasn’t until July that the company began a full review and rebuild of its order-processing pipeline, ultimately identifying the root cause of the vulnerability.
Fortunately, SafePal has taken swift action to address the issue, including fixing the exploited vulnerability, tightening the retention period for order-related information, and notifying all affected customers. The company is also working closely with partners to prevent further propagation of the issue and has retained a third-party security firm to investigate the breach in more detail.
In addition, SafePal has identified and taken down over 30 fraudulent websites and phishing links tied to scam activities related to the incident, with continued active monitoring for new ones. The company is urging customers who may have experienced financial losses as a result of the breach to contact them immediately and provide relevant details.
While this data breach highlights the importance of robust security measures in protecting sensitive customer information, it also underscores the need for vigilance among cryptocurrency wallet users. SafePal advises all affected individuals to be cautious of suspicious communication requesting their seed phrases or private keys and to take immediate action if they have already shared or entered these sensitive details.
For those using a SafePal device or official application, the company recommends creating a new wallet immediately and moving any remaining assets to the new wallet. This precautionary measure will help prevent potential financial loss in case the compromised wallet is targeted by scammers. As always, staying informed about security best practices and being proactive in protecting one’s online identity can significantly mitigate the risks associated with data breaches like this one.
Source: SecurityWeek — 2026-08-17