SafePal data breach impacts 39,798 customers, stolen info for sale

SafePal Warns of Data Breach Affecting 39,798 Customers, Stolen Info Put Up for Sale Online

A significant data breach has been uncovered at SafePal, a leading provider of cryptocurrency hardware wallets. The company has revealed that approximately 39,798 customers had their order information compromised after a flaw in the order-tracking function was exploited by a threat actor. The stolen data, which includes names, email addresses, shipping addresses, phone numbers, and purchase information, is now being sold on a cybercrime forum.

The breach occurred between March 2, 2025, and April 11, 2026, affecting customers who placed orders during this period. Fortunately, SafePal assures that wallet seed phrases, private keys, passwords, bank account information, payment card numbers, government-issued identification numbers, or other sensitive credentials were not exposed. However, the company warns that the stolen data could still be used to launch targeted phishing and social engineering attacks against affected customers.

As evidence of the breach, a threat actor is offering the stolen customer data for sale on a cybercrime forum. The seller claims to have information on approximately 39,798 customers who placed orders during the specified period, which aligns with SafePal’s initial disclosure. However, it remains unclear whether the threat actor actually possesses the stolen data.

SafePal’s investigation into the breach revealed that an authorization flaw in the order-tracking function of a plug-in allowed unauthorized access to customer order information. The company has since fixed the vulnerability and implemented additional security measures, including a full review and rebuild of its order-processing system. A third-party security firm is currently working with SafePal to validate the fix and conduct a broader review of its order-processing systems.

For affected customers, SafePal has launched an online verification tool that allows individuals to enter their order number and shipping country to determine whether their details were stolen. The company has also taken steps to purge personal data from active e-commerce servers for orders affected by the breach, although an encrypted offline copy is being retained for potential law-enforcement investigations.

In a disturbing twist, some customers have reported receiving SafePal phishing emails and phone calls as early as May, claiming that a security vulnerability had been discovered in the company’s hardware wallets. These attempts are likely linked to the data breach, with scammers using stolen information to launch targeted attacks against affected individuals.

As the cryptocurrency market continues to grow, it’s essential for users to remain vigilant about their online security. SafePal’s warning serves as a reminder that even reputable companies can fall victim to data breaches. To protect yourself from similar incidents, make sure to regularly monitor your accounts and be cautious of unsolicited emails or phone calls claiming to be from your wallet provider.

In light of this breach, it’s crucial for customers to take proactive steps to safeguard their online security. When interacting with SafePal or any other cryptocurrency service, always verify the authenticity of communications through official channels. Never provide sensitive information in response to an unsolicited email or phone call, and report any suspicious activity to the relevant authorities immediately. By staying informed and vigilant, you can minimize your risk of falling victim to similar attacks in the future.


Source: Bleeping Computer — 2026-08-16