SafePal Crypto Wallet Exposes Personal Info of 40,000 Users in Data Breach
A significant data breach has hit the cryptocurrency space, with SafePal, a popular crypto hardware wallet provider, disclosing that roughly 40,000 users had their personal information stolen. The breach occurred due to a vulnerability in an order-tracking function used by a customer order information plugin, allowing hackers to gain access to sensitive customer data.
The compromised information includes names, addresses, email addresses, phone numbers, and order details for customers who placed orders between March 2, 2025, and April 11, 2026. SafePal has assured its users that no other customer-related information was affected, including seed phrases, private keys, wallet passwords, or other sensitive credentials.
The data breach is believed to have been carried out by threat actors who exploited the vulnerability in the order-tracking function. The attackers advertised the stolen data on a cybercrime forum, claiming that 39,798 individuals were affected. SafePal confirmed this number and disclosed the incident on Sunday, prompting immediate action from the company to address the issue.
An investigation revealed that a bug in SafePal’s system resulted in order-related data being stored for much longer than intended. The company has since taken steps to rectify the situation by rebuilding its order-processing pipeline and tightening the retention period for order-related information. Additionally, over 30 fraudulent websites and phishing links tied to the scam activities have been identified and removed.
Customers who may have experienced financial losses related to the incident are urged to contact SafePal and provide relevant details. The company has also retained a third-party security firm to investigate further and ensure that no other sensitive data was compromised.
This breach serves as a stark reminder of the importance of cybersecurity in the cryptocurrency space, where users often store large amounts of sensitive information. SafePal’s swift response to the incident demonstrates its commitment to protecting user data and minimizing potential losses.
In light of this breach, it is essential for all crypto wallet users to remain vigilant about suspicious communication requesting their seed phrases or private keys. If you suspect that your wallet has been compromised, treat it as a security risk and create a new wallet using a trusted SafePal device or official application. This will help prevent any potential financial losses and ensure the continued security of your assets.
As the cryptocurrency industry continues to grow and evolve, incidents like this serve as a wake-up call for companies to prioritize cybersecurity and protect user data from potential threats. By staying informed and taking proactive measures, users can minimize their risk and maintain the security of their digital assets.
Source: SecurityWeek — 2026-08-17