SafePal data breach impacts 39,798 customers, stolen info for sale

A massive data breach at cryptocurrency hardware wallet provider SafePal has compromised sensitive information belonging to nearly 40,000 customers. The breach, which occurred between March 2025 and April 2026, exposed names, email addresses, shipping addresses, phone numbers, and purchase information for all affected individuals. However, SafePal claims that wallet seed phrases, private keys, passwords, bank account information, payment card numbers, government-issued identification numbers, or other credentials were not compromised.

The breach was caused by an authorization flaw in the order-tracking function of a plug-in used in SafePal’s e-commerce system. This vulnerability allowed unauthorized access to customer order information, which has now been exploited by a threat actor who claims to be selling the stolen data on a cybercrime forum. The seller is offering approximately 39,798 sets of compromised data, along with proof that the sale is legitimate through SafePal’s online verification tool.

SafePal first received a report consistent with the incident in early May 2026, but initially treated it as an isolated case. It wasn’t until July that the company began a “full review and rebuild” of its order-processing system, which ultimately led to the discovery of the authorization flaw and subsequent investigation into the breach. The company has since fixed the vulnerability, implemented additional security measures, and is working with a third-party security firm to validate the fix and conduct a broader review of its systems.

The breach highlights the importance of robust security measures in protecting sensitive customer data. SafePal’s order-tracking system involves multiple interconnected components and external integrations, as well as third-party logistics partners, making it vulnerable to exploits like this one. As part of their investigation, SafePal also discovered a separate configuration error that caused a data-cleanup process to stop functioning correctly between September 2025 and April 2026, resulting in order data being retained as far back as March 2025.

Customers who placed orders during the affected period are urged to watch for targeted phishing emails and phone calls about firmware upgrades, product returns, refunds, or legal investigations. SafePal has already taken down more than 30 fraudulent websites and phishing links tied to this incident, but customers must remain vigilant to avoid falling prey to these tactics.

SafePal has notified all impacted customers via email with the subject “[Important] Your SafePal Order Information Has Been Affected.” The company also provides an online verification tool that allows customers to enter their order number and shipping country to determine whether their details were stolen. This proactive approach demonstrates SafePal’s commitment to transparency and customer safety.

To stay safe, customers should monitor their accounts for suspicious activity, be cautious of unsolicited emails or phone calls requesting sensitive information, and report any concerns to SafePal directly. Additionally, consider enabling two-factor authentication on your SafePal account and regularly review your order history to detect any discrepancies. By taking these precautions, you can minimize the risk of falling victim to phishing attacks and protect your sensitive financial information.


Source: Bleeping Computer — 2026-08-16