Crypto hardware wallet provider SafePal has disclosed a security incident that exposed the personal information of 39,798 customers. The breach, which occurred due to an "authorization flaw" in a plug-in used for tracking customer orders, exposed names, physical addresses, and contact details of users who placed orders between March 2, 2025, and April 11, 2026. SafePal emphasized that no cryptocurrency funds, seed phrases, private keys, bank details, or government IDs were compromised. However, the company warned that affected users face heightened risks of phishing and impersonation attempts. SafePal has patched the vulnerability, implemented additional security measures, and hired a third-party firm to audit its systems. The company also stated it will now retain customer data for a maximum of 90 days and has removed over 30 fraudulent websites and phishing links associated with the incident. Customers can verify if their data was affected via a tool on SafePal's website.