All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

SafePal data breach exposes 39,798 customers' order information

Created at 16 Aug · 2:11 PM1 source↑ Market-relevant
IN SHORT

Crypto hardware wallet provider SafePal has disclosed a security incident affecting 39,798 customers. The breach exposed names, physical addresses, and contact details due to an authorization flaw in an order-tracking plug-in. No crypto funds or private keys were compromised.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

39,798customers affected by data breach
March 2, 2025 - April 11, 2026order placement window for affected customers
90 daysmaximum data retention period for order processing
30+fraudulent websites and phishing links removed

Who's Involved

SafePal
Crypto hardware wallet provider that experienced a data breach
[email protected]
Email address used by SafePal to notify affected customers
SafePal data breach exposes 39,798 customers' order information

↳ Why This Matters

The data breach highlights ongoing security risks in the cryptocurrency ecosystem, even for hardware wallet providers, and underscores the importance of robust data protection measures and customer vigilance against phishing attempts.

Key facts

  • Crypto wallet provider SafePal experienced a data breach.
  • The incident exposed personal information of 39,798 customers.
  • Exposed data includes names, physical addresses, and contact details.
  • No cryptocurrency funds, private keys, or seed phrases were compromised.
  • The breach stemmed from an authorization flaw in an order-tracking plug-in.

Crypto hardware wallet provider SafePal has disclosed a security incident that exposed the personal information of 39,798 customers. The breach, which occurred due to an "authorization flaw" in a plug-in used for tracking customer orders, exposed names, physical addresses, and contact details of users who placed orders between March 2, 2025, and April 11, 2026. SafePal emphasized that no cryptocurrency funds, seed phrases, private keys, bank details, or government IDs were compromised. However, the company warned that affected users face heightened risks of phishing and impersonation attempts. SafePal has patched the vulnerability, implemented additional security measures, and hired a third-party firm to audit its systems. The company also stated it will now retain customer data for a maximum of 90 days and has removed over 30 fraudulent websites and phishing links associated with the incident. Customers can verify if their data was affected via a tool on SafePal's website.

Frequently asked questions

The breach exposed customer names, physical addresses, and contact details for those who placed orders between March 2, 2025, and April 11, 2026.

No, SafePal stated that cryptocurrency funds, seed phrases, private keys, bank details, and government IDs were not affected by the breach.

The breach was caused by an "authorization flaw" in a plug-in used by SafePal to track customer orders, which likely allowed unauthorized access to order details.

SafePal has patched the vulnerability, enhanced security measures, notified affected customers, hired a third-party auditor, and removed fraudulent websites.

What Happens Next

01Customers can use a verification tool on SafePal's website to check if their data was affected.
02SafePal will retain customer personal data for a maximum of 90 days.
03A third-party security firm is auditing SafePal's fix and order-processing systems.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence

How It Developed

SafePal disclosed a security incident affecting customer data.
The breach impacted 39,798 customers who placed orders between March 2, 2025, and April 11, 2026.
Exposed data included names, physical addresses, and contact details.
No cryptocurrency funds, seed phrases, private keys, or government IDs were compromised.
SafePal identified an "authorization flaw" in a plug-in used for tracking customer orders.
The company has patched the vulnerability and implemented additional security measures.
Affected customers were notified via email, and a third-party firm is auditing the fix.
SafePal will now retain personal data for only 90 days.

Sources

T1
Crypto wallet SafePal reveals a data breach exposing nearly 40,000 customers' order infoCoinDesk

Related Stories

EU crypto crackdown fuels surge in scam activity
16 Aug · 2:06 PM
Russia Bans Bitcoin Mining in Moscow, Kursk Through 2032
15 Aug · 3:27 PM
Tokenized Stock Holders Surge to 1.31 Million as Volume Tops $23 Billion
15 Aug · 5:31 PM
TradFi giants embrace digital assets, ending 'long bitcoin, short bankers' era
16 Aug · 12:06 PM
Bybit adds Unitree, Moonshot AI to pre-IPO perpetuals lineup
15 Aug · 7:36 PM