SafePal Data Breach: Nearly 40,000 Customer Order Details Exposed
SafePal announced a data breach exposing order details for nearly 40,000 customers. Private keys and crypto assets remain secure, but the exposed data may lead to phishing attempts.

Cryptocurrency hardware wallet provider SafePal announced a data breach that exposed the personal order information of approximately 39,798 customers. The company stated that the breach, which affected orders placed between March 2, 2025, and April 11, 2026, included data such as names, email addresses, shipping addresses, phone numbers, and purchase details. SafePal emphasized that this incident did not impact customers' seed phrases, private keys, or crypto assets within their wallets, confirming that funds remained secure.
The root cause of the breach was identified as an authorization flaw in a plugin used by SafePal for its order-tracking system. This vulnerability, under certain conditions, allowed unauthorized access to another customer's order information by manipulating the order number. SafePal reported that it remediated the issue immediately upon discovery and implemented additional security measures. It was also noted that a data retention configuration error between September 2025 and April 2026 led to older order records being stored longer than intended, thereby extending the affected period. The company has individually notified all affected customers via email and launched a verification tool where customers can check their status using their order ID and shipping country.
Such data breaches typically have a limited direct and immediate price impact on cryptocurrency markets, as this incident compromised personal data rather than the security of crypto assets themselves. However, it can negatively affect user trust and indirectly slow down new customer acquisition. In a broader industry context, it underscores the critical importance of customer data protection for hardware wallet providers. Following the breach, SafePal announced that it has reduced the retention period for personal data in its order processing system to 90 days and has taken down over 30 fraudulent websites and phishing links.
This incident generally highlights the persistent cybersecurity risks within the cryptocurrency ecosystem and re-emphasizes the significance of protecting users' personal data. It particularly shows that third-party integrations within the ecosystem of products considered “secure,” such as hardware wallets, can also pose risks. Recent similar data exposures faced by other wallet providers like Trezor and Ledger indicate a need for tightened supply chain and partner security audits across the industry.
Analysts and market observers suggest that SafePal's swift and transparent response is crucial for rebuilding customer trust. However, warnings about the potential use of exposed information for phishing and impersonation attempts must be taken seriously. SafePal urged customers to remain vigilant against any suspicious contact or hardware delivery referencing their SafePal purchase and reiterated that it would never ask for seed phrases or private keys. The company also added that it is working with an independent third-party security firm to validate its fixes and conduct a broader review of its systems.
₿ Want to ride this crypto move?
Open an account in minutes. Compare brokers offering crypto and start investing today — zero commission options available.
Comments (0)
No comments yet. Be the first to comment!