TLDR
SafePal, a Binance-backed non-custodial wallet, has disclosed a data breach affecting 39,798 customers order data, while stressing that wallets, seed phrases, and funds remain secure.
- SafePal reports an authorization flaw in its order-tracking plugin exposed names, emails, phone numbers, shipping addresses, and purchase details for orders between March 2025 and April 2026.
- No seed phrases, private keys, wallet passwords, bank details, or government IDs were leaked, but affected users now face elevated phishing and impersonation risk.
- SafePal has patched the flaw, tightened data retention, and removed phishing sites; the key thing to watch is follow up security hardening and any evidence of data misuse.
Deep Dive
1. What Was Breached
SafePal says an authorization flaw in an order tracking plugin allowed unauthorized access to customer order records for people who bought SafePal products between 2 March 2025 and 11 April 2026. Reports from multiple outlets note that about 39,798 customers had their names, email addresses, shipping addresses, phone numbers, and purchase details exposed through this flaw, not their wallet secrets. The company describes the issue as a bug that let one users order tracking query reveal another customers order details, which is now patched according to its incident summary and coverage by sources such as Crypto wallet SafePal reveals a data breach exposing nearly 40,000 customers order info.
2. Impact On Wallets And Main Risk
SafePal emphasizes that hardware wallets, seed phrases, private keys, and wallet passwords are stored in an isolated environment separate from the ecommerce infrastructure, and were not touched in this incident. Independent reporting confirms that payment card numbers, bank account information, and government IDs were also not part of the leaked dataset, as noted in analysis like SafePal data breach exposes details of 40,000 users. The main risk is targeted phishing and impersonation using real names and shipping data, for example fake refund offers, firmware update links, or support calls designed to trick users into revealing their recovery phrase or private keys.
The breach is about identity and contact data, not direct crypto theft, but it increases the odds that convincing scams aimed at SafePal users will appear.
3. What To Watch Next
SafePal says it has fixed the plugin, added extra access controls, shortened personal data retention in the affected system to 90 days, and removed more than 30 fraudulent phishing websites. Affected customers have been emailed individually, and a lookup tool lets people check if their order was involved. For users, the most important signals to monitor are any suspicious communications claiming to be SafePal, and future transparency from the company about whether leaked data is being actively abused or whether further security reviews uncover deeper issues.
Confidence: high because several independent reports quote SafePals own incident disclosure and align on the scope and nature of the breach.
Conclusion
SafePals breach is serious in terms of personal data exposure but, based on current information, it does not compromise wallet keys or funds. The real danger is more convincing phishing and impersonation that leverage leaked customer details. Crypto users should treat this as another reminder that most wallet failures happen around the wallet, not inside it, and that strong habits around recovery phrases and private keys remain the best protection.
