TLDR
SafePal, a crypto wallet provider, has confirmed a data breach that exposed order information for 39,798 customers but not their wallet keys or crypto funds.
- An authorization flaw in SafePal's order tracking plugin exposed customer names, emails, shipping addresses, phone numbers and purchase details for orders between March 2025 and April 2026.
- Wallet seed phrases, private keys, passwords and payment data were not involved, but exposed users face higher phishing and impersonation risks from scammers posing as SafePal support.
- SafePal has patched the flaw, tightened data retention and removed over 30 phishing sites, while emailing affected users and offering a tool to check if an order was impacted.
Deep Dive
1. Scope Of The Breach
SafePal disclosed that a data breach affected about 39,798 customers order information, including names, email addresses, shipping addresses, phone numbers and purchase details for orders between 2 March 2025 and 11 April 2026, citing an authorization flaw in its order tracking system and plugin that allowed one order query to expose other customers details if manipulated SafePal data breach report.
Multiple reports from crypto media describe this as an incident confined to SafePals e commerce and support infrastructure, not to the wallet software or hardware itself, but still large enough to be one of the more significant wallet related data leaks in recent years, alongside earlier Trezor and Ledger customer data exposures SafePal breach coverage.
Confidence: high, because several independent outlets report consistent details and numbers.
2. Security Impact And Risks
SafePal stresses that seed phrases, private keys, wallet passwords, bank account and card details and government IDs were not exposed, and that there is no evidence of direct compromise of wallets or funds, thanks to the hardware wallets cold storage architecture being isolated from e commerce servers wallet security statement.
The main risk is targeted phishing and social engineering. With real names, emails, phone numbers and device order history, attackers can craft convincing messages that appear to be SafePal staff offering firmware updates, refunds or replacement devices, and then attempt to trick users into revealing recovery phrases or private keys phishing risk analysis.
for affected users, the biggest danger is giving away secrets in response to highly realistic fake support contacts, not an invisible drain from the wallet itself.
3. Response And What To Watch
SafePal says it has fixed the flawed plugin, added stricter access controls, shortened retention of personal order data to 90 days, and removed more than 30 phishing sites and related links tied to the incident post incident measures.
All known affected customers have been contacted by email, and SafePal provides a verification tool where users can input an order number and shipping country to check whether that order was exposed, while a third party security firm has been engaged to audit the fixes and review the order processing pipeline incident summary.
For any user who suspects they may have already shared a seed phrase or private key in response to a suspicious message, SafePal advises treating that wallet as compromised and moving assets to a new wallet.
Conclusion
This breach did not break SafePals core wallet security, but it did leak enough personal data to materially increase phishing and impersonation risk for nearly forty thousand customers.
The practical takeaway is that hardware wallets remain effective only if recovery phrases and keys stay secret, and incidents like this shift the battle line toward social engineering rather than technical exploits.
Watching for follow up disclosures from SafePal and other wallet providers, and staying skeptical of any unsolicited request for recovery phrases or keys, will be key to limiting the real world impact of this data leak.
