Need help? Support
BITCOIN
Tether Dominance USDT.D

SafePal data breach hits 39,798 customers

Published 568 words 3 min read

TLDR

SafePal has confirmed a data breach that exposed order information for 39,798 customers but left wallet keys and funds untouched.

  1. The breach stemmed from an authorization flaw in an order-tracking plugin that exposed names, emails, shipping addresses, phone numbers and purchase details over a year-long period.
  2. Seed phrases, private keys, wallet passwords and payment data were not compromised, but affected users face elevated phishing, impersonation and potentially physical targeting risk due to leaked addresses.
  3. SafePal patched the flaw, tightened data retention to 90 days and removed phishing sites, while users should verify communications and consider diversifying storage across multiple trusted wallets.

Deep Dive

1. What Happened To SafePal Customers

SafePal, a non-custodial wallet provider backed by Binance, disclosed a security incident affecting about 39,798 customers who placed orders between 2 March 2025 and 11 April 2026.

Multiple outlets describe a data breach exposing order info for 39,798 customers, caused by an authorization flaw in an order-tracking plugin that let attackers see other users order records.

Exposed fields include names, email addresses, shipping addresses, phone numbers and detailed purchase information, but not wallet-related secrets or banking data.

Confidence: high, based on multiple independent reports and SafePals incident disclosure.

2. How Serious The Risk Is For Users

The main risk is targeted social engineering. With names, emails and order details, scammers can send convincing messages posing as SafePal support, offering refunds, replacements or firmware updates to trick users into revealing their seed phrases or private keys.

Because shipping addresses are included, some commentators note increased risk of so called wrench attacks, where attackers use physical coercion to obtain wallet access. The risk is highest for users with large holdings and publicly known crypto activity.

Importantly, SafePal and reporters stress that seed phrases, private keys, wallet passwords, bank account details, card numbers and government IDs were not accessed, so wallets are only at risk if users respond to phishing and voluntarily share secrets.

What this means

The incident is more a social engineering and physical safety problem than a direct on-chain theft, so vigilance around communications and privacy matters as much as technical wallet security.

3. SafePals Response And What To Watch Next

SafePal says it has fixed the plugin flaw, added stricter access controls, shortened personal data retention in its order system to 90 days and taken down more than 30 phishing websites tied to the breach. Some reports note criticism of delayed disclosure, with phishing complaints surfacing weeks before the public notice, so regulatory and reputational fallout is still possible.

For affected users, high-level safety steps include:

  1. Treat any unsolicited contact claiming to be SafePal as suspicious and verify via official channels before acting.
  2. Never share seed phrases, private keys or wallet passwords with anyone, including supposed support staff.
  3. If you have already entered such data on a suspicious site or shared it with a caller, consider your wallet compromised and migrate funds to a new, clean wallet.

More broadly, the breach adds to a pattern of wallet-related data incidents, reinforcing the case for diversifying storage and minimizing personally identifiable information tied to crypto purchases.

Conclusion

SafePals data breach did not directly touch users crypto holdings but exposed enough personal and order information to materially raise phishing and physical targeting risks.

For crypto users, the practical takeaway is to harden operational security around communications and identity, and to treat any request for wallet secrets as an immediate red flag, while regulators and the industry reassess how much customer data e-commerce and wallet vendors truly need to retain.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top