Need help? Support
BITCOIN
Tether Dominance USDT.D

SafePal wallet breach exposes 39,798 customer orders

Published Updated 541 words 3 min read

TLDR

SafePal (SFP) has confirmed a data breach that exposed order information for 39,798 hardware wallet customers, while private keys and crypto funds remain unaffected.

  1. An authorization flaw in an order-tracking plugin let attackers access names, emails, shipping addresses, phone numbers and purchase details for orders from March 2025 to April 2026.
  2. No seed phrases, private keys, wallet passwords, bank details or government IDs were compromised, but affected users now face elevated phishing, impersonation and potential physical security risks.
  3. SafePal has patched the flaw, shortened data retention to 90 days and removed over 30 phishing sites, but users should treat any unsolicited support contact as suspicious and verify only via official channels.

Deep Dive

1. What Was Exposed And When

SafePal disclosed that about 39,798 customers who placed orders between 2 March 2025 and 11 April 2026 had their order records exposed via an authorization flaw in an order-tracking plugin. The leaked fields included names, email addresses, shipping addresses, phone numbers and detailed purchase information, according to incident reports from SafePal and multiple outlets such as Coindesk and crypto.news.

SafePal and independent coverage confirm that seed phrases, private keys, wallet passwords, payment card numbers, bank account data and government-issued IDs were not accessed. The breach was restricted to e?commerce order data, not the wallet infrastructure itself.

2. Why This Matters For Users And Hardware Wallet Trust

While funds and keys appear safe, attackers can use this personal data to craft highly convincing phishing and impersonation attempts, including fake refund offers, firmware update notices or support messages that reference real orders and addresses. SafePal and reporters warn that exposed shipping addresses also increase the risk of targeted physical wrench attacks for some users, as highlighted in Bitcoin.coms coverage.

This breach follows similar hardware wallet-related incidents at providers like Trezor, reinforcing that even cold storage brands are exposed through their web shops and logistics partners. For crypto holders, the lesson is that operational security now includes how and where you buy hardware, how much personal data vendors retain and whether you diversify wallet providers.

What this means

The main practical threat is social engineering using real personal details, so treating every unsolicited SafePal-branded message as hostile until verified is more important than ever.

3. What To Watch And Practical Safeguards

SafePal says it has fixed the plugin flaw, reduced personal-data retention in its order systems to 90 days and taken down more than 30 phishing websites linked to the incident, as reported by Reuters via Yahoo Finance. The company has emailed impacted users and offers a tool to check whether an order was affected.

For affected and non-affected users alike, useful safeguards include:

  1. Verify any SafePal-related update only through the official app or website typed manually, never via emailed links.
  2. Remember SafePals own guidance that it will never ask for your seed phrase, PIN or private keys in support interactions.
  3. If you ever shared such credentials in response to suspicious messages, treat that wallet as compromised and migrate assets to a fresh one.

Conclusion

The SafePal breach did not touch crypto wallets or keys, but it exposed enough personal order data to materially raise phishing and social-engineering risks for nearly 40,000 customers. For crypto users, the key takeaway is to harden verification habits around support and migration messages, and to factor vendor data practices into how you choose and buy hardware wallets.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top