Need help? Support
BITCOIN
Tether Dominance USDT.D

SafePal data breach exposes 39,798 customers

Published Updated 477 words 3 min read

TLDR

SafePal has confirmed a data breach that exposed order information for 39,798 customers, raising phishing and physical security risks even though wallet keys remain intact.

  1. The breach came from an authorization flaw in an order tracking plugin, exposing names, addresses and contact details from orders between March 2025 and April 2026.
  2. Seed phrases, private keys and funds were not touched, but exposed users face higher phishing and potential physical attack risk similar to past hardware wallet leaks.
  3. SafePal has patched the flaw, tightened data retention and opened a verification page, while criticism over slow disclosure shows how critical vendor security and transparency have become.

Deep Dive

1. Breach Scope And Data

SafePal disclosed that an authorization flaw in its order tracking system allowed attackers to access other customers order details, affecting 39,798 users who bought products between March 2, 2025 and April 11, 2026. Reports note that exposed data includes names, email addresses, shipping addresses, phone numbers and purchase information, but not payment card numbers or government IDs. SafePal and multiple outlets emphasize that seed phrases, private keys, wallet passwords and crypto funds were not involved, framing this as an e commerce side breach rather than a direct wallet compromise.

2. Risks For Affected Users

Even without key exposure, combining personal identity, shipping address and proof of crypto purchases creates a powerful dataset for targeted scams. Media coverage warns of convincing phishing and impersonation attempts where attackers pose as SafePal support, offer refunds or firmware updates, and try to trick users into revealing wallet credentials. Analysts also point to the growing risk of so called wrench attacks, where criminals use physical threats against known crypto holders, citing earlier incidents after Ledger and Trezor customer data leaks.

What this means

The main danger is social engineering, not automatic fund loss, so the practical risk is responding to fake support or pressure messages that misuse your exposed details.

3. SafePal Response And Lessons

SafePal says it has fixed the plugin flaw, added access controls, shortened personal data retention in its order system to 90 days and engaged a third party security auditor, according to detailed coverage from outlets such as Coindesk. The company has emailed affected customers, taken down more than 30 phishing sites and published a verification page where users can check if their order was in the breached set using an order ID and country. However, investigators and users have criticized SafePal for not linking earlier scam reports to a possible breach sooner, underlining how delays in disclosure can compound harm.

Conclusion

The SafePal incident shows that hardware wallet security is not just about keeping seed phrases offline, but also about protecting the customer databases that reveal who owns those devices. Even though wallets and keys remain technically secure, nearly forty thousand users now face elevated phishing and possible physical targeting risk, and the wider crypto community gets another reminder that vendor selection should factor in operational security and breach response, not just product features.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top