Crypto Wallet Service SafePal Reports Data Breach Exposing Nearly 40,000 Customer Order Details

Deep News
Aug 17

SafePal, a provider of cryptocurrency hardware wallets, has disclosed a security incident affecting approximately 39,798 customers, with their order information exposed.

The leaked data includes personal details such as customer names, addresses, and contact information, placing affected users at risk of phishing and impersonation scams. The company emphasized that all private keys, seed phrases, and crypto assets remain unaffected by this event, and the core security of the wallets is intact.

SafePal is a cryptocurrency security firm that offers physical hardware wallets and software applications to help investors securely store and manage digital assets. The company stated that the incident stemmed from an "authorization vulnerability" in an order tracking plugin, which may have allowed attackers to view other customers' order information by altering order numbers. The exposure affected customers who placed orders between March 2, 2025, and April 11, 2026.

SafePal stressed that users' seed phrases, private keys, bank passwords, bank account details, payment card numbers, and government-issued identification documents were not compromised. However, if customers shared their private keys or seed phrases via phishing emails, calls, or letters, they should consider their wallets compromised and immediately transfer their assets to a new wallet. SafePal said it has fixed the vulnerability and implemented additional security measures. It has notified all affected customers via its official email and has hired an independent third-party security firm to audit the fix and the order processing system. The company has also shortened the retention period for customer personal data in the order processing system to 90 days from the date of collection and has identified and removed over 30 fraudulent websites and phishing links related to the incident. Customers can use a verification tool on the SafePal official website to check if their data was affected.

This incident follows closely on the heels of a recent hack on the Coldcard hardware wallet, where attackers reportedly stole at least $120 million in Bitcoin. While these two events do not necessarily indicate a systemic weakness in hardware wallets, they demonstrate that crypto asset storage solutions are not entirely risk-free. They also underscore the importance of assessing concentration risks and, where appropriate, diversifying crypto asset holdings and wallet storage.

Disclaimer: Investing carries risk. This is not financial advice. The above content should not be regarded as an offer, recommendation, or solicitation on acquiring or disposing of any financial products, any associated discussions, comments, or posts by author or other users should not be considered as such either. It is solely for general information purpose only, which does not consider your own investment objectives, financial situations or needs. TTM assumes no responsibility or warranty for the accuracy and completeness of the information, investors should do their own research and may seek professional advice before investing.

Most Discussed

  1. 1
     
     
     
     
  2. 2
     
     
     
     
  3. 3
     
     
     
     
  4. 4
     
     
     
     
  5. 5
     
     
     
     
  6. 6
     
     
     
     
  7. 7
     
     
     
     
  8. 8
     
     
     
     
  9. 9
     
     
     
     
  10. 10