Nearly 40,000 SafePal customers had their personal and order information exposed after a security flaw allowed unauthorized access to the cryptocurrency wallet provider’s order-tracking system.
SafePal said an authorization flaw in a plug-in connected to customer orders allowed outsiders, under certain conditions, to access another customer’s information. The incident affected approximately 39,798 customers who placed orders between March 2, 2025, and April 11, 2026.
Exposed information included names, email addresses, shipping addresses, phone numbers, and purchase details.
The cryptowallet company assured that seed phrases, private keys, wallet passwords, bank account information, payment card numbers, and government-issued identification numbers were not exposed. It also found no evidence that the incident directly compromised customer wallets or cryptocurrency funds.
Exposed Order Data Raises Phishing Risk
The biggest immediate threat for affected customers is social engineering.
SafePal warned that attackers could use the compromised information to create convincing phone calls, emails, text messages, letters, refund offers, firmware-update requests, malicious websites, and fake customer-support communications.
The company notified affected customers by email on Aug. 16.
Customers do not need to move their cryptocurrency solely because their order information was exposed, the company added. However, anyone who has already entered a seed phrase or private key into a suspicious website or shared it with someone claiming to represent SafePal should consider that wallet compromised.
Those customers should create a new wallet using a trusted SafePal device or the company’s official application and transfer any remaining assets, SafePal advised.
SafePal Tightens Security After Incident
SafePal said it fixed the authorization flaw after discovering it and introduced additional security measures. It is also engaging an independent third-party security firm to validate the remediation and conduct a broader review of its order-processing systems.
The retention period for personal information in the affected order-processing environment to 90 days, subject to legal requirements, and opened a dedicated support channel for affected customers.
Logistics were already contacted, including fulfillment partners, to determine whether the exposure extended into their systems.
Meanwhile, SafePal said it has identified and taken down more than 30 fraudulent websites and phishing links associated with scam activity and is continuing to monitor for new malicious domains.
Affected customers should treat unexpected communications referencing a SafePal purchase as suspicious. SafePal stressed that it will never request a seed phrase, private key, or wallet password by phone, email, or other communication channels.
Additional updates will be published as its third-party security review and phishing-monitoring efforts continue.
Other News: AI security failures, actively exploited vulnerabilities, and major data breaches dominated the latest week of cybersecurity threats.





