SafePal disclosed a security breach on Sunday that exposed the names, physical addresses, and contact details of 39,798 customers who placed orders between March 2, 2025 and April 11, 2026. The company traced the leak to an "authorization flaw" in an order-tracking plug-in that let attackers view other customers' order records by manipulating order numbers. SafePal stressed that private keys, seed phrases, bank passwords, payment card numbers, and government IDs were not compromised.
Why it matters
Even with on-chain assets untouched, the exposed PII gives attackers a clean targeting dataset for phishing, impersonation, and social-engineering attempts aimed at affected users. SafePal's own warning is blunt: anyone who has shared seed phrases or private keys via a phishing email, phone call, or letter should treat their wallet as compromised and rotate funds. The incident lands weeks after the reported $120 million Coldcard hardware-wallet theft, and the two together underline that wallet security spans both custody and the customer-data layer wrapped around it.
Market impact
The direct on-chain risk is contained, but the phishing tail is the real exposure. Expect targeted impersonation emails, fake "wallet recovery" calls, and cloned order-verification pages aimed at the 39,798 affected users through the rest of the year. Watch for copycat probes of other hardware-wallet vendors' order systems, and for any disclosure on whether the order-tracking plug-in was built in-house or by a third party. SafePal says it has patched the flaw, hired an independent auditor to review the fix, cut order-data retention to 90 days, and taken down more than 30 fraudulent sites tied to the breach.
Frequently asked questions
-
Was any cryptocurrency stolen in the SafePal breach?
No. SafePal says private keys, seed phrases, bank details, payment card numbers, and government IDs were not exposed. The leak was limited to names, physical addresses, and contact details pulled from the order system.
-
How did attackers access other customers' order data?
SafePal traced it to an "authorization flaw" in an order-tracking plug-in. Attackers could view other customers' order records simply by changing order numbers, because the plug-in failed to verify that the requester was the customer who placed the order.
-
How can I check whether my SafePal order data was exposed?
SafePal published a verification tool on its website that lets customers check whether their data was affected. The company also emailed affected users from [email protected] on Sunday.
-
What should affected users do next?
Treat any unsolicited email, call, or letter asking for seed phrases or private keys as phishing, and rotate funds to a new wallet if a seed phrase has ever been shared with anyone. SafePal warned that exposed users face elevated impersonation risk.
-
Does this mean hardware wallets are unsafe?
Not directly. The flaw was in SafePal's order-tracking plug-in, not in the wallet code itself. Combined with the reported $120 million Coldcard theft weeks earlier, it underscores that wallet security spans both custody and the customer-data layer wrapped around it.
CoinDesk