Loading prices…
🩸BEARISH

SafePal data breach exposes 39,798 customers’ personal data

The exposure is the third wallet-industry customer-data incident in months, all routed through commerce or shipping vendors rather than the wallets themselves, putting the spotlight on the…

Crypto hardware wallet provider SafePal disclosed Sunday that an authorization flaw in its order-tracking system exposed the personal data of approximately 39,798 customers. Leaked information includes customer names, email addresses, shipping addresses, phone numbers, and purchase details tied to orders placed between March 2, 2025 and April 11, 2026.

SafePal stressed that no seed phrases, private keys, wallet passwords, bank account information, payment card numbers, or government-issued IDs were compromised, and that there is no evidence of unauthorized access to SafePal wallets or funds.

Why it matters

This is the third wallet-industry customer-data incident in months, and every one was routed through a commerce or shipping stack rather than the wallets themselves. SafePal's disclosure came days after The Block reported a ShipMonk breach exposed nearly 14,000 Trezor customer records. Ledger disclosed a similar exposure via its commerce vendor Global-e in January. The pattern points to a structural weakness in the third-party ordering infrastructure that every hardware-wallet vendor relies on, not in the cryptographic design of the wallets themselves.

Market impact

Customers face elevated phishing risk in the days ahead. SafePal warned attackers may pose as staff to offer fake firmware updates, refunds, or replacement devices before attempting to extract seed phrases, and the company has taken down more than 30 fraudulent sites linked to the scam. Public complaints on Trustpilot and Reddit from early July describe scammers already contacting users with full purchase records, weeks before Sunday's disclosure. Investors tracking SafePal's SFP token will weigh reputational drag against the fact that on-device funds were never touched. SafePal has not disclosed when the authorization flaw was introduced or how many attackers accessed the records.

Related tokens
$SFP

Frequently asked questions

  1. How many SafePal customers were affected by the breach?

    Approximately 39,798 customers had their personal data exposed, according to SafePal's incident report.

  2. Were SafePal wallet seed phrases or private keys compromised?

    No. SafePal said no seed phrases, private keys, wallet passwords, bank account information, payment card numbers, or government IDs were exposed.

  3. What customer information was exposed in the SafePal breach?

    The leaked records include names, email addresses, shipping addresses, phone numbers, and purchase details for orders placed between March 2, 2025 and April 11, 2026.

  4. How are attackers using the exposed SafePal data?

    SafePal warned that scammers are impersonating company staff to offer fake firmware updates, refunds, or replacement devices, then attempting to extract wallet credentials from affected users.

  5. Is the SafePal breach connected to the Trezor and Ledger disclosures?

    Each incident was separate and routed through a different third-party commerce or shipping vendor, but all three followed the same pattern of customer-data exposure without wallet compromise.

Source attribution
Aggregated from TheBlock · Verified · Last refreshed 1h ago
Open original →