Security

SafePal Data Breach Exposes Personal Info of Nearly 40,000 Customers

2 min read

Crypto wallet provider SafePal has disclosed a data breach affecting 39,798 customers. The incident exposed order and shipping information but did not touch private keys or crypto holdings. It comes days after a similar breach hit rival hardware wallet maker Trezor.

The company identified an authorization flaw in a plug-in used to track customer orders, according to a company announcement reported by The Block and CoinDesk. Attackers could likely view other customers’ orders by manipulating order numbers. SafePal likened the vulnerability to a parcel-tracking system letting one customer see another’s receipt.

Orders placed between March 2, 2025 and April 11, 2026 were exposed. Compromised data included customers’ names, physical addresses, and contact details. Private keys, seed phrases, crypto assets, bank details, and government identification documents were not affected, the company stated.

SafePal began notifying affected customers by email from [email protected] on Sunday, August 16. The vulnerability has been patched and additional security measures put in place. An independent third-party security firm has been retained to audit the fix and review the company’s order-processing systems. Going forward, SafePal said it will hold personal data in its order-processing system for only 90 days from the date of collection.

The company also identified and removed more than 30 fraudulent websites and phishing links tied to the breach. A verification tool on the SafePal website lets customers check whether their data was affected.

The disclosure follows a breach at Trezor earlier the same week. That incident exposed order information for roughly 13,689 customers via a fulfillment partner. Both breaches targeted order and shipping data, the off-chain logistics layer, rather than wallet security itself. No source has confirmed whether the two share an attacker, vendor, or tooling.

Some SafePal customers reported phishing attempts as early as July, before the breach was publicly disclosed, according to The Block. SafePal advised users who shared private keys or seed phrases via phishing email, phone call, or letter to treat their wallet as compromised and transfer assets to a new one.

The timing places SafePal’s breach alongside a string of incidents targeting crypto wallet vendors. Earlier in August, Coldcard hardware wallets were hit by a separate attack in which an attacker reportedly stole at least $120 million in bitcoin. That was a different vector involving direct theft rather than order data, as CoinDesk noted in framing the incidents together.

Whether the wave of attacks reflects a coordinated campaign or opportunistic targeting of a shared weakness in wallet vendors’ fulfillment systems is not yet known. SafePal has not named the third-party security firm conducting the audit. No source has confirmed any customer crypto losses resulting from phishing tied to the breach.

Avatar of Mara Velasquez

Mara Velasquez

Mara Velasquez covers markets and DeFi for NFT Signals, reporting on price action, liquidity and the listed companies with crypto on their balance sheets. She also tracks exploits and stolen-funds recovery.