TLDR
- SafePal disclosed a data breach affecting about 39,798 customers after an authorization flaw exposed order records.
- The leaked information included names, emails, phone numbers, shipping addresses, and purchase details.
- SafePal said seed phrases, private keys, wallet passwords, payment details, and customer funds were not compromised.
- The company warned affected users about phishing and impersonation scams involving fake refunds, firmware updates, and replacement devices.
- SafePal said it has removed more than 30 fraudulent websites and phishing links linked to the scam campaign.
Crypto wallet provider SafePal disclosed a data breach that exposed order information linked to about 39,798 customers. The company said an authorization flaw in its order-tracking system allowed unauthorized access to customer records.
Dear community,
While your SafePal wallet, seed phrase, and private keys are secure; we identified a flaw in the order-tracking plug-in that led to unauthorized access to information of a subset of customers.
The issue has been fixed with additional security measures…
— SafePal – Crypto Wallet (@SafePal) August 16, 2026
The exposed data included names, email addresses, shipping addresses, phone numbers, and purchase details. Customers placed the affected orders between March 2, 2025, and April 11, 2026.
SafePal Says Wallet Credentials Stayed Secure
SafePal said the incident did not expose seed phrases, private keys, wallet passwords, payment card numbers, bank details, or government identification numbers. The company also said it found no evidence that attackers gained access to customer wallets or funds.
The firm warned affected customers about possible phishing attempts. Attackers may pose as SafePal staff and offer firmware updates, refunds, or replacement devices while trying to collect wallet credentials. SafePal advised customers to stay cautious of messages requesting sensitive wallet information or unexpected actions.
SafePal said it received the first report linked to the breach in early May but treated it as an isolated case. The company later expanded its review and began rebuilding its order-processing pipeline in July.
Public reports appeared before the company’s Sunday disclosure. A July 4 Trustpilot review described scammers using detailed customer information, while a July 3 Reddit post reported a similar approach involving a fake SafePal support website.
More Than 30 Phishing Sites Removed
SafePal said it has identified and removed more than 30 fraudulent websites and phishing links connected to the scam. The company did not say whether any customers lost funds, but it asked users who reported losses to submit details through its support channel.
The company has not disclosed when the flaw first appeared, when attackers first accessed records, or how many people obtained the data. It also said investigations carried out earlier did not detect a breach at the time.
The SafePal incident follows recent customer-data exposures linked to commerce systems used by other hardware wallet companies. Trezor said its shipping partner ShipMonk exposed information belonging to nearly 14,000 customers.
Ledger also notified some customers in January that a third-party commerce provider exposed names and contact details. In each case, the wallet providers said private keys and wallet access remained secure.







