Security & Audits
Share
SafePal disclosed a data breach affecting 39,798 customers who placed orders between March 2, 2025, and April 11, 2026, exposing names, postal addresses, and contact details through a vulnerability in its order-tracking system, while funds, private keys, and recovery phrases remained unaffected.
Digital asset wallet provider SafePal has disclosed a security incident that exposed personal information belonging to nearly 40,000 customers, raising fresh concerns about the risks surrounding user data in the cryptocurrency ecosystem.
According to the company, the incident affected 39,798 customers who placed orders between March 2, 2025, and April 11, 2026.
The compromised information included customer names, postal addresses and contact details. SafePal said, however, that the incident did not compromise users' funds, passwords, private keys or recovery phrases.
The distinction is significant because the breach appears to have affected data surrounding SafePal's order-processing systems rather than the underlying security infrastructure protecting users' crypto wallets.
SafePal said it discovered a vulnerability in an extension used to track customer orders.
The flaw appears to have allowed an attacker to access information associated with other customers' orders by manipulating order-related data.
In practical terms, the vulnerability could be compared to a package-tracking system that allows someone to view another customer's information simply by changing an order number.
The company said it has since addressed the vulnerability and taken additional measures to prevent similar incidents.
The incident involved personal information connected to customer orders.
SafePal said the exposed information did not include recovery phrases, private keys, account passwords, banking information, payment-card numbers or government-issued identification documents.
The company also said there was no indication that the incident provided attackers with direct access to customers' cryptocurrency holdings.
That does not mean the leaked information is without risk.
Names, addresses and contact details can give attackers valuable information for constructing highly targeted phishing campaigns. A scammer who knows that someone purchased a SafePal product may be able to make a fraudulent email, phone call or message appear significantly more convincing.
The company has urged affected customers to remain particularly cautious about unsolicited communications claiming to come from SafePal.
Users should be suspicious of any message requesting a recovery phrase, private key or account credentials, regardless of how legitimate the communication appears.
SafePal specifically advised customers who may have disclosed their private keys or recovery phrases in response to fraudulent emails, calls or messages to treat those wallets as compromised and move their assets to a new wallet.
This distinction is important because legitimate wallet providers do not need users' recovery phrases or private keys to provide routine customer support.
Following the discovery, SafePal said it fixed the vulnerability and implemented additional security measures.
The company also brought in an independent security firm to conduct a broader review of its order-processing infrastructure and help address the underlying issue.
SafePal said it notified affected customers through its official security email address and introduced a new data-retention policy under which personal information in its order-processing system will be retained for only 90 days from collection.
The company has also identified and removed more than 30 fraudulent websites and phishing links associated with the incident.
SafePal has provided customers with a verification tool through its website that allows them to determine whether their information was affected.
For users who were impacted, the most immediate concern is likely to be follow-on fraud rather than direct theft of cryptocurrency.
Personal information can provide attackers with the context needed to impersonate a wallet provider, customer-service representative or other trusted party. Such attacks can ultimately be used to trick victims into voluntarily revealing the information that the original breach did not expose.
The SafePal incident highlights a broader issue in digital asset security: protecting cryptocurrency does not end with protecting private keys.
Hardware wallets and other self-custody products are designed to isolate sensitive cryptographic information from online threats. But companies operating around those products still handle customer information through websites, order systems, support platforms and other connected infrastructure.
Those systems can become attack vectors even when the wallets themselves remain secure.
The incident therefore underscores the importance of third-party risk management and customer-data protection alongside traditional wallet security.
For cryptocurrency users, the most important lesson from the SafePal incident may be that a data breach does not have to expose private keys to create serious security risks.
An attacker armed with a customer's name, address and knowledge that the person uses a particular wallet provider may have enough information to launch a targeted social-engineering campaign.
As digital asset ownership expands, security will increasingly depend not only on protecting blockchain transactions and private keys, but also on safeguarding the personal information surrounding those assets.
For SafePal, the incident serves as a reminder that the security perimeter extends well beyond the wallet itself. For users, it reinforces a fundamental rule of self-custody: never disclose a recovery phrase or private key, even to someone claiming to represent a trusted crypto company.
Disclaimer of Warranty
The information provided in this article is for general informational purposes only. We make no warranties about the completeness, reliability, and accuracy of this information. Read full disclaimer
Editor's Picks

Exclusive: Flipster GM Benjamin Grolimund Discusses Full VARA License and UAE Growth
Anna K.
Aug 4, 2026
4 min

Digital Euro: Europe’s Sovereignty Project Has a Demand Problem
Walid Abou Zaki
Jul 10, 2026
9 min

In Digital Finance, the Product Is the Regulation
Walid Abou Zaki
Jul 9, 2026
7 min
Read More Articles
In the Same Space

Cardano Sets Dijkstra Hard Fork Roadmap With Peras Finality Targeted for 2027
News Desk
Aug 17, 2026
4 min

Hong Kong’s First HKD Stablecoin Goes Live With Retail Access Restricted
News Desk
Aug 14, 2026
4 min

Tether KPMG Audit Raises the Bar for Stablecoins—and UAE
Walid Abou Zaki
Aug 14, 2026
9 min

Wall Street Moves Beyond Blockchain Tests With Live Tokenized Securities Trades
News Desk
Aug 14, 2026
5 min