SafePal Data Breach Exposes 40K Customer Records

SafePal’s data breach exposed order details of nearly 40K customers. Here’s what was accessed, what remained secure and how SafePal responded.

SafePal Data Breach Exposes 40K Customer Records
SafePal Data Breach Exposes 40K Customer Records

SafePal announced a security breach involving approximately 40,000 customers who placed orders between March 2, 2025, and April 11, 2026. The information that was disclosed included names, phone numbers, email addresses, shipping addresses, and transaction details. According to SafePal, seed phrases, private keys, wallet passwords, payment information, bank account details, and government IDs were all untouched. On the other hand, the disclosed information might enable highly targeted phishing and impersonation attempts.

SafePal Says 39,798 Customers Were Affected

An authorisation fault in an order-tracking feature linked to customer order data was identified as the cause of the event. The security flaw allowed unauthorised parties to view another customer's order data under specific circumstances.

SafePal stated that after identifying the problem, it added additional security measures and fixed it. Approximately 39,798 customers were impacted by the event, including those who placed orders within the designated time frame.

According to the company, each impacted customer received a personal email on August 16 from security@safepal.com with the subject line "[Important] Your SafePal Order Information Has Been Affected." Additionally, SafePal is requesting users to independently confirm if their data was impacted.

The event is comparable to the risks described in Trezor ShipMonk Data Breach Exposes Customer Data, where compromised customer data raised questions about targeted phishing rather than a straight compromise of wallet credentials.

Seed Phrases & Private Keys Remained Safe

The fact that wallet cash and credentials were not compromised is the most significant difference in the event.

According to SafePal, seed phrases, private keys, and wallet passwords weren't a factor in the incident. Payment card numbers, government-issued identification numbers, and bank account details were also kept private. According to the company, it doesn't ask for, gather, handle, or keep such data from clients.

SafePal has not discovered any proof that attackers were able to access consumer wallets or money due to the event itself. Customers whose order information was impacted do not, therefore, need to transfer their cryptocurrency assets as a result of this occurrence alone.

But if someone has previously disclosed their private key or seed phrase in response to a fake message, website, phone call, or letter, then things are different. SafePal recommends relocating the remaining assets immediately, treating that wallet as compromised, and setting up a new wallet using official SafePal software or a trusted SafePal device.

This distinction between wallet breach and customer-data exposure is also relevant to What the COLDCARD Exploit Really Means for Crypto, which looked at how security threats might go beyond the direct theft of wallet credentials.

Exposed Order Details Could Enable Targeted Scams

Scammers may be able to use publicly available information to make phishing attempts appear authentic. If attackers had access to a customer's name, contact details, delivery address, and purchase information, they might pretend to be SafePal and contact victims using real orders.

SafePal warned that affected consumers may get fake phone calls, emails, texts, physical letters, refund offers, demands for firmware updates, fake customer service correspondence, or links to malicious websites.

The company emphasised that, whether via phone, email, or any other form of communication, SafePal support will never request a password, private key, or seed phrase.

Additionally, consumers should refrain from scanning QR codes or opening links in unsolicited messages about SafePal. Reporting any questionable emails to the appropriate email provider is advised.

SafePal Takes Additional Steps After the Breach

According to SafePal, the authorisation issue has been resolved, and new security measures have been put in place. In order to verify the solution and carry out a more thorough examination of its order-processing systems, it is also hiring an impartial third-party security company.

Subject to applicable regulatory restrictions, the firm has shortened the retention time for personal information in the relevant order-processing environment to 90 days. It has contacted logistics and fulfilment partners to find out if the problem affected their systems, launched a special help channel for impacted clients, and alerted impacted users individually.

Additionally, SafePal has found and removed over thirty phishing links and fake websites linked to scam activity. In addition to gathering user reports and conducting an ongoing independent security review, monitoring and takedown actions are still underway.

SafePal advises manually entering safepal.com into a browser for extra security rather than clicking on links, even those found in warnings about breaches. The business cautioned that fake websites have tried to mimic its domain in the past by substituting an uppercase "I" for the lowercase "l."

In order to preserve their privacy, SafePal has advised users to use its designated reporting and support channels rather than contacting the company via social media.

If you find any issues in this article or notice missing information, please feel free to reach out at team@etherworld.co for clarifications or updates.

To promote your Web3 articles, events, and projects, you may reach out anytime via EtherWorld PR for submissions and collaboration.

Related Articles

  1. Harmony ONE Token Crashes After $4B Unauthorized Mint
  2. ZachXBT Exposes Alleged $5M Crypto Scam
  3. Crypto User Loses $100K to Address Poisoning Scam
  4. What the COLDCARD Exploit Means for Crypto?
  5. Carrot Shuts Down After Drift Exploit Fallout

To follow blockchain news, track Ethereum protocol progress, and read our latest stories, subscribe to our weekly today.

Join the EtherWorld & Avarch Internship Program and build your career in blockchain, content, social media, video, podcast editing, or operations. Send your resume and brief introduction to contact@etherworld.co.


Disclaimer: The information contained in this website is for general informational purposes only. The content provided on this website, including articles, blog posts, opinions, & analysis related to blockchain technology & cryptocurrencies, is not intended as financial or investment advice. The website & its content should not be relied upon for making financial decisions. Read full disclaimer & privacy policy.

To stay updated on blockchain news, Ethereum protocol progress, and our latest stories, subscribe to our weekly digest and YouTube channel for ELI5 content.

To promote your Web3 articles, events, project updates, and Press Releases, reach out anytime via EtherWorld PR for submissions and collaboration. For other queries, email contact@etherworld.co.

If you’d like to support our work, share the content and consider donating at avarch.eth.

Join our community on Discord and follow us on Twitter, Facebook, LinkedIn & Instagram.

Subscribe to join the discussion.

Please create an account to become a member and join the discussion.

Already have an account? Sign in

Sign up for EtherWorld.co newsletters.

Stay up to date with curated collection of our top stories.

Please check your inbox and confirm. Something went wrong. Please try again.
0/5 free articles read this week
Sign up free