HackMyIP
← Back to News
2026-08-17 SecurityWeek

SafePal Data Breach Exposes 40,000 Crypto Wallet Customers

Data BreachPrivacyIncident Response

Crypto hardware wallet provider SafePal is notifying approximately 39,798 individuals that their personal information was stolen in a data breach disclosed on Sunday. According to the company, threat actors exploited a vulnerability in the order-tracking function of a customer order information plugin, gaining access to names, postal addresses, email addresses, phone numbers, and order details belonging to customers who placed orders between March 2, 2025, and April 11, 2026. The disclosure coincided with a threat actor advertising the stolen SafePal dataset on a cybercrime forum, matching the company's stated victim count. Affected users can verify their exposure using an email breach checker to determine whether their address appeared in the leaked dataset.

The breach stemmed from a bug in SafePal's order-processing system that caused order-related data to be retained far longer than intended. SafePal began looking into the matter after receiving an initial report in May and treated it as an isolated case before launching a full review and rebuild of its order-processing pipeline in July, which confirmed the root cause. Importantly, the company stresses that no seed phrases, private keys, wallet passwords, bank account details, payment card numbers, or government-issued identification numbers were involved in the incident. Even so, exposed email addresses and phone numbers leave victims vulnerable to targeted phishing and social engineering campaigns designed to extract wallet credentials.

SafePal says it has patched the exploited vulnerability, shortened data retention periods for order-related information, notified impacted individuals, engaged partners to ensure the issue did not propagate, and retained a third-party security firm for forensic investigation. The company also reports taking down more than 30 fraudulent websites and phishing links tied to the scam activity, with continued monitoring for new infrastructure. Users who may have inadvertently entered a seed phrase or private key on a suspicious site are urged to treat that wallet as compromised and migrate assets to a freshly created wallet on a trusted device.

As crypto-related breaches increasingly target customer data rather than on-chain assets, hardening personal attack surfaces becomes critical. Wallet holders should run a privacy checkup on their devices and browsers, rotate credentials associated with exposed email addresses, and enable phishing-resistant authentication wherever possible. Anyone experiencing financial loss linked to this incident is encouraged to contact SafePal directly, as the company has engaged on-chain asset-tracing specialists to support recovery efforts.

Source: SecurityWeek →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →