
Crypto wallet SafePal has suffered a security breach that exposed the personal information of approximately 39,798 customers.
In a post on X, the crypto wallet said the affected customers were users who placed orders between March 2, 2025, and April 11, 2026. According to SafePal, the exposed information included names, email addresses, shipping addresses, phone numbers, and purchase details.
However, sensitive information such as seed phrases, private keys, wallet passwords, other wallet credentials, bank account information, payment card numbers, and government issued identification numbers were not exposed.
Detailing the incident in a blog post, SafePal said the breach was caused by an authorization flaw in the order tracking function of one of its plug-ins associated with customer order information. The flaw made it possible for unauthorized parties to access customers' information. After detecting the flaw, SafePal said it promptly fixed the issue and introduced additional security measures.
SafePal has warned affected customers to remain vigilant, as their exposed personal information could potentially be used in sophisticated phishing campaigns. According to the company, these campaigns may take several forms, including fraudulent phone calls, emails, text messages, letters, refund offers, firmware update requests, and fake customer support communications, all intended to obtain customers' wallet credentials or additional personal information.
As part of its remediation efforts, SafePal said it had fixed the flaw and implemented additional security measures. It also engaged an independent third party security firm to verify that the flaw had been fixed and conduct a broader security assessment of its systems.
It said it had also opened a dedicated support channel to respond to affected customers. The crypto wallet company also claimed it had taken down more than 30 websites and phishing links reportedly linked to the scam.