Key Takeaways
- SafePal revealed an authorization vulnerability in its order-tracking platform that exposed records belonging to approximately 39,798 customers.
- Compromised data consisted of customer names, email addresses, contact numbers, delivery addresses, and transaction records.
- The company confirmed that recovery phrases, private keys, wallet access codes, financial credentials, and user funds remained unaffected.
- Affected customers received warnings about potential phishing schemes featuring fraudulent refund offers, fake firmware updates, and counterfeit device replacements.
- The company successfully identified and eliminated over 30 malicious websites and phishing attempts connected to this security incident.
Cryptocurrency wallet company SafePal disclosed a data breach that revealed purchase information associated with approximately 39,798 users. According to the company, a security weakness in its order-tracking infrastructure permitted unauthorized parties to access customer information.
The compromised information encompassed full names, contact email addresses, delivery locations, telephone numbers, and order histories. The affected purchases occurred during the period spanning March 2, 2025, through April 11, 2026.
Wallet Security Credentials Remained Uncompromised
SafePal confirmed the breach did not affect recovery phrases, private cryptographic keys, wallet authentication passwords, credit card information, banking credentials, or identity documents. The organization additionally stated that investigators found no indication of unauthorized wallet access or theft of digital assets.
The company issued alerts to impacted users regarding heightened phishing risks. Malicious actors may impersonate SafePal representatives while presenting fraudulent firmware upgrades, monetary refunds, or hardware replacements in attempts to harvest wallet authentication details. SafePal recommended customers exercise vigilance when receiving communications requesting confidential wallet data or unusual operations.
SafePal indicated it initially received incident-related reports during early May, treating the matter as an individual occurrence. Following further investigation, the organization broadened its security assessment and commenced reconstruction of its order-management infrastructure in July.
Public accounts surfaced ahead of the company’s Sunday announcement. A Trustpilot review dated July 4 detailed scammers leveraging precise customer data, while a July 3 Reddit submission described comparable tactics featuring a counterfeit SafePal assistance portal.
Company Eliminates Over 30 Fraudulent Web Properties
SafePal reported discovering and dismantling more than 30 deceptive websites and malicious links associated with the campaign. The organization did not confirm whether customers experienced financial losses, though it invited affected individuals who sustained damages to provide information via its assistance platform.
The company has not revealed when the vulnerability initially emerged, the timeline of unauthorized access, or the number of individuals who obtained the exposed records. Officials additionally noted that previous security assessments failed to identify the breach during their execution.
This SafePal security event arrives following similar customer information exposures involving e-commerce platforms utilized by competing hardware wallet manufacturers. Trezor reported that its logistics partner ShipMonk leaked data belonging to approximately 14,000 users.
Ledger similarly informed certain customers in January that a third-party commerce platform exposed names alongside contact information. Across these incidents, wallet manufacturers maintained that cryptographic keys and wallet authorization remained fully secured.





