Follow

Keep Up to Date with the Most Important News

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use
Subscribe

SafePal Data Breach Puts Nearly 40,000 Customers at Phishing Risk

SafePal data breach SafePal data breach

The SafePal data breach disclosed on 16 August exposed order records belonging to approximately 39,798 customers, with the company confirming the root cause was an authorisation flaw in a third-party order-tracking plugin.

What the SafePal Data Breach Actually Exposed

The compromised records covered orders placed between 2 March 2025 and 11 April 2026. Each record could include a customer’s name, email address, shipping address, phone number, and purchase details.

What was not in scope: seed phrases, private keys, wallet passwords, payment card numbers, bank account details, and government-issued identification numbers. SafePal’s scam-protection page confirms the company does not collect or store those categories from customers, so they were never at risk of exposure here.

SafePal says it found no evidence the incident gave anyone direct access to wallets or on-chain funds. The company notified affected users individually on 16 August by email from security@safepal.com, with the subject line ‘[Important] Your SafePal Order Information Has Been Affected,’ and launched a self-serve verification tool allowing customers to check whether their order was caught in the window.

The plugin flaw worked by allowing, under certain conditions, one customer to pull another customer’s order data without authorisation. SafePal patched the vulnerability and added further access controls after confirming it during a full security review in July.

How a Configuration Error Extended the Exposure Window

The affected date range stretches further back than it might have, due to a second, separate failure. A scheduled data-cleanup process stopped working correctly between September 2025 and April 2026 because of a configuration error.

According to SafePal, that process failure did not cause the unauthorised access, but it left older records stored longer than intended, widening the pool of exposed data. As Reuters reported, SafePal has since cut personal-data retention in its order-processing environment to 90 days, subject to legal requirements. Affected customers’ data has been removed from active e-commerce servers; an encrypted offline copy is being kept to support any potential investigations.

Phishing Is the Live Risk Now

The dataset that leaked is a phishing kit. Real names, home addresses, and hardware wallet purchase history give attackers everything they need to write convincing pretexts.

The threat is already materialising. According to The Hacker News, a threat actor advertised a dataset on a cybercrime forum citing exactly the same order window and customer count, and offered to let prospective buyers verify records against SafePal’s own verification tool using order IDs and shipping countries. DarkWebInformer surfaced that listing on 16 August.

Infosecurity Magazine reports that SafePal warned customers to watch for fraudulent phone calls, emails, text messages, letters, refund offers, firmware-update requests, and fake customer-support communications, all designed to extract wallet credentials or additional personal data.

SafePal has already taken down more than 30 phishing websites and fraudulent links and is continuing to monitor for new domains. The playbook mirrors what happened after a third-party shipping breach exposed personal information belonging to 13,689 Trezor customers, including names, emails, phone numbers, and shipping addresses, and the subsequent wave of fake Trezor and Ledger letters mailed to customers with QR codes designed to harvest recovery phrases.

SafePal founded in 2018 and backed by Binance, Animoca Brands, and others per its company profile, stresses it will never ask customers for seed phrases, private keys, or passwords. Customers who have already entered credentials into a suspicious site should treat that wallet as compromised, generate a new wallet, and transfer remaining assets immediately.

An independent third-party security firm has been engaged to validate the fix and conduct a broader review of SafePal’s order-processing systems. That firm has not been named publicly. SafePal is also in contact with on-chain asset-tracing specialists for customers reporting financial losses, though it has cautioned that engagement ‘does not represent any admission of liability or commitment to compensation.’

The key near-term signal to watch is whether fresh phishing domains continue to emerge after SafePal’s initial takedown wave, and whether the unnamed security firm’s review surfaces additional plugin vulnerabilities in the same order-processing pipeline.

Keep Up to Date with the Most Important News

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use