What to Know

  • SafePal disclosed a security breach affecting 39,798 customers who placed orders between March 2, 2025, and April 11, 2026.
  • The exposed information included names, physical addresses and contact details linked to customer orders.
  • SafePal said cryptocurrency funds, seed phrases, private keys, bank passwords, bank account information, payment card numbers and government-issued IDs were not compromised.
  • The company identified an authorization flaw in a plug-in used to track customer orders.
  • SafePal said the flaw likely allowed attackers to view other customers’ orders.
  • Affected customers face increased risk of phishing and impersonation attempts, even though wallet security was not breached.
  • SafePal said it patched the vulnerability, added security measures and hired an independent third-party security firm to audit the fix and review its order-processing systems.
  • The company notified affected customers by email from security@safepal.com on Sunday.
  • SafePal said it identified and removed more than 30 fraudulent websites and phishing links associated with the breach.
  • Customers can use a verification tool on SafePal’s website to check whether their data was affected.

SafePal Discloses Customer Data Exposure

SafePal, a crypto security company known for hardware wallets and software applications, has confirmed a data breach that exposed personal order information belonging to 39,798 customers. The incident affected customers who placed orders between March 2, 2025, and April 11, 2026, and involved data tied to the company’s order-processing and tracking environment rather than the cryptographic infrastructure that protects user wallets.

The information exposed in the incident included customer names, physical addresses and contact details. SafePal said the breach did not affect cryptocurrency funds, seed phrases, private keys, passwords, bank details, payment card numbers or government-issued identification. That distinction is critical for wallet users because order data exposure creates privacy and social-engineering risks, while compromise of seed phrases or private keys can directly endanger crypto assets.

For customers, the central concern now shifts from on-chain theft to off-chain targeting. A person in possession of a customer’s name, delivery address and contact information may attempt to impersonate SafePal, a courier, a support representative or another trusted party. In crypto, where irreversible transactions and self-custody remain defining features, phishing attempts can become especially dangerous if attackers convince users to disclose a seed phrase or private key.

What SafePal Says Happened

SafePal said it identified an authorization flaw in a plug-in used to track customer orders. In practical terms, the flaw likely enabled attackers to view other customers’ orders. A simple way to understand the issue is to compare it with a parcel-tracking system that incorrectly allows one customer to view another customer’s receipt and delivery information by altering an order reference. The company framed the incident as an order-information exposure rather than a breach of wallet cryptography.

The affected order window ran from March 2, 2025, to April 11, 2026. SafePal said customers whose information was affected were notified by email from security@safepal.com on Sunday. While the company’s notice emphasized that core wallet protections remained intact, it also warned that exposed users should be alert to heightened phishing and impersonation risks.

SafePal’s disclosure is likely to draw attention across the self-custody market because hardware wallets are often marketed as a safer alternative to keeping assets on centralized platforms. The incident does not show that SafePal wallet keys were exposed, and the company said sensitive wallet and financial credentials were not affected. Still, it highlights a recurring security issue for crypto firms: even when wallet architecture is secure, customer databases, logistics systems, plug-ins and third-party operational tools can become weak points.

Private Keys and Funds Were Not Compromised

SafePal stressed that user funds remained safe and that seed phrases and private keys were not compromised. In self-custody, the seed phrase and private key are the most sensitive elements of wallet security. Anyone who obtains them can typically move assets without needing customer support approval, bank authorization or a password reset. Because blockchain transactions are generally final, recovering assets after a successful seed phrase theft can be extremely difficult.

That is why SafePal’s warning about phishing is important. The company said users who have shared private keys or seed phrases through a phishing email, phone call or letter should treat the wallet as compromised and transfer assets to a new wallet. This guidance reflects a basic rule of crypto security: a seed phrase should never be typed into an unverified website, read to a caller, shared by message or sent in response to an email. A legitimate wallet provider should not need a user’s seed phrase to provide support.

Even though the breach did not include seed phrases, attackers may try to use the exposed contact data to create convincing messages. For example, an attacker could reference a real order, delivery information or a customer’s name to build trust. That kind of personalization can make phishing attempts harder to spot, especially for users who are already concerned after learning that their order information may have been exposed.

Company Response and Security Measures

SafePal said it patched the vulnerability and introduced additional security measures after identifying the issue. The company also hired an independent third-party security firm to audit the fix and review its order-processing systems. External review can be an important step after a security incident because it gives a company an opportunity to test whether the immediate patch worked and whether related systems carry similar weaknesses.

The company also said it would retain customer personal data in its order-processing system for only 90 days from the date of collection. Reducing data retention can limit future exposure because information that is no longer stored cannot be taken in a later incident. For hardware wallet providers, that approach may become increasingly important because order records can reveal that a person purchased a crypto storage device, making the customer a more attractive target for scams or impersonation.

SafePal further said it identified and removed more than 30 fraudulent websites and phishing links associated with the breach. The removal of fraudulent sites is an important containment measure, but users should still assume that new phishing pages and messages may appear. In crypto-related incidents, attackers often move quickly to exploit public concern, sometimes creating fake support portals or urgent security warnings designed to push users into revealing sensitive wallet information.

Why Order Data Matters in Crypto Security

Order data may appear less sensitive than seed phrases or private keys, but it can still carry meaningful security implications. A physical address can expose a customer’s location. A contact detail can become a channel for repeated phishing attempts. A name attached to a crypto hardware wallet purchase may indicate that the person holds or intends to hold digital assets. In combination, these details can support impersonation, harassment, fraud or targeted social-engineering attempts.

For self-custody users, operational privacy is part of security. A hardware wallet can protect private keys from online compromise, but it cannot prevent someone from receiving a fake message, visiting a fraudulent website or disclosing recovery information under pressure. This is why crypto security depends on both technical safeguards and user habits. Devices, apps, order systems, email practices and customer support workflows all sit within the broader risk environment.

The SafePal incident also arrives in a market environment where scrutiny of wallet security remains high. A recent hack of Coldcard hardware wallets reportedly involved at least $120 million in bitcoin being stolen. The SafePal incident is different because the company said wallet funds and private keys were not affected. However, both cases reinforce a broader lesson recognized by many security-minded market participants: no storage method eliminates every risk, and users should evaluate how they manage custody, privacy, backups and exposure to phishing.

What Affected Customers Should Watch For

Customers who may have been affected should be skeptical of unsolicited messages that reference SafePal, wallet security, delivery details or urgent account action. Attackers may attempt to create pressure by claiming that funds are at risk or that a device must be verified immediately. The goal of such messages is often to make a user reveal a seed phrase, enter a private key into a fake form or install malicious software.

SafePal said customers can use a verification tool on its website to check whether their data was affected. Users should navigate carefully and avoid using links sent through suspicious emails, text messages or social media posts. Because fraudulent websites and phishing links have already been associated with the breach, customers should be especially cautious about lookalike pages or messages that use familiar branding.

Anyone who believes they disclosed a seed phrase or private key in response to a suspicious message should treat the wallet as compromised, in line with SafePal’s warning, and transfer assets to a new wallet. Users who did not share seed phrases or private keys should still remain alert, because phishing attempts may continue after the initial notification period. The safest posture is to assume that any request for recovery words is malicious.

Broader Implications for Hardware Wallet Users

The incident underscores that hardware wallets are one layer of protection, not a complete security system by themselves. They are designed to keep private keys isolated from internet-connected environments, but the companies that sell them still rely on websites, plug-ins, order-management systems, email infrastructure and customer-service processes. A weakness in any of those areas can create risk even when the wallet’s cryptographic design remains intact.

Some chart watchers and security-focused market participants may view the incident as another reminder to avoid excessive reliance on a single provider or single storage method. Diversifying wallets and custody arrangements can reduce concentration risk, though it can also add complexity. For many users, the most practical starting point is simpler: keep seed phrases offline, verify communications carefully, limit personal data exposure where possible and never disclose recovery information to anyone.

SafePal’s disclosure gives customers important clarity on what was and was not affected. The exposed data relates to order information, while the company says funds, wallet keys and sensitive financial identifiers remain safe. The ongoing risk is therefore less about immediate wallet compromise and more about how exposed personal information could be used in future phishing and impersonation campaigns.

Frequently Asked Questions (FAQs)

What happened in the SafePal breach?

SafePal disclosed a security incident involving an authorization flaw in a plug-in used to track customer orders. The flaw likely allowed attackers to view other customers’ order information, including names, physical addresses and contact details.

How many customers were affected?

SafePal said the breach affected 39,798 customers who placed orders between March 2, 2025, and April 11, 2026.

Were crypto funds stolen in the SafePal breach?

SafePal said no cryptocurrency funds were compromised. The company also said seed phrases, private keys, passwords, bank account information, payment card numbers and government-issued IDs were not affected.

What information was exposed?

The exposed information included names, physical addresses and contact details connected to customer orders. This type of data can increase the risk of phishing and impersonation attempts.

Why is phishing a concern after this breach?

Attackers may use exposed order details to create convincing emails, phone calls, letters or fake websites. The main danger is that a customer could be tricked into sharing a seed phrase or private key.

What should users do if they shared a seed phrase or private key?

SafePal said users who shared private keys or seed phrases through a phishing email, phone call or letter should treat the wallet as compromised and transfer their assets to a new wallet.

How did SafePal respond to the incident?

SafePal said it patched the vulnerability, added security measures, hired an independent third-party security firm to audit the fix and review its order-processing systems, and notified affected customers by email from security@safepal.com on Sunday.

Did SafePal remove phishing sites linked to the breach?

SafePal said it identified and removed more than 30 fraudulent websites and phishing links associated with the breach.

Can customers check whether they were affected?

SafePal said customers can use a verification tool on its website to check whether their data was affected, while remaining cautious of suspicious links and lookalike pages.

Photo by DS stories on Pexels