-
SafePal says an order-tracking flaw exposed information linked to the orders of thousands of customers over 12 months.
-
The attack didn’t expose any seed phrases, private keys, wallet passwords, payment data, and crypto funds, according to SafePal.
-
The leaked data could expose users to targeted phishing because criminals can use real order details to make fake l messages look like they’re truly from SafePa.
SafePal, a popular crypto wallet maker, has officially confirmed a security breach that exposed records of orders belonging to nearly 40,000 customers. According to the company, the breach affected SafePal customers who placed orders between March 2, 2025 and April 11, 2026.
The company said the issue was due to a vulnerability in a plug-in used for tracking customer orders. There were instances in which the vulnerability enabled unauthorized access to the order information of another customer.
On the positive side, the company said they’ve patched the vulnerability after identification and also deployed additional security measures. Also, SafePal hired an independent security firm to look into the fix and examine its other order processing systems.
This breach compromised sensitive customer info including names, emails, shipping addresses, phone numbers as well as purchase information. SafePal sent out notifications to affected customers via email on August 16.
The Breach Didn’t Affect Wallet Keys and Funds
SafePal clarified that the hack only targeted their order tracking system. They found no proof suggesting that hackers accessed any SafePal wallets or customers’ money. Seed phrases, private keys, passwords of SafePal wallets, bank account details, credit card numbers, and government identities are also safe.
This means that users don’t have to change their SafePal devices or transfer their cryptocurrencies due to the exposure of their order details.
However, SafePal warned that the leaked information could still create serious risks. A criminal who knows someone’s name, address, phone number, email address, and SafePal purchase details has a strong starting point for a convincing scam.
Phishing is the Biggest Concern
SafePal warned that criminals could use the information to craft fake support emails, fraudulent phone calls (vishing), text messages, or letters. They could even make refund offers, delivery notices, or bogus firmware warnings to steal from users.
For instance, a scammer could call a customer, claiming their device has a security problem. The message could then ask the victim to install an update or enter wallet details.
Because the attacker may already know what device the person bought, the scam can appear genuine. SafePal said it has already taken down more than 30 fraudulent websites and phishing links connected to the incident.
The SafePal breach is part of a larger pattern of customer data appearing on dark web forums. In April 2026, a threat actor listed a database of approximately 728,000 customer records from suzhouyou.com, a Chinese website, with the data allegedly including contact details, support tickets, and order records that could similarly fuel phishing and fraud on a massive scale.
The company has also warned about lookalike websites. Some reportedly replace the lowercase “l” in the SafePal name with an uppercase “I,” making fake addresses harder to spot.
SafePal has a long history of warning users about impersonation scams. Its security guidance says its staff will not ask users for seed phrases or private keys.
SafePal is Cutting Data Retention
The company said it has shortened the time it keeps sensitive order information. Under the new policy, the order processing environment will only store personal data for 90 days, subject to legal requirements. SafePal said the incident may have also affected some records in a secure offline backup. The company said this is for possible investigations.
The change marks a shift from SafePal’s earlier approach. The company previously said it can store hardware-wallet order information for six months to support returns and after-sales service.
Customers Should Verify Messages Themselves
SafePal says affected customers can check their status through its official website. Users should avoid using links from unexpected emails, texts, or phone calls. Instead, they should type safepal.com into their browser and access support from there.
A vital notification for all SafePal customers. Never scan any unexpected QR codes. Also, SafePal said none of its legitimate employees will contact a customer via any channel whatsoever asking for a seed phrase, a private key, wallet password, or related personal info. The company encouraged anyone who reveals any of these details on a random site to take immediate action to avoid losing their funds.
SafePal says those wallets should be treated as compromised. Users should create a new wallet using a legit SafePal device or official app and immediately move their remaining assets to the new wallet. The breach does not appear to have directly put customer cryptocurrency at risk. But it shows why order data can be valuable to criminals.
For hardware-wallet users, knowing who bought a device and where they shipped the device can be enough to build a highly believable attack. SafePal’s response now centers on fixing the flaw, reducing stored data, and warning customers before scammers can turn that information into stolen funds.