(Advertisement)

top ad mobile advertisement
news1h ago

Safepal Users Face Phishing Risk After Major Data Breach

SafePal has disclosed a data breach affecting 39,798 customers after an authorization flaw in its order-tracking plug-in exposed names, addresses, and contact details. Wallet funds and private keys were not compromised.

Safepal Users Face Phishing Risk After Major Data Breach

(Advertisement)

native ad1 mobile advertisement

Order-Tracking Flaw Exposed Nearly 40,000 Customers

Crypto hardware wallet provider SafePal has disclosed a security incident that put the personal data of nearly 40,000 customers at risk. SafePal identified an "authorization flaw" in a plug-in used to track customer orders, which likely allowed attackers to view other customers' order details. The vulnerability worked much like a parcel-tracking system that lets one customer see another's receipt and delivery information simply by changing the order number.

The breach affects customers who placed orders between March 2, 2025, and April 11, 2026, exposing their names, email addresses, shipping addresses, phone numbers, and purchase information. SafePal said it identified the root cause only recently, though customers had posted publicly online about being targeted by phishing attempts as early as May.

The company says the breach did not expose customers' wallet seed phrases, private keys, passwords, bank account information, payment card numbers, government-issued identification numbers, or other credentials. Customers whose order information was exposed do not need to replace their hardware wallets or move cryptocurrency because of the breach, according to SafePal. However, if a customer already shared their seed phrase or private key in response to a phishing email or text, they should treat their wallet as compromised and transfer any assets to a new wallet on a trusted SafePal device or official application.

SafePal Acts to Contain Fallout

The company notified all affected customers by email and hired an independent third-party security firm to audit the fix and review its order-processing systems. SafePal also confirmed it has identified and taken down more than 30 fraudulent websites and phishing links tied to the stolen data.

SafePal has launched an online verification tool that lets customers enter their order number and shipping country to determine whether the details of that order were stolen. Going forward, SafePal said it will retain customer personal data in its order-processing system for only 90 days from the date of collection.

SafePal warns customers to watch for targeted phishing emails and phone calls about firmware upgrades, product returns, refunds, or legal investigations. The incident is the latest customer-data breach involving a major hardware wallet brand, following Trezor's disclosure of a breach at ShipMonk, its shipping provider.

Sources:
BleepingComputer: SafePal data breach impacts 39,798 customers
CoinDesk: SafePal security vulnerability exposes data of 39,798 customers
The Block: Wallet provider SafePal says data breach exposed personal info of nearly 40,000 customers

Latest News

Read More...

Author

Soumen Datta profile photoSoumen Datta

Soumen has been a crypto researcher since 2020 and holds a master’s in Physics. His writing and research has been published by publications such as CryptoSlate and DailyCoin, as well as BSCN. His areas of focus include Bitcoin, DeFi, and high-potential altcoins like Ethereum, Solana, XRP, and Chainlink. He combines analytical depth with journalistic clarity to deliver insights for both newcomers and seasoned crypto readers.

Join our newsletter

Sign up for the very best tutorials and the latest Web3 news.

Subscribe Here!
BSCN

BSCN

BSCN RSS Feed

BSCN is your destination for all things crypto and blockchain. Discover the latest cryptocurrency news, market analysis, and research covering Bitcoin, Ethereum, altcoins, memecoins and everything in between.

Safepal Users Face Phishing Risk After Major Data Breach | BSCN Breaking News