Crypto hardware wallet provider SafePal has confirmed a significant data breach affecting nearly 40,000 users after hackers exploited a vulnerability in an order-tracking plugin. While wallet keys remain secure, personal details have been leaked onto cybercrime forums.
- Approximately 39,798 SafePal customers had their personal data stolen.
- The breach occurred via a vulnerability in a third-party order-tracking plugin.
- Seed phrases, private keys, and wallet passwords were NOT compromised.
- Affected data includes names, addresses, emails, phone numbers, and order history.
The cryptocurrency hardware wallet giant SafePal has issued a formal notification to its community regarding a sophisticated data breach that has compromised the personal information of roughly 40,000 individuals. The breach was triggered by a vulnerability within the order-tracking function of a customer order information plugin, allowing unauthorized actors to scrape sensitive user data.
According to official statements, the breach specifically impacted customers who placed orders between March 2, 2025, and April 11, 2026. The stolen dataset includes names, physical addresses, email addresses, phone numbers, and specific order details. The company disclosed the incident on a Sunday, coinciding with the appearance of the stolen data on a known cybercrime forum where a threat actor began advertising the leak.
BozokMedia analysis shows that while the core cryptographic security of the wallets remains intact, this breach creates a massive surface for targeted phishing attacks. When hackers possess a user's full name, phone number, and exact purchase history, they can craft highly convincing "social engineering" scams that trick users into revealing their seed phrases.
The danger in crypto breaches isn't always the loss of funds through a hack, but the loss of identity that leads users to voluntarily hand over their keys to a sophisticated imposter.
SafePal has clarified that the breach did not extend to seed phrases, private keys, bank account details, or government IDs. However, the company admitted that an internal investigation started in May was initially treated as an isolated case. It was later discovered that a system bug caused order-related data to be stored far longer than the intended retention period, providing a larger window for attackers.
In response, SafePal has completely rebuilt its order-processing pipeline and tightened data retention policies. The company has also taken down over 30 fraudulent phishing websites linked to this specific breach and has engaged a third-party security firm to conduct a forensic audit of their systems.
| Compromised Data | Secure Data (Not Leaked) |
|---|---|
| Full Names & Addresses | Seed Phrases / Private Keys |
| Email & Phone Numbers | Wallet Passwords |
| Order History | Bank Account/Card Numbers |
Q1: Is my cryptocurrency still safe in my SafePal wallet?
Yes, because seed phrases and private keys were not stored on the compromised server. However, you must be extremely cautious of phishing emails or calls.
Q2: What should I do if I shared my seed phrase after receiving a suspicious message?
SafePal advises treating that wallet as compromised immediately. You should create a new wallet on a trusted device and move all remaining assets to the new address instantly.