started · updated
SafePal discloses data breach affecting nearly 40,000 customers
SafePal, a cryptocurrency wallet provider, has disclosed a data breach that exposed the personal information of approximately 39,798 customers. The incident was caused by an authorization flaw in an order-tracking plugin, which allowed unauthorized users to view order details belonging to other customers. The breach affected orders placed between March 2, 2025, and April 11, 2026.
Exposed data includes customer names, email addresses, shipping addresses, phone numbers, and purchase history. SafePal emphasized that core security credentials—including seed phrases, private keys, wallet passwords, bank account details, and payment card information—were not compromised. There is currently no evidence that user funds or actual wallets were directly accessed.
In response to the breach, SafePal has patched the vulnerability and implemented stricter access controls. The company has also taken down more than 30 fraudulent websites and phishing links associated with the incident. To mitigate future risks, SafePal announced a new policy to retain customer personal data in its order processing system for a maximum of 90 days. Users are warned to remain vigilant against targeted phishing and social engineering attempts that may use the leaked information to impersonate company support.
Entities
Binance · Binance Labs · Reuters · SafePal · Trezor
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 22 SOURCES] The unauthorized access occurred for orders placed between March 2, 2025, and April 11, 2026. wdez.com · jack1065.com · crypto.news · srnnews.com · wkzo.com · +17 more
- [● 22 SOURCES] SafePal disclosed a data breach involving unauthorized access to approximately 39,798 customers' order information. wdez.com · jack1065.com · crypto.news · srnnews.com · wkzo.com · +17 more
- [● 11 SOURCES] SafePal has identified and taken down more than 30 fraudulent websites and phishing links related to the breach. wdez.com · jack1065.com · crypto.news · srnnews.com · wkzo.com · +6 more
- [● 22 SOURCES] The breach was caused by an authorization flaw in an order-tracking plugin. wdez.com · jack1065.com · crypto.news · srnnews.com · wkzo.com · +17 more
- [● 11 SOURCES] The company will now retain customer personal data in its order processing system for only 90 days. wdez.com · jack1065.com · crypto.news · srnnews.com · wkzo.com · +6 more
- [● 22 SOURCES] Exposed data included names, email addresses, shipping addresses, phone numbers, and purchase details. wdez.com · jack1065.com · crypto.news · srnnews.com · wkzo.com · +17 more
- [● 22 SOURCES] Seed phrases, private keys, wallet passwords, and payment card information were not compromised. wdez.com · jack1065.com · crypto.news · srnnews.com · wkzo.com · +17 more