Cryptocurrency hardware wallet maker SafePal is notifying approximately 40,000 customers that their personal information was stolen in a data breach caused by a vulnerability in a third-party plugin.
The company disclosed on August 17 that attackers exploited a flaw in the order-tracking function of a customer information plugin to access data belonging to users who placed orders between March 2, 2025, and April 11, 2026. The compromised information includes names, email addresses, phone numbers, physical addresses, and order details.
SafePal confirmed that roughly 39,798 individuals were affected. The disclosure came the same day a threat actor began advertising the stolen data on a cybercrime forum, claiming the same number of victims.
No Wallet Credentials Compromised
The company emphasized that the breach did not expose seed phrases, private keys, wallet passwords, bank account information, payment card numbers, or government-issued identification. SafePal urged affected customers to remain alert for phishing attempts requesting sensitive wallet information.
If you have already shared or entered your seed phrase or private key in response to a suspicious message, website, phone call, or letter, treat that wallet as compromised.
SafePal said it received the initial report in May but initially treated it as an isolated case. A subsequent investigation revealed that a system bug had caused order-related data to be retained far longer than intended.
Response and Remediation
The company says it has patched the exploited vulnerability, shortened the data retention period, notified all impacted users, and engaged a third-party security firm. SafePal has also identified and taken down over 30 fraudulent websites and phishing links tied to the breach.
The SafePal incident adds to a string of breaches affecting cryptocurrency platforms, joining recent compromises at Trezor fulfillment partner ShipMonk and other crypto-adjacent services.
Sources: SecurityWeek; SafePal blog; Dark Web Informer
discussion