Skip to content
live markets
S&P 5007,785.76▲ 3.21%NASDAQ26,729.16▲ 2.38%DOW53,732.41▲ 2.33%GOLD4,425.00▲ 11.02%WTI82.47▲ 4.46%BRENT88.80▲ 5.43%EUR/USD1.1578▲ 1.16%USD/JPY159.18▼ 1.97%DXY99.59▼ 1.13%BTC$62,823▼ 0.40%ETH$1,873▼ 0.50%SOL$74.49▼ 1.50%TOTAL CRYPTO$2.25T▼ 0.31%
pulseofnations.
UTC --:--NYC --:--LON --:--WAW --:-- telegram ↗ bluesky ↗ Join the wire

SafePal Discloses Data Breach Affecting Nearly 40,000 Customers

Crypto wallet provider SafePal revealed an authorization flaw exposed names, addresses and contact details of 39,798 customers who ordered between March 2025 and April 2026.

Partner Surfshark VPN

Crypto hardware wallet provider SafePal disclosed a security incident on Sunday that exposed personal information of nearly 40,000 customers, marking the latest in a string of breaches targeting crypto storage infrastructure.

The company said an “authorization flaw” in a plug-in used to track customer orders allowed unauthorized access to other customers’ order details. Affected users had placed orders between March 2, 2025, and April 11, 2026, and the exposed data included names, physical addresses, email addresses, phone numbers, and purchase details.

Crypto Assets Remain Unaffected

SafePal stressed that the breach did not compromise any cryptocurrency funds, seed phrases, private keys, bank account information, payment card numbers, or government-issued IDs. The company’s core wallet security infrastructure was not impacted. However, it warned that exposed users now face heightened phishing and impersonation risks.

The incident follows a recent hack of Coldcard hardware wallets, in which the attacker reportedly stole at least $120 million in bitcoin. While the two incidents are unrelated, they highlight that even hardware wallet providers, which are designed to offer offline key storage, are not immune to data security failures on the business and logistics side of their operations.

SafePal Response and Remediation

SafePal said it has patched the vulnerability and introduced additional security measures. The company notified all affected customers by email on Sunday and hired an independent third-party security firm to audit the fix and review its order-processing systems. SafePal also identified and removed more than 30 fraudulent websites and phishing links tied to the breach.

The company announced it would retain customer personal data in its order-processing system for only 90 days from the date of collection, down from whatever previous retention period was in place. A verification tool on SafePal’s website allows affected users to check whether their data was compromised.

The breach underscores a growing tension in the hardware wallet industry. Companies like SafePal and Coldcard sell devices designed to keep crypto assets offline and secure, but they still operate centralized e-commerce operations that collect personal data. That business-side data can be exploited for social engineering attacks even when the wallet’s cryptographic security remains intact.

Users who shared their private keys or seed phrases via a phishing email, phone call, or letter should treat their wallet as compromised and transfer assets to a new wallet immediately, SafePal cautioned. Customers who have not been contacted can verify their status through the company’s official security portal.

Sources: CoinDesk; The Block; Reuters

React to this dispatch
Share this dispatch Telegram X WhatsApp Report an error

discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Next dispatch Israel’s Largest Bank Partners With Galaxy for Crypto Read →