SafePal says order-data breach exposed records of 39,798 customers
The wallet maker says names, contact details and purchase information were accessed, but seed phrases, private keys, passwords and funds were not compromised.
By The Third AnglePublished 3 min read
Illustrative data-center imagery for SafePal's customer-information breach; the image does not depict SafePal's systems. Photo: Unsplash · Unsplash License
SafePal says a flaw in an order-tracking plug-in exposed personal information belonging to about 39,798 customers. The wallet maker's security notice says the incident affected orders placed between March 2, 2025, and April 11, 2026, and did not expose seed phrases, private keys, wallet passwords, payment-card data or access to customer funds.
The exposed fields included names, email addresses, shipping addresses, phone numbers and purchase details. That makes the incident a targeting risk even though it is not, on the company's current evidence, a wallet-compromise event.
SafePal's updated account
SafePal says the underlying authorization flaw has been fixed and that it has tightened the retention period for order information to 90 days. The company says it notified affected customers individually on Aug. 16 and took down more than 30 fraudulent websites and phishing links connected to scam activity.
In an Aug. 18 update, SafePal said it was engaging third-party investigation and audit teams. It also said people claiming to possess the customer file were advertising it for sale, but that the company could not yet verify those claims. The Defiant reported that a seller was offering records on a cybercrime forum and was using order IDs and shipping countries to advertise the data.
The risk now is impersonation
SafePal is warning users to expect more targeted phishing, fake support messages, fraudulent firmware-update requests and impersonation attempts. The company says users do not need to move assets solely because their order information was affected, but anyone who shared a seed phrase or private key in response to a suspicious contact should treat that wallet as compromised and move funds using a trusted device or official application.
The disclosure leaves an important distinction for customers: the public record confirms exposure of order information, not theft from SafePal wallets. The outstanding questions concern how widely the file circulates, whether additional systems were affected and whether the external review validates the company's fix.