Skip to main content

SafePal Data Breach Exposes 39,798 Customer Order Details

5 min read Runtime Rebel Intel
Primary source: bleepingcomputer.com

This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy

Key points
  • Immediate impact: 39,798 SafePal customers' order details are exposed and being sold, increasing phishing and social engineering risks.
  • Affected systems: SafePal's e-commerce order-tracking function, impacting orders placed March 2, 2025 – April 11, 2026.
  • Remediation: Customers must verify order status, be vigilant against targeted phishing, and move funds if seed phrases were shared.

Advertisement

SafePal, a prominent cryptocurrency hardware wallet provider, has disclosed a data breach affecting approximately 39,798 customers. The breach, which exposed sensitive customer order information, stems from an exploited authorization flaw within its order-tracking system. The compromised data, now reportedly being offered for sale on cybercrime forums, significantly elevates the risk of targeted phishing and social engineering attacks against affected individuals, as detailed by BleepingComputer.

Technical Details of the SafePal Data Breach

Understanding the Exploited Flaw

The investigation by SafePal revealed that the breach originated from an authorization flaw found in the order-tracking function of a third-party plug-in used within their e-commerce system. This vulnerability allowed unauthorized access to other customers’ order details. SafePal also identified a separate configuration error that caused a data-cleanup process to malfunction between September 2025 and April 2026, leading to the retention of order data stretching back to March 2025. This combination of factors facilitated the prolonged exposure and eventual exfiltration of customer information.

The breach specifically impacts customers who placed orders between March 2, 2025, and April 11, 2026. The exposed data includes names, email addresses, shipping addresses, phone numbers, and purchase information. Crucially, SafePal has confirmed that highly sensitive data such as customers’ wallet seed phrases, private keys, passwords, bank account information, payment card numbers, or government-issued identification numbers were not compromised. The company explicitly states, “No evidence has been found that the incident itself compromised access to SafePal wallets or funds.”

Post-Breach Landscape: Data for Sale and Phishing Campaigns

Following the disclosure, a threat actor has claimed to be selling the stolen SafePal customer data on a cybercrime forum. The seller’s claims align with SafePal’s official statements regarding the affected order period and the approximate number of customers impacted. To validate the authenticity of the data, the threat actor offers to share specific order IDs and shipping countries, which buyers can then cross-reference with SafePal’s publicly available online verification tool. This detail underscores the verifiable nature of the stolen SafePal order information exposed on these forums.

The immediate aftermath has seen a surge in targeted phishing and social engineering attempts. SafePal customers have reported receiving fraudulent emails and phone calls, some as early as May 2026, purporting to be from the company. These deceptive communications often suggest fabricated security vulnerabilities, demand firmware updates, or discuss product returns and refunds to trick users into divulging sensitive information or transferring assets. SafePal has already initiated efforts to take down over 30 fraudulent websites and phishing links related to this incident.

Actionable Recommendations for Mitigating SafePal Phishing Attacks

Immediate Steps for Affected Customers

For customers concerned about the SafePal data breach customer impact, immediate action is essential to protect against potential follow-on attacks:

  • Verify Your Order Status: Utilise SafePal’s online verification tool by entering your order number and shipping country to determine if your specific order details were compromised.
  • Exercise Extreme Caution: Be highly suspicious of any unsolicited communications (emails, phone calls, SMS messages) that claim to be from SafePal. This includes requests related to firmware upgrades, product returns, refunds, or legal investigations. SafePal communicates official updates directly through its official channels and previously notified affected users via email on August 16, 2026.
  • Never Share Sensitive Information: Reiterate that SafePal will never ask for your wallet seed phrase, private keys, or passwords. Any request for this information is a phishing attempt. Hardware wallets are designed to protect these assets directly on the device.
  • Act if Seed Phrase Was Compromised: If, in response to a phishing attempt, you have already shared your seed phrase or private key, consider that wallet compromised. Immediately transfer all assets from the affected wallet to a new, secure wallet setup on a trusted SafePal device or official application.

General Security Best Practices

To bolster overall digital security, particularly in light of this breach, security professionals and individuals alike should:

  • Enable Multi-Factor Authentication (MFA): Wherever available, activate MFA on all online accounts, especially those related to cryptocurrency exchanges and financial services.
  • Educate Against Social Engineering: Understand common social engineering tactics. Attackers leverage exposed personal details to craft highly convincing and personalized scams. Always verify the legitimacy of requests through official, independently sourced contact information, rather than links or numbers provided in suspicious communications.
  • Monitor Financial Accounts: Keep a close watch on your cryptocurrency exchange accounts and any linked financial accounts for unusual activity.

SafePal has addressed the underlying vulnerability and implemented additional security measures, including working with a third-party security firm for validation. While direct wallet compromise was avoided, the exposure of personal order information necessitates heightened vigilance from all affected customers to prevent secondary financial or identity theft.

Related: ShinyHunters Data Leaks Fuel $2,000 Sextortion Phishing Campaign, FBI Warns: $388M Lost to Crypto ATM Scams in 2023 – Defense Guide

Advertisement

Advertisement