Crypto hardware wallet provider SafePal has disclosed a data breach affecting approximately 39,798 customers, raising concerns about phishing and impersonation attacks even though the company said users’ crypto assets were not compromised.
SafePal said an authorization flaw in an order-tracking plugin allowed unauthorized access to customer order information. The affected customers placed orders between March 2, 2025, and April 11, 2026. The exposed information included names, email addresses, physical or shipping addresses, phone numbers and purchase details.
Dear community,
While your SafePal wallet, seed phrase, and private keys are secure; we identified a flaw in the order-tracking plug-in that led to unauthorized access to information of a subset of customers.
The issue has been fixed with additional security measures…
— SafePal – Crypto Wallet (@SafePal) August 16, 2026
The company stressed that the incident did not expose users’ seed phrases, private keys or wallet passwords. Bank account information, payment card details and government-issued identification documents were also not affected
This distinction is important because SafePal’s hardware wallets are designed to keep private keys separated from internet-connected systems. The reported breach involved customer order information rather than direct access to cryptocurrency wallets.
However, the leaked personal information could still create security risks. Attackers could potentially use names, addresses and purchase details to create convincing phishing emails, phone calls or other impersonation attempts targeting SafePal customers.
The company has reportedly fixed the vulnerability and introduced additional security measures. SafePal also notified affected customers individually and engaged an independent security firm to review the fix and its order-processing systems.
The incident highlights a broader cybersecurity challenge for the cryptocurrency industry. Even when wallet infrastructure itself remains secure, customer databases and e-commerce systems can become targets for attackers.
Hardware wallet users are therefore advised to be particularly cautious about unsolicited messages that reference previous purchases, wallet orders or delivery information.
SafePal has also warned users not to share seed phrases or private keys in response to emails, calls or messages. If a user has already revealed sensitive wallet credentials, the wallet should be treated as compromised and assets moved to a new wallet.
The breach serves as a reminder that crypto security involves more than protecting private keys. Personal information linked to crypto purchases can also become valuable to attackers and may be used to target users through sophisticated social-engineering campaigns.
Stay informed with the latest trends in Web3, blockchain innovation, and cybersecurity updates at 3verseTV
You need to login in order to Like










Leave a comment