Crypto hardware wallet provider SafePal has disclosed a data breach exposing the names, physical addresses, and contact details of nearly 40,000 customers who placed orders over the past year.
Key Points
- The breach affected 39,798 customers who placed orders between March 2, 2025, and April 11, 2026.
- An authorization flaw in a third-party order-tracking plug-in allowed unauthorized access to customer delivery information.
- SafePal confirmed that all private keys, seed phrases, cryptocurrency assets, and payment card details remain secure and uncompromised.
- The company has patched the vulnerability, hired an independent security firm for an audit, and removed over 30 associated phishing websites.
- Affected users can verify their status using a dedicated tool on the official SafePal website.