AUTO-UPDATED

Crypto wallet SafePal reveals a data breach exposing nearly 40,000 customers' order info

Crypto hardware wallet provider SafePal has disclosed a data breach exposing the names, physical addresses, and contact details of nearly 40,000 customers who placed orders over the past year.

Key Points

  • The breach affected 39,798 customers who placed orders between March 2, 2025, and April 11, 2026.
  • An authorization flaw in a third-party order-tracking plug-in allowed unauthorized access to customer delivery information.
  • SafePal confirmed that all private keys, seed phrases, cryptocurrency assets, and payment card details remain secure and uncompromised.
  • The company has patched the vulnerability, hired an independent security firm for an audit, and removed over 30 associated phishing websites.
  • Affected users can verify their status using a dedicated tool on the official SafePal website.

Why it Matters

While the incident did not compromise actual digital assets, the exposure of personal contact information significantly increases the risk of targeted phishing attacks against hardware wallet owners. This event highlights the importance of maintaining strict data hygiene and diversifying storage solutions to mitigate risks beyond just the security of the hardware itself.
CoinDesk Published by Omkar Godbole
Read original