SafePal reports data breach: data of 39,798 customers exposed
Crypto wallet provider SafePal has disclosed a security incident in which the personal data of nearly 40,000 customers was exposed. A flaw in an order tracking plugin allowed unauthorised access to customer data. Wallets, seed phrases and private keys have not been compromised, but affected customers face an increased risk of phishing attempts.
In brief:
- A flaw in an order tracking plugin gave unauthorised parties access to the data of 39,798 SafePal customers.
- The leaked information includes names, email addresses, shipping addresses, phone numbers and purchase details.
- Seed phrases, private keys and payment information have not been affected; SafePal warns of phishing.
Flaw discovered in order tracking plugin
SafePal says its team found an authorisation error in the plugin used to track orders. Under certain circumstances, this flaw made it possible to view another customer’s order data. Customers who placed an order between 2 March 2025 and 11 April 2026 may have been affected.
According to the security advisory on the SafePal website, the data of 39,798 customers is involved. The exposed information includes names, email addresses, shipping addresses, phone numbers and purchase details. Financial data such as card information, bank details and government documents have not been affected. There is also no evidence that wallets or funds have been compromised.
SafePal states that the flaw was closed as soon as it was discovered and that additional security measures have been introduced. An independent security firm has also been brought in to validate the fix and conduct a broader review of the order processing systems.
Phishing risk for affected customers
Although wallets and crypto funds are safe, SafePal warns that the leaked data could be used for targeted phishing attacks. This includes fraudulent phone calls, emails, text messages or fake customer service communications in which scammers attempt to obtain wallet credentials.
SafePal has already had more than 30 fraudulent websites and phishing links linked to the matter taken offline. Affected customers have been informed individually by email. Through the page safepal.com/scam protection, customers can check whether their data has been affected using their order number and delivery country.
The company urges customers never to share their seed phrase, private key or password, including with anyone posing as a SafePal employee. SafePal advises anyone who has already opened suspicious links or entered login details on an unknown website to create a new wallet immediately and transfer any funds to it.
Not financial advice. The Latest Crypto News provides educational and informational content only. Crypto-assets are highly volatile and you can lose your entire investment. Always do your own research. Read our full disclaimer.
Affiliate disclosure. Some links on this site are affiliate links. If you sign up with a partner through one of them, we may earn a commission at no extra cost to you. This never influences our reporting. See our editorial guidelines.