SafePal Data Breach Exposes Personal Info of 39,798 Users

iconUnLock
Share
AI summary iconSummary
A security breach at SafePal exposed personal data of 39,798 users who placed orders between March 2, 2025, and April 11, 2026. Names, postal addresses, and contact details were leaked via a flaw in the order-tracking system. Funds, private keys, and recovery phrases remained secure. SafePal patched the issue, implemented a 90-day data-retention policy, and took down over 30 phishing sites. The incident highlights the need for stronger security measures amid rising inflation data and increased cyber threats.

Summary

SafePal disclosed a data breach affecting 39,798 customers who placed orders between March 2, 2025, and April 11, 2026, exposing names, postal addresses, and contact details through a vulnerability in its order-tracking system, while funds, private keys, and recovery phrases remained unaffected.

Key Takeaways

  • The breach originated in an order-tracking extension, not in wallet security infrastructure, meaning crypto holdings were not directly at risk, but exposed personal data creates a viable attack surface for targeted phishing campaigns.
  • SafePal introduced a 90-day data-retention policy for its order-processing system and removed more than 30 fraudulent websites and phishing links identified in connection with the incident.
  • The incident illustrates that self-custody wallet providers face security risks beyond private-key protection, as customer-facing order and support systems can be exploited even when the wallets themselves remain secure.
  • SafePal has provided a verification tool on its website allowing customers to confirm whether their data was affected, and advises users who disclosed recovery phrases or private keys in response to suspicious communications to migrate assets to a new wallet immediately.

Digital asset wallet provider SafePal has disclosed a security incident that exposed personal information belonging to nearly 40,000 customers, raising fresh concerns about the risks surrounding user data in the cryptocurrency ecosystem.

According to the company, the incident affected 39,798 customers who placed orders between March 2, 2025, and April 11, 2026.

The compromised information included customer names, postal addresses and contact details. SafePal said, however, that the incident did not compromise users' funds, passwords, private keys or recovery phrases.

The distinction is significant because the breach appears to have affected data surrounding SafePal's order-processing systems rather than the underlying security infrastructure protecting users' crypto wallets.

How the SafePal Breach Happened

SafePal said it discovered a vulnerability in an extension used to track customer orders.

The flaw appears to have allowed an attacker to access information associated with other customers' orders by manipulating order-related data.

In practical terms, the vulnerability could be compared to a package-tracking system that allows someone to view another customer's information simply by changing an order number.

The company said it has since addressed the vulnerability and taken additional measures to prevent similar incidents.

What SafePal Customer Data Was Exposed?

The incident involved personal information connected to customer orders.

SafePal said the exposed information did not include recovery phrases, private keys, account passwords, banking information, payment-card numbers or government-issued identification documents.

The company also said there was no indication that the incident provided attackers with direct access to customers' cryptocurrency holdings.

That does not mean the leaked information is without risk.

Names, addresses and contact details can give attackers valuable information for constructing highly targeted phishing campaigns. A scammer who knows that someone purchased a SafePal product may be able to make a fraudulent email, phone call or message appear significantly more convincing.

SafePal Warns Users About Phishing Attempts

The company has urged affected customers to remain particularly cautious about unsolicited communications claiming to come from SafePal.

Users should be suspicious of any message requesting a recovery phrase, private key or account credentials, regardless of how legitimate the communication appears.

SafePal specifically advised customers who may have disclosed their private keys or recovery phrases in response to fraudulent emails, calls or messages to treat those wallets as compromised and move their assets to a new wallet.

This distinction is important because legitimate wallet providers do not need users' recovery phrases or private keys to provide routine customer support.

SafePal Fixes Vulnerability and Reviews Its Systems

Following the discovery, SafePal said it fixed the vulnerability and implemented additional security measures.

The company also brought in an independent security firm to conduct a broader review of its order-processing infrastructure and help address the underlying issue.

SafePal said it notified affected customers through its official security email address and introduced a new data-retention policy under which personal information in its order-processing system will be retained for only 90 days from collection.

The company has also identified and removed more than 30 fraudulent websites and phishing links associated with the incident.

How SafePal Users Can Check Their Data

SafePal has provided customers with a verification tool through its website that allows them to determine whether their information was affected.

For users who were impacted, the most immediate concern is likely to be follow-on fraud rather than direct theft of cryptocurrency.

Personal information can provide attackers with the context needed to impersonate a wallet provider, customer-service representative or other trusted party. Such attacks can ultimately be used to trick victims into voluntarily revealing the information that the original breach did not expose.

The Broader Security Challenge for Crypto Wallet Providers

The SafePal incident highlights a broader issue in digital asset security: protecting cryptocurrency does not end with protecting private keys.

Hardware wallets and other self-custody products are designed to isolate sensitive cryptographic information from online threats. But companies operating around those products still handle customer information through websites, order systems, support platforms and other connected infrastructure.

Those systems can become attack vectors even when the wallets themselves remain secure.

The incident therefore underscores the importance of third-party risk management and customer-data protection alongside traditional wallet security.

SafePal Breach Highlights the Human Side of Crypto Security

For cryptocurrency users, the most important lesson from the SafePal incident may be that a data breach does not have to expose private keys to create serious security risks.

An attacker armed with a customer's name, address and knowledge that the person uses a particular wallet provider may have enough information to launch a targeted social-engineering campaign.

As digital asset ownership expands, security will increasingly depend not only on protecting blockchain transactions and private keys, but also on safeguarding the personal information surrounding those assets.

For SafePal, the incident serves as a reminder that the security perimeter extends well beyond the wallet itself. For users, it reinforces a fundamental rule of self-custody: never disclose a recovery phrase or private key, even to someone claiming to represent a trusted crypto company.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.