SafePal Discloses Data Breach Exposing Order Data of Nearly 40,000 Customers
Key Takeaways
- •SafePal said an authorization flaw in its order-tracking system exposed order information for approximately 39,798 customers.
- •The exposed data included names, addresses, contact details, and purchase information.
- •SafePal said the breach did not reveal cryptocurrency funds, seed phrases, private keys, wallet passwords, bank account or payment card details, or government-issued identification numbers.
- •The company warned that the stolen information could be used for targeted phishing and impersonation attacks.
- •SafePal said it has fixed the vulnerability, added security measures, removed more than 30 fraudulent websites and phishing links, and will retain order data for only 90 days.

Cryptocurrency wallet provider SafePal has disclosed a data breach that exposed order information belonging to approximately 39,798 customers, including names, addresses, contact details, and purchase data.
According to the company, the breach was caused by an authorization flaw in SafePal's order-tracking system that allowed users to access another customer's order information between March 2, 2025 and April 11, 2026, a window spanning roughly 13 months. Flaws of this kind, often described as broken access control, can let an authenticated user view records that should be restricted to other accounts; broken access control has ranked first in the OWASP Top 10, the industry-standard list of the most critical web application security risks, since 2021.
SafePal stated that the incident did not expose cryptocurrency funds, seed phrases, private keys, wallet passwords, bank account or payment card information, or government-issued identification numbers.
The company nevertheless warned that the exposed information could be used in targeted phishing and impersonation attempts, particularly because customer addresses and purchase details were involved. Phishing is among the most common attack vectors in the cryptocurrency sector, and messages that cite genuine order details are typically harder to distinguish from legitimate vendor communications.
SafePal said it has fixed the vulnerability and introduced additional security measures. The company also reported that it had identified and removed more than 30 fraudulent websites and phishing links associated with the incident.
As part of the measures introduced following the breach, SafePal plans to retain customers' personal information in its order-processing system for only 90 days, a data-minimization measure that limits how long personal records remain stored.
SafePal, founded in 2018, is a cryptocurrency wallet provider known for its hardware wallets and mobile application, which support a broad range of digital assets across multiple blockchains. In 2018, it became the first hardware wallet project to receive investment from Binance, through the exchange's venture arm Binance Labs.
This report is based on coverage by BitcoinKE.