
SafePal data breach exposes 39,798 customers; stolen info for sale
Cryptocurrency hardware wallet provider SafePal has confirmed a data breach affecting order information belonging to about 39,798 customers. The exposed data covers customers who placed orders between March 2, 2025, and April 11, 2026, and a threat actor is now claiming to be selling the stolen records on a cybercrime forum. The stolen details include customer names, email addresses, shipping addresses, phone numbers, and purchase information. In a security advisory published Sunday, SafePal said the incident did not expose wallet seed phrases, private keys, passwords, bank account information, payment card numbers, government-issued identification numbers, or other credentials. It also said there was no evidence that the incident compromised access to SafePal wallets or funds. The breach stemmed from an authorization flaw in the order-tracking function of a plug-in in SafePal's e-commerce system, which allowed unauthorized access to other customers' order information. SafePal discovered the issue in July 2026 during a full review and rebuild of its order-processing system. The company says it has fixed the vulnerability and added extra security measures, and is working with a third-party security firm to validate the fix and conduct a broader review. The impact was compounded by a separate configuration error that made a data-cleanup process stop working properly between September 2025 and April 2026. As a result, order data was retained as far back as March 2025. SafePal has purged affected personal data from active e-commerce servers, while keeping an encrypted offline copy for potential law-enforcement investigations. SafePal notified affected customers by email on August 16 with the subject "[Important] Your SafePal Order Information Has Been Affected." The company says it first received a report consistent with the incident in early May 2026 and initially treated it as an isolated case; it later escalated the matter into a formal security investigation. Separately, a customer posted on X in May that they had received a SafePal phishing email and a phone call from someone claiming to be a company employee. The phishing email claimed a security vulnerability had been discovered in the SafePal X1 hardware wallet and that a firmware update was required. A threat actor is now claiming to be selling the stolen data on a cybercrime forum, according to a post spotted by DarkWebInformer. The seller cited the same affected order period and the same approximate number of customers disclosed by SafePal, telling prospective buyers: "Not interested in low balls, please come correct and with a good price or do not message me at all." The seller is willing to share order ID and shipping country details so buyers can confirm the data against SafePal's online verification tool. SafePal says customers whose order information was exposed do not need to replace their hardware wallets or move cryptocurrency because of the breach. It warns them to watch for phishing emails and phone calls about firmware upgrades, product returns, refunds, or legal investigations, and says it has already taken down more than 30 fraudulent websites and phishing links connected to the incident. Customers who already shared their seed phrase or private key in response to a phishing email or text should treat their wallet as compromised and move their assets to a new wallet on a trusted SafePal device or through the official application. The leak of SafePal shipping addresses and phone numbers creates a serious phishing risk for cryptocurrency users in Somalia and the diaspora who rely on hardware wallets to hold their funds. Because the stolen data shows exactly when and where a device was bought, criminals can craft convincing SMS or email scams impersonating technical support. Anyone using these wallets should treat sudden requests for firmware updates or seed phrase verification as hostile attacks, even if the sender knows their exact order history.
Read our sourcing and corrections policy



Be the first to comment on this story!