SafePal Breach Exposes Data of Nearly 40,000 Customers
A flaw in SafePal’s order-tracking plugin exposed personal details for about 39,798 customers who ordered between March 2, 2025 and April 11, 2026. SafePal says no wallet credentials were taken.
SafePal disclosed a vulnerability in an order-tracking plugin that exposed names, addresses, email addresses, phone numbers and order details for approximately 39,798 customers who placed orders between March 2, 2025 and April 11, 2026.
The company began investigating after receiving a report in May and later determined a bug caused order-related data to be retained longer than intended. A full review and rebuild of the order-processing pipeline started in July, and the root cause was confirmed during the investigation. The disclosure coincided with a threat actor advertising the stolen data on a cybercrime forum; the attacker claimed the same number of affected customers.
SafePal reported it has fixed the vulnerability and shortened the retention period for order-related information. The company identified and notified impacted customers, contacted partners to confirm the issue had not spread, retained a third-party security firm to investigate, and removed more than 30 fraudulent websites and phishing links tied to the incident while continuing to monitor for new malicious sites.
Customers were warned to be cautious of phishing attempts and any communications requesting seed phrases or private keys. The company advised that if a seed phrase or private key has already been shared or entered in response to a suspicious message or website, the associated wallet should be treated as compromised. Affected users were instructed to create a new wallet using a trusted SafePal device or the official SafePal application and move remaining assets to the new wallet immediately.
SafePal asked customers who believe they suffered financial loss related to the incident to contact the company and provide details, and said it is working with on-chain asset-tracing specialists. The company added: “Note that this does not represent any admission of liability or commitment to compensation; our focus at this stage is supporting recovery and ongoing investigations.”








