Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
SafePal data breach exposes personal information of nearly 40,000 customers
00

SafePal data breach exposes personal information of nearly 40,000 customers

Aug 16, 2026

On August 16, 2026, cryptocurrency hardware wallet provider SafePal disclosed a data breach exposing the personal information of 39,798 customers who ordered between March 2, 2025, and April 11, 2026. An authorization flaw in an order-tracking plugin allowed unauthorized access to names, emails, physical addresses, and phone numbers. While private keys and crypto funds remain secure, users face heightened phishing risks. SafePal patched the flaw, hired an auditor, and limited data retention to 90 days.

SafePal data breach incident

  • ▪SafePal disclosed a security breach on August 16, 2026, that exposed the personal information of 39,798 customers.
  • ▪SafePal stated on August 16, 2026, that it found the root cause of the breach recently, although customers had reported being targeted by phishing attempts as early as July 2026.

Order-tracking plugin vulnerability

  • ▪The SafePal order-tracking plugin flaw allowed unauthorized access to order progress and receipt details, similar to viewing another customer's receipt by changing the order number.
  • ▪The SafePal data breach was caused by an authorization flaw in an order-tracking plugin that allowed unauthorized external access to customer order information.

Exposed customer information scope

  • ▪SafePal warned that the exposed customer order details could be used by attackers to target affected customers with sophisticated phishing and impersonation attempts.
  • ▪The SafePal security incident did not compromise cryptocurrency funds, seed phrases, private keys, wallet passwords, bank account details, payment card numbers, or government-issued identification numbers.
  • ▪The SafePal breach exposed the names, email addresses, physical shipping addresses, phone numbers, and purchase details of customers who placed orders between March 2, 2025, and April 11, 2026.

SafePal security response measures

  • ▪SafePal notified all affected customers individually via email on August 16, 2026, and provided a verification tool on its website for customers to check if their data was exposed.
  • ▪SafePal identified and removed more than 30 fraudulent websites and phishing links associated with the data breach.
  • ▪SafePal announced on August 16, 2026, that it will retain customers' personal data in its order-processing system for only 90 days from the date of collection.
  • ▪SafePal patched the order-tracking plugin vulnerability, introduced additional security measures, and hired an independent third-party security firm to audit the fix and review its order-processing systems.

Hardware wallet security context

  • ▪Trezor, another hardware wallet provider, leaked 13,689 records days prior to the SafePal disclosure, contributing to over 53,000 crypto owners having their data exposed in the same week.
  • ▪The SafePal breach follows a security incident involving Coldcard hardware wallets, where an attacker reportedly stole at least $120 million in bitcoin.

4 sources

BeInCrypto
Over 53,000 Crypto Owners Lost Something This Week That Isn’t Money
View source article
The Block
Wallet provider SafePal says data breach exposed personal info of nearly 40,000 customers
View source article
U.Today
Binance-Backed SafePal Reveals Data Breach: 40,000 Users' Info Exposed - U.Today
View source article
CoinDesk
Safepal security vulnerability exposes data of 39,798 customers
View source article

Story comments

Loading comments…

Related Projects

TrezorSafePal

Topics

Crypto hacksData breachesCrypto privacy & surveillance