SafePal Data Breach Impacts 40,000 Users
Cryptocurrency hardware wallet manufacturer SafePal has announced that the personal information of nearly 40,000 customers has been stolen. Attackers exploited a vulnerability in the order tracking system to access names, addresses, and contact details. The company stated that wallet funds remain secure.
What Happened
SafePal, a manufacturer of hardware wallets operating in the cryptocurrency security space, is in the news with a data breach that has shaken its user base. According to an official statement from the company, the personal information of approximately 40,000 customers was compromised by cyber attackers. The incident was attributed to a vulnerability in a plugin within the company's order tracking system. SafePal also confirmed that on the same day the breach was publicly disclosed on Sunday, a threat actor appeared on a cybercrime forum claiming to possess the same data. The attacker claimed the stolen data belonged to 39,798 individuals, consistent with SafePal's disclosure, and listed it for sale.
According to the company's statement, the data affected belongs to customers who placed orders between March 2, 2025, and April 11, 2026. This indicates that customer data was at risk for over a year. SafePal stated that it initially identified the incident as an isolated case in May but later discovered through a detailed investigation that a bug in its system caused order data to be stored for much longer than intended. Following this discovery, they began a full review and rebuild of their order-processing pipeline in July, confirming the root cause during this process.
Data Compromised
SafePal reported that the breach resulted in the theft of non-critical but still sensitive customer information. The company specifically emphasized that the incident did not affect crypto assets in wallets, private keys, or seed phrases. However, the compromised data provides a valuable foundation for targeted phishing attacks against users.
The leaked information includes:
- Names: Full names of customers.
- Addresses: Physical addresses where customers received their orders.
- Email Addresses: Email addresses used for communication.
- Phone Numbers: Mobile or landline numbers belonging to customers.
- Order Details: Information such as which product was ordered and when.
The combination of this information allows attackers to create highly convincing and personalized scam scenarios. For example, an attacker, knowing a victim's name, address, and which SafePal product they purchased, could send a fraudulent support request email. This email might use pretexts like a "security update" or "account verification" to request the user's secret wallet credentials. The success rate of such personalized attacks is much higher than that of generic phishing attempts.
How the Attack Occurred
According to SafePal's statement, the attackers exploited a vulnerability in a customer order information plugin used on the company's website. This flaw was located in the plugin's order-tracking function. The attackers managed to infiltrate the system by exploiting this vulnerability and gain access to the customer database. The company has not shared the precise technical details of the attack or the type of vulnerability that was exploited.
During its investigation, SafePal also discovered that a bug in its own systems had exacerbated the situation. Order-related data that should have been deleted after a certain period was retained in the system for much longer than intended due to this error. This allowed the attackers to access data from a wider time frame (approximately 13 months). The company stated that it has patched this vulnerability and tightened its data retention policies.
Who Is Affected
The data breach affected approximately 39,798 customers who ordered a hardware wallet or a related product from SafePal between March 2, 2025, and April 11, 2026. If you placed an order during these dates, there is a high probability that your personal information was compromised. You can use a Data Breach Search service to check if your information has been exposed in this or similar incidents. The company has announced that it has begun notifying all affected customers.
What You Can Do
SafePal has issued a series of important recommendations for users who are affected or suspect they may be affected by the breach. Following these steps is critical to protect yourself from potential fraud attempts.
- Be Wary of Suspicious Communication: Be extremely skeptical of any message received via email, SMS, or phone call asking for your seed phrase or private keys. SafePal or any other legitimate organization will never ask for this information.
- Never Share Your Seed Phrase: Your 12 or 24-word seed phrase is the master key to your wallet and provides access to all your assets. Avoid storing it digitally, taking a photo of it, or sharing it with anyone.
- Act Immediately if You Believe Your Wallet is Compromised: If you have shared your seed phrase in response to a suspicious message or by entering it on a fake website, assume that wallet is no longer secure. Immediately create a new wallet using a trusted SafePal device or the official SafePal application and transfer your remaining assets to this new wallet.
- Use Official Channels: When you need to contact SafePal or perform a software update, only use the official website or application. Do not trust links from search engines or social media.
What the Company Says
SafePal expressed its regret over the incident and transparently shared the steps it has taken to manage the situation. According to the company's statement, the following measures were taken after the breach was detected:
- The security vulnerability exploited in the attack has been patched.
- Data retention policies have been tightened by shortening the storage period for order-related information.
- All 39,798 affected customers have been identified, and the notification process has been initiated.
- Partners have been contacted to ensure the issue did not propagate to their systems.
- An independent third-party cybersecurity firm has been retained to investigate the incident and audit the systems.
- Over 30 fraudulent websites and phishing links tied to scam activities have been identified and taken down, with active monitoring for new ones continuing.
- Customers who may have experienced a financial loss related to the incident have been asked to contact the company. SafePal stated it is in contact with on-chain asset-tracing specialists to assist these individuals but added that this does not represent any admission of liability or commitment to compensation.
The company reiterated that users' funds are not at direct risk, stating, "This incident did not involve your seed phrase, private keys, wallet password, or other wallet credentials, bank account information, payment card numbers, or government-issued identification numbers."
Source
https://www.securityweek.com/40000-impacted-by-safepal-data-breach/
This content was generated with AI assistance through our Argus Flow application. We are continuously working to improve Argus Flow; if you encounter any issues such as translation errors, incorrect sources, or unverified information, you can report them using the button below. We appreciate your feedback.