Markets World Tech USA · World
S&P 500
7,785.76
+28.12   +0.36%
At close
Dow
53,732.41
-304.52   -0.56%
At close
Nasdaq
26,729.16
+38.54   +0.14%
At close
USD Index
99.64
-0.18   -0.18%
Live
Russell
3,068.41
+33.93   +1.12%
At close

Crypto

Crypto wallet SafePal reveals a data breach exposing nearly 40,000 customers' order info

· CoinDesk

While the data breach exposed the personal order details of thousands of customers, all private keys, seed phrases, and crypto assets remain completely safe.

  • SafePal disclosed a security breach that exposed the names, physical addresses and contact details of 39,798 customers who placed orders between March 2, 2025, and April 11, 2026.
  • The company said no cryptocurrency funds, seed phrases, private keys, bank details or government IDs were compromised, but warned that exposed users face heightened phishing and impersonation risks.
  • SafePal has taken several steps to address the situation.

Crypto hardware wallet provider SafePal has disclosed a security incident that exposed the personal information of thousands of customers.

The exposed data included names, physical addresses, and contact details, putting affected users at risk of phishing and impersonation attempts. However, the breach did not compromise any cryptocurrency funds, passwords, or private wallet keys.

SafePal is a cryptocurrency security company that provides physical hardware wallets and software applications designed to help investors safely store and manage their digital assets.

The latest exploit follows a recent hack of Coldcard hardware wallets, in which the attacker reportedly stole at least $120 million in bitcoin. While the incidents do not necessarily point to a systemic weakness in hardware wallets, they show that no crypto-storage solution is entirely risk-free. They also validate calls to assess concentration risk and, where appropriate, to diversify both crypto holdings and the wallets used to store them.

What happened?

SafePal said on Sunday that it identified an “authorization flaw” in a plug-in used to track customer orders. This flaw likely allowed attackers to see other customers’ orders. Think of it as a store’s parcel-tracking system allowing one customer to view another customer’s receipt and delivery details simply by changing the order number.

The breach has impacted 39,798 customers who placed orders between March 2, 2025 and April 11, 2026.

SafePal stressed that the core security of its wallets remains intact, adding that users’ seed phrases, private keys, bank passwords, bank account information, payment card numbers, and government-issued IDs were not affected.

However, SafePal said users who have shared their private keys or seed phrases via a phishing email, phone call, or letter should treat their wallet as compromised and transfer their assets to a new wallet.

How SafePal is responding

The company said it had patched the vulnerability and introduced additional security measures in response. SafePal notified all affected customers by email from [email protected] on Sunday and hired an independent third-party security firm to audit the fix and review its order-processing systems.

SafePal also said it would retain customers’ personal data in its order-processing system for only 90 days from the date of collection. In addition, the company identified and removed more than 30 fraudulent websites and phishing links associated with the breach.

Customers can use a verification tool on SafePal’s website to check whether their data was affected, the company said.

Zcash’s Tachyon upgrade aims to scale shielded payments, improve quantum readiness, and test whether its funding, security, and governance can hold.