The exposed data included names, physical addresses, and contact details, putting affected users at risk of phishing and impersonation attempts. However, the breach did not compromise any cryptocurrency funds, passwords, or private wallet keys.
SafePal is a cryptocurrency security company that provides physical hardware wallets and software applications designed to help investors safely store and manage their digital assets.
The latest exploit follows a recent hack of Coldcard hardware wallets , in which the attacker reportedly stole at least $120 million in bitcoin. While the incidents do not necessarily point to a systemic weakness in hardware wallets, they show that no crypto-storage solution is entirely risk-free. They also validate calls to assess concentration risk and, where appropriate, to diversify both crypto holdings and the wallets used to store them.
SafePal said on Sunday that it identified an “authorization flaw” in a plug-in used to track customer orders. This flaw likely allowed attackers to see other customers’ orders. Think of it as a store’s parcel-tracking system allowing one customer to view another customer’s receipt and delivery details simply by changing the order number.
The breach has impacted 39,798 customers who placed orders between March 2, 2025 and April 11, 2026.
SafePal stressed that the core security of its wallets remains intact, adding that users’ seed phrases, private keys, bank passwords, bank account information, payment card numbers, and government-issued IDs were not affected.
However, SafePal said users who have shared their private keys or seed phrases via a phishing email, phone call, or letter should treat their wallet as compromised and transfer their assets to a new wallet.
The company said it had patched the vulnerability and introduced additional security measures in response. SafePal notified all affected customers by email from [email protected] on Sunday and hired an independent third-party security firm to audit the fix and review its order-processing systems.
SafePal also said it would retain customers’ personal data in its order-processing system for only 90 days from the date of collection. In addition, the company identified and removed more than 30 fraudulent websites and phishing links associated with the breach.
Customers can use a verification tool on SafePal’s website to check whether their data was affected, the company said.
1 MiCA's cleanup is creating a new scam wave across the European Union 7 min ago 2 The stablecoin yield clash that won't go away has banks, crypto battling over tradition 1 hr ago 3 The 'long bitcoin, short the bankers' era is officially over as TradFi giants embrace digital assets 2 hrs ago 4 Robot maker Unitree is going public. Hyperliquid traders see 4x upside from IPO price 22 hrs ago 5 Swiss mega-bank UBS ramps up its Bitcoin exposure with a massive 24-fold surge in ETF call options 22 hrs ago 6 Why the world’s second-largest Bitcoin mining power is shutting down rigs in its capital city 22 hrs ago 7 Paul Tudor Jones’ investment firm increases stake in BlackRock's bitcoin ETF after year of selling 22 hrs ago 8 The $11.2 billion in 2026 funding that killed crypto’s permissionless era 1 day ago 9 Clarity survives (barely), Strategy sells and the untold story of Mastercard's $1.8 billion deal: Crypto's week in 5 stories 1 day ago 10 Wall Street's private blockchain obsession is a 'race to the bottom,' Ethereum advocate Raman warns 1 day ago Latest Research Building the Zcash Machine: Tachyon and Quantum Readiness Building the Zcash Machine: Tachyon and Quantum Readiness Zcash’s Tachyon upgrade aims to scale shielded payments, improve quantum readiness, and test whether its funding, security, and governance can hold.
Zcash’s Tachyon upgrade aims to scale shielded payments, improve quantum readiness, and test whether its funding, security, and governance can hold.