
Crypto wallet provider SafePal has disclosed a data breach that allowed unauthorized access to order information belonging to approximately 39,798 customers, exposing names, contact details, shipping addresses and purchase information.
SafePal said the incident was caused by an authorization flaw in an order-tracking system. The affected information relates to customers who placed orders between March 2, 2025, and April 11, 2026, according to the company’s incident disclosure and CoinDesk’s report.
The company said the breach did not expose seed phrases, private keys, wallet passwords, bank account information, payment card numbers or government-issued identification numbers. SafePal also said it has found no evidence that the incident itself compromised access to customer wallets or funds.
SafePal said the exposed information could nevertheless be used in targeted phishing and impersonation attempts. Attackers could use customer names, addresses, phone numbers and purchase details to make fraudulent communications appear to come from SafePal employees, including messages involving firmware updates, refunds or replacement devices.
According to The Block, SafePal received a report consistent with the breach in early May 2026 but treated it as an isolated case at the time. The company later escalated its investigation and began a broader review and rebuild of its order-processing pipeline in July, during which it confirmed the root cause.
The timing of the investigation has also drawn attention because customers had publicly described suspicious SafePal-themed contacts before the company’s disclosure. A July 4 Trustpilot review alleged that scammers knew the user’s account information and directed the person to a website presented as a SafePal replacement-device service. A separate Reddit post from July 3 described a similar contact in which the caller allegedly knew the user’s name, address, phone number, email address and order details.
The Block reported that it could not independently establish that those individual reports were caused by the disclosed SafePal breach. SafePal also said that an investigation carried out at the time did not identify a breach.
SafePal said it has since fixed the authorization issue and introduced additional security measures. The company has also identified and taken down more than 30 fraudulent websites and phishing links associated with the activity.
The company said it would reduce the retention period for personal information in its order-processing system to 90 days. SafePal has also notified affected customers and established a verification process that allows customers to check whether their information was affected.
SafePal’s security information describes the company as a decentralized wallet provider that does not require registration, know-your-customer checks or identity verification for its wallet services. Its security page also says purchase information is removed every 12 months. The newly disclosed incident concerns information handled by its order-processing infrastructure rather than users’ wallet keys.
SafePal has engaged an independent cybersecurity firm to assess the fix and review its order-processing systems, according to CoinDesk. The company said affected customers were contacted by email from security@safepal.com.
The company has not publicly disclosed when the vulnerability was introduced, when customer records were first accessed, how many people may have obtained the information or whether any customers were confirmed to have lost funds as a result of the incident. SafePal has said it is working with asset-tracing specialists and has asked anyone reporting a loss to provide details through its support channel.
The disclosure comes days after a separate data breach involving Trezor’s shipping partner ShipMonk exposed information connected to nearly 14,000 customers. In that incident, names, phone numbers and full shipping addresses were exposed for 11,742 customers, while another 1,947 had names, cities and email addresses exposed, according to The Block. Ledger also disclosed in January that some customer names and contact information had been exposed through Global-e, a third-party commerce provider.
In each of those cases, the companies said the incidents did not compromise customers’ wallet private keys. The SafePal incident similarly centers on customer and order information rather than the cryptographic credentials used to control digital assets.
For affected customers, SafePal has warned against responding to unsolicited messages that request wallet credentials or direct users to unfamiliar websites. The company’s disclosure says the exposed information creates a risk of targeted impersonation and phishing even though seed phrases and private keys were not part of the compromised data.
Customers who have already disclosed a seed phrase or private key to someone claiming to represent SafePal should treat the wallet as compromised and move assets to a new wallet, according to CoinDesk. SafePal’s disclosure, however, does not indicate that such credentials were obtained through the breach itself.
The incident highlights a distinction between the security of a non-custodial wallet and the security of the commercial systems used to sell and deliver the device. SafePal’s stated wallet architecture can keep private keys and seed phrases outside the company’s control, while order-processing systems can still contain identifying information that may be valuable to attackers.
SafePal has said its corrective measures are now in place, while several questions about the extent and timing of unauthorized access remain unanswered. For customers whose information was included, the immediate concern is the possibility of convincing SafePal impersonation attempts based on the order information that was exposed.
References:
- Reuters report on the SafePal breach
- CoinDesk’s coverage of the incident
- The Block’s investigation and timeline
- SafePal security information
Discover more from Aree Blog
Subscribe now to keep reading and get access to the full archive.

