Full story
SafePal breach details
SafePal disclosed a data breach affecting about 39,798 customers after an authorization flaw in its order-tracking system allowed unauthorized access to order information tied to customers’ purchases.
“between Mar 2, 2025, and Apr 11, 2026”
The company said the affected orders were placed between Mar 2, 2025, and Apr 11, 2026, and that the exposed records included names, email addresses, shipping addresses, phone numbers and purchase histories.

SafePal said the breach did not involve access to “seed phrases”, private keys, wallet passwords, bank account information, payment card numbers or government-issued identification numbers, and it said it found no evidence of unauthorized wallet access or asset theft.
In response, SafePal said it fixed the issue and introduced further security measures, including reducing personal-data retention in its order-processing system to 90 days.
Phishing risk and warnings
SafePal warned that exposed order details could be used for targeted phishing and impersonation attempts, with attackers armed with genuine names, addresses and purchase details to craft more convincing fraudulent communications.
The company said attackers may impersonate SafePal employees and try to steal wallet credentials by using firmware updates, refunds or replacement devices as a pretext.

SafePal also told customers to treat unexpected contact as suspicious, and it warned: "Consider suspicious any contact unexpected or hardware delivery that references your SafePal purchase".
Bloomingbit reported that SafePal disclosed the authentication flaw on X and that it had not immediately responded to The Block’s emailed questions about the timing of the flaw’s introduction or how many attackers obtained the data.
What SafePal says comes next
SafePal said it has identified and taken down more than 30 fraudulent websites and phishing links tied to the breach, and it said it emailed affected customers individually on Sunday.
“SafePal has now reduced personal-data retention in the relevant order-processing environment to 90 days”
The company said it is engaging an independent third-party security firm to validate its fix and conduct a broader review of its order-processing systems, and it said the firm has not yet been named publicly.
SafePal also said affected customers’ personal information has been removed from active e-commerce servers while an encrypted offline copy is being retained to support potential investigations.
In addition to tightening retention to 90 days, SafePal said it launched a verification tool allowing buyers to check whether their orders were affected using their order number and shipping country.



