bytevyte
bytevyte
Language
quick-beats

SafePal data breach exposes nearly 40,000 customer orders via tracking flaw

SafePal data breach

SafePal has disclosed a data breach affecting roughly 39,798 customers who placed orders between March 2, 2025 and April 11, 2026. The crypto hardware wallet maker said the incident, announced on August 16, stems from an authorization flaw in its order-tracking plug-in that let unauthorized parties pull up another customer's order details. No wallet credentials or funds were compromised.

SafePal data breach: what was exposed

The leaked records cover order information rather than wallet infrastructure. SafePal confirmed that seed phrases, private keys, and wallet passwords were not accessed, and it found no evidence of unauthorized access to wallets or assets. Since SafePal's wallets are non-custodial, recovery phrases and private keys remain on the user's device, which put them out of reach of this incident.

  • Exposed: names, email addresses, phone numbers, shipping addresses, and purchase details.
  • Not exposed: seed phrases, private keys, wallet passwords, payment card numbers, bank account details, and government-issued IDs.

The SafePal data breach traces back to a broken access control flaw in the order-tracking plug-in used on the company's e-commerce platform, meaning one customer could view another customer's order information. SafePal said the vulnerability has been identified and fixed. The affected window spans roughly 13 months, covering every order placed between early March 2025 and mid-April 2026.

The main follow-on risk is phishing. With names, addresses, and phone numbers in hand, attackers can build impersonation attempts that closely mimic official SafePal communications. The company has urged affected customers to stay alert for phishing and impersonation messages and to treat any unsolicited request for login details or recovery phrases as suspicious. Anyone who ordered during the affected window should assume their contact details are now in third-party hands and judge incoming messages on that basis.

Why this matters

For crypto users, the SafePal data breach is a reminder that personal information can leak even when funds stay safe. The exposed contact details remain usable for convincing phishing campaigns long after the disclosure, so affected customers should verify any message claiming to come from SafePal. The fact that seed phrases and private keys were untouched does not reduce the need for caution with the personal data that did get out.

AI-generated image.

✔Human Verified


Researched and cross-referenced against primary sources by the Bytevyte editorial team. This article was generated with the assistance of artificial intelligence and reviewed by the Bytevyte editorial team.