ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

SafePal discloses breach exposing nearly 40,000 customers' order data as stolen information surfaces for sale

SafePal, a company that makes hardware wallets and software applications for storing cryptocurrency, is notifying roughly 39,798 customers that their order information was stolen after a security flaw in its e-commerce system was exploited. The company said the exposed data covers orders placed between March 2, 2025, and April 11, 2026, and includes customer names, email addresses, shipping addresses, phone numbers and purchase details.


SafePal said the incident did not expose wallet seed phrases, private keys, account passwords, bank information, payment card numbers or government identification numbers, and it has found no evidence that the breach gave attackers access to customer wallets or funds. The company began emailing affected customers on Aug. 16 and built an online tool that lets customers check whether a specific order was compromised by entering the order number and shipping country.


A threat actor is now claiming, in a post on a cybercrime forum, to be selling the stolen SafePal data. Security monitoring account DarkWebInformer identified the post, which cites the same order window and roughly 39,798-customer figure that SafePal disclosed. The seller is reportedly offering order ID and shipping-country details from the stolen batch as proof the data is authentic, since that information can be checked against SafePal’s own verification tool. BleepingComputer has not independently confirmed that the seller actually holds the data.


SafePal traced the origin of the breach to a plug-in used for tracking customer orders, which contained an authorization flaw that let one customer’s order details be viewed through another customer’s account access. The company said it first received a report matching this pattern in early May 2026 and treated it at the time as a single, isolated case, citing the complexity of an order-processing system that spans multiple internal components, external integrations and third-party logistics partners. The case was later escalated into a formal security investigation, and in July SafePal undertook what it called a full review and rebuild of its order-processing system, during which it identified and fixed the underlying flaw.


Separately, SafePal said it discovered a configuration error that disabled a data-cleanup process between September 2025 and April 2026, causing order records to be retained further back than intended, to as early as March 2025. The company said it has since purged personal data tied to affected orders from its active servers, while keeping an encrypted offline copy in case law enforcement needs it.


SafePal said suspicious activity connected to the breach may date back to May, when a customer described on social media platform X receiving a phishing email and a phone call from someone posing as a SafePal employee. The email claimed a security flaw had been found in the SafePal X1 hardware wallet and asked the recipient to install a firmware update. SafePal has not confirmed whether that specific report is connected to this breach.


The company is warning customers to watch for phishing emails and calls referencing firmware updates, product returns, refunds or legal investigations, and said it has taken down more than 30 fraudulent websites and phishing links tied to the incident. SafePal said customers whose order data was exposed do not need to replace their hardware wallets or move their cryptocurrency as a result of this breach. It said any customer who has already shared a seed phrase or private key with a phisher should treat that wallet as compromised and move their assets to a new device or official application.


SafePal is working with an outside security firm to verify the fix and conduct a wider review of its order-processing systems. The company also said it will limit retention of customer personal data in its order-processing system to 90 days from the date of collection going forward.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543