SafePal Data Breach Affects Nearly 40,000 Users
SafePal Data Breach Exposes Customer Information
SafePal has announced a data breach affecting approximately 39,798 customers. The breach, announced on August 16, 2026, was attributed to an authorization flaw in an order-tracking plugin, which led to unauthorized access to sensitive customer order information.
Details of the Breach
The exposed information includes names, email addresses, shipping addresses, phone numbers, and specific details about purchases made through SafePal. However, the company confirmed that crucial data such as seed phrases, private keys, wallet passwords, and payment information were not compromised.
Timeline of Events
Records affected by the breach span orders placed between March 2, 2025, and April 11, 2026. SafePal received a phishing report in May and subsequently began a formal investigation in July, during which the authorization flaw was identified. The breach also coincided with a data-retention issue, which inadvertently extended the duration that older records were stored.
Response and Remediation
In response to the breach, SafePal has implemented multiple security measures, including fixing the authorization flaw and enhancing access controls. The company has reached out to affected customers via email and has established a tool for them to verify their order details using specific identifiers.
Additionally, SafePal has taken proactive measures against phishing attempts by removing over 30 phishing websites and continues to monitor for fraudulent activity that may exploit the leaked customer information. They emphasized that customers do not need to move assets as a precaution, unless they have interacted with questionable websites.
Future Actions
SafePal is also engaging an independent third-party security firm to evaluate their security enhancements and perform a comprehensive review of their order-processing systems. While they have found no evidence of wallet access compromise, ongoing investigations and updates are expected to provide further clarity on the incident.
For those concerned, SafePal reassured their user base that they never request sensitive information like seed phrases or passwords, and they are committed to addressing any potential impacts stemming from this breach.
Source: crypto.news