SafePal discloses security incident affecting 39,798 customers

News Team
Written by News Team

Hardware wallet provider SafePal disclosed a security incident affecting approximately 39,798 customers. The breach involved an authorisation flaw in an order-tracking system that allowed unauthorised access to customer order records for purchases made between March 2, 2025, and April 11, 2026.

Names, phone numbers, email addresses, shipping addresses, and transaction information were all disclosed. Seed phrases, private keys, wallet passwords, and cryptocurrency funds were not compromised, according to SafePal.

What happened

SafePal revealed it discovered an authorisation flaw in an order-tracking plug-in used to manage customer order information. According to SafePal, the vulnerability has been fixed, new security measures have been put in place, and an independent third-party security firm has been hired to verify the fix and carry out a more thorough examination of its order-processing environment.

The company claims that it established a specific help channel for the occurrence. On August 16, 2026, it sent notices to each of the impacted clients via its security email account with the subject line “[Important] Your SafePal Order Information Has Been Affected.”

SafePal said it is reducing the retention period for personal information in the affected order-processing environment to 90 days, subject to applicable legal requirements.

What this means for affected customers

For people who were affected, the main thing is to be careful and check everything. SafePal told customers to use the company’s tools to see if their information was part of the problem. People should also watch out for messages they do not expect that talk about their SafePal orders, the kind of wallet they have, where their things were sent, or what they bought from SafePal.

Customers do not need to relocate their assets just because their order details were compromised, according to SafePal. The business pointed out that needless transfers can increase dangers, especially if clients accept directions from unauthorised messages.

Requests for a seed phrase are a major warning sign. A legitimate wallet provider does not need a customer’s seed phrase to provide standard support. SafePal has warned customers not to share seed phrases, private keys, or passwords with anyone, including individuals claiming to represent SafePal support. The company said it does not request such credentials by phone, email, or other communication channels.

The company also advised customers not to click links or scan QR codes contained in unsolicited messages. Instead, it recommends accessing the official SafePal website directly rather than relying on links included in notifications. In those cases, the recommended response is different. Users should create a new wallet on a trusted device or in the official application, then transfer any remaining assets to it.

SafePal removes fraudulent websites and phishing links

SafePal said it has identified and taken down more than 30 fraudulent websites and phishing links linked to scams related to the incident. The company also said it continues to monitor for additional fraudulent websites and domains.

SafePal said customers can use a verification tool on its website to check whether their information was affected. The company advised users to access the official website directly rather than through links received via email, text, or social media. It also recommended manually entering its web address into a browser, a step intended to reduce the risk of phishing through misleading links.

Verification information should be obtained from SafePal’s official website and published security updates rather than from ads, sponsored links, unsolicited messages or QR codes.