SafePal, a cryptocurrency wallet provider, has disclosed a data breach that involved unauthorized access to about 39,798 customers’ order information, including personal details such as names, addresses and purchase data.
Data Breach Details
An authorization flaw in the order tracking system allowed access to another customer’s order information between March 2, 2025, and April 11, 2026, SafePal said in a statement. The breach did not involve access to “seed phrases,” private keys, wallet passwords, bank account and payment card information or government-issued identification numbers.
As a result of the breach, affected users’ order information could be used for targeted phishing and impersonation attempts, the firm said. SafePal has fixed the issue and introduced further security measures in response, adding that it will retain customers’ personal data in its order processing system for only 90 days.
The crypto hardware wallet provider has identified and taken down more than 30 fraudulent websites and phishing links tied to the breach.
Original reporting: Appleton, WI News Feed (HLL/CB) — read the source article.