Urgent.News

One page, thousands of outlets. See who else covered it.

Editions

Tech

Crypto wallet provider SafePal discloses data breach affecting nearly 40,000 users’ order information

The company said it has rectified the problem

Cryptocurrency wallet provider SafePal announced on Sunday (Aug 16) that it experienced a data breach, affecting approximately 39,798 customers' order information. The unauthorized access occurred via an authorization flaw in the order tracking system, which was active between March 2, 2025, and April 11, 2026. SafePal disclosed the incident in a statement, explaining that the breach did not involve access to seed phrases, private keys, wallet passwords, bank account or payment card information, or government-issued identification numbers.

The compromised order information includes personal details such as names, addresses, and purchase data, which could be exploited for targeted phishing and impersonation attempts. The wallet provider assured that wallet passwords, usually alphanumeric, and seed phrases, a set of random words for additional security, were not accessed. Should customers lose their passwords and phrases, they would lose access to their wallets.

SafePal asserted that it had rectified the issue and implemented additional security measures. The company also announced that it would retain customers' personal data in its order processing system for only 90 days. Furthermore, SafePal identified and took down more than 30 fraudulent websites and phishing links associated with the breach.

Written by urgent.news from The Business Times - Companies & Markets's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at businesstimes.com.sg →

More in Tech

What are you working on? #01

What are you working on? I hear these words in my day-to-day. And sometimes, when I hear them, there’s this little brain freeze that happens because my brain is probably trying to put into words the…

The Angular pattern that needs no Provider

Services are often the default abstraction for reusable Angular logic. But what if the logic is local to a component, depends on its injection context, and does not represent shared application state?

More from Sunday 16 August →