SafePal breach exposes customer details to phishing risk
SafePal has warned nearly 40,000 customers that their personal information was exposed after attackers exploited a flaw in an order-tracking system, creating a heightened risk of targeted phishing and impersonation attacks against cryptocurrency holders. The cryptocurrency wallet provider said information belonging to approximately 39,798 customers was accessed without authorisation. The affected…
SafePal, a cryptocurrency wallet provider, has disclosed that personal information of nearly 40,000 customers was exposed after attackers exploited a flaw in its order-tracking system. This heightened risk of phishing and impersonation attacks against crypto holders stems from the compromised data, which included names, email addresses, shipping addresses, telephone numbers, and purchase details from March 2, 2025, to April 11, 2026.
Notably, seed phrases, private keys, wallet passwords, and other direct cryptocurrency credentials were not accessed. The breach, attributed to an authorisation weakness in a plug-in associated with the order-tracking function, allowed unauthorized access to customer order information under certain conditions. SafePal swiftly patched the flaw and implemented additional security measures.
The incident, which was initially reported to the company in early May, prompted a formal security investigation that uncovered a separate data-cleaning process disruption between September 2025 and April 2026. Affected customers were notified on August 16 and can verify if their orders were compromised via an online mechanism. SafePal has also shortened the retention period for personal information within the order-processing environment to 90 days, subject to legal requirements.
An independent security firm is evaluating the remediation efforts, and third-party logistics and fulfilment companies have been contacted as part of the investigation. The episode highlights the vulnerability of customer information surrounding cryptocurrency transactions, even when private keys remain protected.
Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.