Regulation
SafePal Data Breach Exposes Order Details of Nearly 40,000 Wallet Customers
18 Aug 2026, 06:25
14 views
Admin
Crypto wallet provider SafePal disclosed a data breach tied to an order-tracking plugin flaw that exposed personal information for 39,798 customers, though private keys and seed phrases were not affected.
Crypto wallet provider SafePal disclosed a data breach that exposed the personal information of 39,798 customers, tracing the root cause to an authorization flaw in a plugin the company used for order tracking. Under certain conditions, the flaw allowed one customer to view another customer's order information, a class of vulnerability known as an insecure direct object reference, where an application fails to properly verify that a user requesting a piece of data is actually authorized to see it.
The exposure covers orders placed between March 2, 2025 and April 11, 2026, a window of more than a year during which the underlying flaw apparently went undetected. Information exposed to unauthorized viewers included customer names, email addresses, shipping addresses, phone numbers and purchase details, the kind of data that is commonly used to craft convincing phishing attacks even when it doesn't include financial credentials directly. SafePal was explicit that wallet-critical information remained secure throughout the incident: private keys and seed phrases, the cryptographic material that actually controls access to a user's crypto holdings, were not exposed, and the company said it has found no evidence that customer funds were directly affected by the breach.
SafePal's own disclosure to affected customers warned that the exposed data could be weaponized for follow-up social engineering attacks, specifically flagging the risk of "fraudulent phone calls, emails, text messages, letters, refund offers, firmware-update requests, fake customer-support communications, malicious websites, or other attempts to obtain your wallet credentials or additional personal information." That warning reflects a broader pattern in crypto-adjacent data breaches, where the initial exposure rarely involves direct theft of funds, but instead hands attackers the raw material needed to impersonate a trusted company and trick victims into voluntarily handing over the credentials that actually matter.
The breach's real-world impact escalated shortly after disclosure. According to threat-intelligence monitoring service DarkWebInformer, a threat actor began advertising the stolen data on a cybercrime forum, with the listing citing the same order window and the same customer count, 39,798, that SafePal disclosed, lending credibility to the claim that the listed data does in fact originate from this breach. Security researchers tracking the incident have noted that hardware wallet and self-custody companies present an especially attractive target for this kind of order-database attack, since their customer lists effectively function as a directory of people known to hold meaningful cryptocurrency balances, making phishing campaigns built from stolen order data disproportionately effective compared to breaches at companies without that built-in signal of wealth. SafePal has not disclosed the specific plugin vendor responsible for the authorization flaw or detailed what remediation steps have been taken to prevent similar exposures going forward.
The exposure covers orders placed between March 2, 2025 and April 11, 2026, a window of more than a year during which the underlying flaw apparently went undetected. Information exposed to unauthorized viewers included customer names, email addresses, shipping addresses, phone numbers and purchase details, the kind of data that is commonly used to craft convincing phishing attacks even when it doesn't include financial credentials directly. SafePal was explicit that wallet-critical information remained secure throughout the incident: private keys and seed phrases, the cryptographic material that actually controls access to a user's crypto holdings, were not exposed, and the company said it has found no evidence that customer funds were directly affected by the breach.
SafePal's own disclosure to affected customers warned that the exposed data could be weaponized for follow-up social engineering attacks, specifically flagging the risk of "fraudulent phone calls, emails, text messages, letters, refund offers, firmware-update requests, fake customer-support communications, malicious websites, or other attempts to obtain your wallet credentials or additional personal information." That warning reflects a broader pattern in crypto-adjacent data breaches, where the initial exposure rarely involves direct theft of funds, but instead hands attackers the raw material needed to impersonate a trusted company and trick victims into voluntarily handing over the credentials that actually matter.
The breach's real-world impact escalated shortly after disclosure. According to threat-intelligence monitoring service DarkWebInformer, a threat actor began advertising the stolen data on a cybercrime forum, with the listing citing the same order window and the same customer count, 39,798, that SafePal disclosed, lending credibility to the claim that the listed data does in fact originate from this breach. Security researchers tracking the incident have noted that hardware wallet and self-custody companies present an especially attractive target for this kind of order-database attack, since their customer lists effectively function as a directory of people known to hold meaningful cryptocurrency balances, making phishing campaigns built from stolen order data disproportionately effective compared to breaches at companies without that built-in signal of wealth. SafePal has not disclosed the specific plugin vendor responsible for the authorization flaw or detailed what remediation steps have been taken to prevent similar exposures going forward.